Skip to main content
Executing Code

TypeScript

Run and type-check TypeScript in Secure Exec with the secure-exec/typescript entry point.

secure-exec/typescript exports the same execute and evaluate as the main entry point, plus check.

import { check, evaluate } from "secure-exec/typescript";

// Running TypeScript strips types without checking them, so type-check an
// agent's generated code first and feed the diagnostics back to it.
const generated = `([5, 10, "27"] as number[]).reduce((a, b) => a + b, 0)`;

const checked = await check(generated, { filePath: "generated.ts" });
for (const diagnostic of checked.diagnostics) {
	console.log(
		`${diagnostic.category} TS${diagnostic.code}: ${diagnostic.message}`,
	);
}

const fixed = generated.replace(`"27"`, "27");
const recheck = await check(fixed, { filePath: "generated.ts" });
if (recheck.outcome === "succeeded" && !recheck.hasErrors) {
	const result = await evaluate<number>(fixed);
	console.log(result.outcome === "succeeded" ? result.value : result.error); // 42
}

Running strips types

execute and evaluate transpile TypeScript and run it. They do not type check, so code with type errors still runs. This keeps the hot path fast.

Checking runs the real compiler

check runs the TypeScript compiler inside the VM and returns structured diagnostics without running your code. Each diagnostic has a code, category, message, and, when known, a filePath, line, and column.

filePath only labels the source in diagnostics. It is never read from disk. Pass compilerOptions or tsconfigPath to change compiler settings.

Check a project

A project lives in a VM’s filesystem, so type-check it on a VM. vm.typescript.checkProject() checks the project in the working directory using its tsconfig.json, and vm.typescript has the same execute, evaluate, executeFile, and check as this entry point.

Feeding diagnostics back to a model is the cheapest way to fix generated code. See Agent Code Tool.

Edit this page Last updated September 21, 2026