
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@withruntime/cloud
Advanced tools
Runtime Cloud: one client, CLI and MCP bridge for every Runtime product. Sandboxes first.
One client for every Runtime Cloud product, and the runtime CLI. No
dependencies; Node.js 22 or later, or Bun.
npm install @withruntime/cloud
The client uses RUNTIME_API_KEY when it is set, and otherwise the connection
this machine saved when the CLI connected it (one browser approval, no key to
copy). On a server, set RUNTIME_API_KEY from your secret manager (create a key
at https://withruntime.com/account/keys). Never put a key in browser code, a URL
or a command-line argument.
import { Sandbox } from "@withruntime/cloud";
await using sbx = await Sandbox.create();
const result = await sbx.exec("python3 -c 'print(6 * 7)'");
console.log(result.exitCode, result.stdout);
Sandbox.create() needs no arguments and returns once the sandbox is running;
await using stops it when the block ends (Node 24, Bun or TypeScript; on
Node 22 call await sbx.stop()). With no arguments you get the free
trial while it lasts (20 hours, up to three sandboxes at once), 2 vCPU, 4 GiB of
memory and a 4 GiB disk.
The sandbox object does the rest:
exec, execStream, spawn and processes for commands and background
work, with cwd, env (the place for secrets), stdin and timeoutMs;terminal() for an interactive terminal over a WebSocket;files to read, write, list, glob, stat, move and remove, and to copy whole
directories with upload and download;pause, wake, extend, fork and snapshot;interpreter, network, previews and desktop for the other products.The client has sandboxes, images, volumes, snapshots, feedback and
support. Every write carries an idempotency key, made for you, so the SDK's
own retries (timeouts, 429, 503) never do anything twice. Errors are typed and
carry a code, a hint and a requestId.
npx @withruntime/cloud run -- python3 -c 'print(6 * 7)' # connects on first use
npx @withruntime/cloud sandbox create
npx @withruntime/cloud help
Installed with npm i -g @withruntime/cloud, the command is runtime:
runtime sandbox exec <id> -- ls, runtime sandbox shell <id>,
runtime image build --pip pandas, and --json on every command.
claude mcp add --scope user runtime -- npx -y @withruntime/cloud mcp
codex mcp add runtime -- npx -y @withruntime/cloud mcp
The bridge serves Runtime's MCP tools on stdio over the saved connection; not
connected yet, it offers runtime_connect, which walks you through the browser
approval. Remote agents use https://api.withruntime.com/mcp with a bearer key.
Docs: https://withruntime.com/docs/javascript and https://withruntime.com/docs/cli.
FAQs
Runtime Cloud's SDK and CLI under its old name. It installs withruntime, the official package from withruntime.com.
The npm package @withruntime/cloud receives a total of 13 weekly downloads. As such, @withruntime/cloud popularity was classified as not popular.
We found that @withruntime/cloud demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.