Skip to main content
Glama
ar-blues

ScratchRun MCP Server

README.md
# @scratchrun/mcp-server

MCP server for [ScratchRun](https://scratchrun.dev) — ephemeral, MicroVM-isolated code execution for AI agents.

Each call runs in a fresh hardware-isolated MicroVM. The VM is hard-purged after execution. No state, no files, nothing persists between calls.

## Install

Add to your `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "scratchrun": {
      "command": "npx",
      "args": ["-y", "@scratchrun/mcp-server"],
      "env": {
        "SCRATCHRUN_API_KEY": "sr_live_your_key_here"
      }
    }
  }
}
```

Get an API key at [scratchrun.dev](https://scratchrun.dev).

## Tool: `scratchrun_exec`

Executes code in an ephemeral sandbox and returns stdout, stderr, exit code, and any output files.

**Parameters:**

| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `runtime` | `python3.12` \| `python3.11` \| `node20` \| `bash` | yes | Runtime to use |
| `code` | string | yes | Code to execute |
| `timeout_ms` | integer | no | Timeout in ms (default 10000, max 30000) |
| `memory_mb` | integer | no | Memory limit in MB (default 256, max 512) |
| `env` | object | no | Environment variables — use for secrets, not code strings |
| `files` | object | no | Files to write before execution (path → content) |
| `return_files` | string[] | no | File paths to capture after execution (returned as base64) |

**Example — run Python and return a chart:**

```json
{
  "runtime": "python3.12",
  "code": "import matplotlib.pyplot as plt\nimport numpy as np\nx = np.linspace(0, 10, 100)\nplt.plot(x, np.sin(x))\nplt.savefig('/tmp/plot.png')",
  "return_files": ["/tmp/plot.png"]
}
```

Output files are returned as base64. Image files (PNG, JPG, SVG) are returned as MCP image content blocks and render inline in Claude.

## Isolation

- Hardware-virtualized MicroVM per execution (own kernel, not a shared-kernel container)
- `TerminateMicroVM` called unconditionally after every run — VM destroyed, never reused
- RFC 1918 + cloud metadata (`169.254.x.x`) always blocked at the network layer
- Read-only system filesystem via OverlayFS; `/tmp` is RAM-backed and gone with the VM

## Latency

~400ms median (warm pool). 2–8s cold start if the pool is empty.

## License

MIT

TDQS

A4.8/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no possibility of confusion between tools. The tool's purpose is clearly described as sandboxed code execution, making it unambiguous.

Naming Consistency5/5

The single tool name 'scratchrun_exec' follows a clear snake_case pattern with a descriptive prefix and verb. Consistency is trivially maintained when there is only one tool.

Tool Count5/5

The server is focused entirely on one function: executing code in an ephemeral sandbox. One tool is exactly the right size for this narrow, well-defined purpose, and the parameter space covers execution, environment variables, and file output.

Completeness5/5

For the server's stated purpose (sandboxed code execution), the tool fully covers the lifecycle: execute code, pass environment variables, and retrieve output files. No obvious missing operations exist within the domain.

Maintenance

ActivitySlowing
ResponsivenessNo issues