SecurityBox runs untrusted Ruby code inside a ruby.wasm (wasm32-unknown-wasip1) module via the wasmtime gem. The guest has no filesystem, network, processes, threads or sockets, and the host enforces CPU (fuel), wall-clock, memory and output-size limits, always receiving a structured Result back.
Required Ruby Version
>= 4.0
Authors
Marcelo Junior
Versions
- 0.1.0 September 13, 2026 (37.7 MB)