Gives an agent a real Linux VM with its own kernel, dedicated per sandbox rather than a shared container, so untrusted model-generated code stays contained. Placed alphabetically in the existing Code Execution list.