Replit Brings AI-Built Apps to Windows With Sandboxed Local Execution

Replit's new Windows desktop app runs AI-generated builds locally, with each one sandboxed by Microsoft Execution Containers and NVIDIA OpenShell.

·
·
·
  • Replit announced a Windows desktop app preview that builds and runs AI-generated apps locally
  • Each build is isolated in its own sandbox using Microsoft Execution Containers and NVIDIA OpenShell
  • Access is waitlist-only; the preview launches on Windows first with no public pricing yet
  • MXC is now generally available on Windows 11 as a policy-driven agent containment layer
  • OpenShell adds credential management and OCSF auditing on top of MXC's file and network policies
  • Codex, Copilot, Replit, LM Studio, Claude Code, Perplexity and others are adopting MXC

Replit previews local, sandboxed app builds on Windows

Replit has opened a waitlist for a Windows desktop preview that compiles and runs agent-generated apps on the user’s PC. Each build runs in its own isolated sandbox built on Microsoft Execution Containers.

Replit’s announcement covers local compilation and execution. The company has not said that its model or planning service runs on-device. A RuntimeWire report also notes that Replit has disclosed no separate price for the desktop client.

Detail Current status
Availability Waitlist preview
Platform Windows only at launch
Local execution Generated apps compile and run on the PC
Isolation One MXC and OpenShell sandbox per build
Pricing Not disclosed
General release No date announced
Offline use Not confirmed
Replit desktop app on Windows showing a PC Cleanup dashboard built locally at localhost port 13000
Replit’s promotional image shows a generated app running through localhost:13000.

Local builds move the trust boundary

Cloud workspaces usually execute generated code inside remote infrastructure, separated from files and credentials on the developer’s computer. Local execution places that code closer to project directories, installed tools, environment variables, SSH keys, browser data, and cloud credentials.

A local runtime can shorten the edit-and-run cycle and work directly with local repositories and toolchains. Those capabilities require strict controls over files, processes, credentials, desktop access, and network connections. Replit is using MXC and OpenShell to enforce those boundaries.

MXC turns permissions into policy

Microsoft Execution Containers is a Windows containment layer for untrusted code and dynamically generated workloads. Its policies can wrap generated programs, plugins, tool calls, agent harnesses, or an entire agent. Microsoft made MXC generally available for Windows 11 alongside the Replit preview, according to its MXC release post.

MXC supports several isolation levels, including process and session isolation, Windows Subsystem for Linux containers, virtual machines, and Windows 365 for Agents. These options carry different performance, compatibility, and isolation costs. Replit has not identified the container type used by its desktop preview.

A JSON policy defines which resources a workload may use. Microsoft’s coding-agent example includes controls such as:

  • Grant read and write access to the current project repository.
  • Permit Git, compilers, package managers, and approved language toolchains.
  • Deny access to personal paths such as the user’s Documents folder.
  • Restrict inbound and outbound traffic to approved endpoints.
  • Deny access to the interactive Windows desktop.

That example illustrates MXC’s policy model. Replit has not published the default policy it will ship or said whether users can inspect and modify it.

OpenShell supplies credentials and telemetry

NVIDIA OpenShell adds agent-oriented controls around MXC, including file and inference permissions, network rules, credential management, and security events formatted with the Open Cybersecurity Schema Framework. OCSF gives security tools a common structure for recording what an agent attempted, which policy applied, and whether the action succeeded.

MXC’s native activity reporting has a specific limitation: JSON activity reports are available only for process containers running in learning or permissive modes. Enforcement mode does not produce that report. Teams using enforcement therefore need endpoint detection software or an integration such as OpenShell’s OCSF auditing to record denied actions. Replit has not described which logs its preview will expose.

A malicious webpage can become an instruction

Prompt injection occurs when an agent treats untrusted content as instructions. A webpage, repository file, issue comment, or package description can attempt to make a coding agent read secrets, execute commands, or send data to an external server.

Microsoft demonstrated this threat with a test website containing instructions intended to hijack a coding agent. Defender blocked the attempted action and flagged the agent while preserving the presenter’s own access to the protected documents. The demonstration shows the intended interaction between containment policy and endpoint security; it does not reveal how Replit will configure those controls.

Policy quality determines the protection developers receive. Overbroad file grants can expose secrets, permitted network routes can carry accessible data outside the machine, and approved shells or package managers can expand what generated code can do. Artifacts executed later outside the sandbox also inherit the permissions of their new environment.

The preview leaves key controls unspecified

Replit’s public material does not yet answer several implementation questions that affect development and security workflows:

  • Which Windows versions, editions, and hardware configurations are supported?
  • Which MXC isolation type does each build use?
  • Can users inspect or edit file, process, desktop, and network policies?
  • How are API keys and other credentials injected, scoped, rotated, and redacted?
  • Can generated apps bind local ports or contact development services on the host?
  • Which logs record successful actions, blocked attempts, and policy changes?
  • Which features continue working without an internet connection?
  • What protections remain when users export or execute an artifact outside Replit?
  • Are macOS and Linux clients planned?

Windows gains a shared agent boundary

Microsoft lists OpenAI Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell, and Unsloth AI among the tools supporting MXC. Anthropic Claude Code, Box, Egnyte, Manus, Perplexity, Raycast, and Simular are listed as adding support.

Developers building local agents can use this shared Windows policy model in place of unconstrained subprocess execution. Effective integrations will limit file access to project directories, broker credentials, restrict network egress, record denied actions, and preserve containment when generated artifacts run. Replit’s preview will show how much of that control reaches developers through the product interface.

Trending
  • No trending articles

Comments

avatar

Next Reads