@slicervm/mcp
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@slicervm/mcpSpawn a Linux VM, install cowsay, fork it into three, run a different command in each, then destroy all."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@slicervm/mcp
A Model Context Protocol server that gives an AI agent its own fleet of disposable Linux microVMs on hardware you control.
When an agent executes code, it runs on something. Run it on your laptop and
a bad rm -rf, a leaked key, or a runaway process is your problem. This server
puts that execution inside a real VM boundary instead: the agent spawns an
isolated microVM, runs commands in it, cold-forks a prepared VM into many
branches to explore changes in parallel, and destroys them when done — all on
your own box, sub-second, with the daemon's egress policy in force.
Tools
Tool | What it does |
| Boot a fresh isolated microVM, wait until ready, return name + IP |
| Run a shell command in a VM; return stdout, stderr, exit code |
| Cold-fork a prepared VM into N children that each start from its exact disk state |
| List the microVMs with status, IP, and tags |
| Permanently delete a microVM and its disk |
slicer_fork is the differentiated one: set an environment up once
(install deps, clone a repo, warm a cache), then fork it so an agent can try
ten approaches in parallel from an identical starting point. Only on-disk state
carries over — write anything you want inherited to a real path, not /tmp.
Related MCP server: RelayMe
Requirements
A running Slicer daemon (your laptop, homelab, or a server) reachable over HTTP or a Unix socket.
Node.js 18+.
Configure
Set three environment variables:
SLICER_URL— daemon API URL or socket path (required)SLICER_TOKEN— bearer token, if the daemon requires authSLICER_HOSTGROUP— host group to launch into (auto-selected when the daemon has one group, or thesboxgroup; otherwise set it explicitly)
Claude Code
claude mcp add slicer -- npx -y @slicervm/mcp \
-e SLICER_URL=http://127.0.0.1:8080 \
-e SLICER_TOKEN=... \
-e SLICER_HOSTGROUP=sboxClaude Desktop / Cursor (mcp.json)
{
"mcpServers": {
"slicer": {
"command": "npx",
"args": ["-y", "@slicervm/mcp"],
"env": {
"SLICER_URL": "http://127.0.0.1:8080",
"SLICER_TOKEN": "...",
"SLICER_HOSTGROUP": "sbox"
}
}
}
}Try it
Once wired in, ask your agent:
Spawn a Linux VM, install cowsay, snapshot it, then fork it three ways and have each fork say something different. Clean up after yourself.
Development
This package depends on cold-fork support in @slicervm/sdk >= 0.2.0,
which is pending publish. For local development, link the SDK build:
(cd ../sdk-ts && npm run build && npm link)
npm link @slicervm/sdkThen build this server:
npm install
npm run build
node dist/index.js # with SLICER_URL etc. setThis server cannot be deployed
Maintenance
Related MCP Connectors
Linux microVM sandboxes for AI agents: run commands, files, processes, pause and wake.
Real Linux labs your AI agent deploys, routes and runs, with domains, TLS, DBs and an audit log.
Persistent Linux microVMs for agents: root, internet, sub-second resume and a public URL.
Remote Linux boxes for coding agents: Docker, a browser, screenshots, logs, human takeover.
Related MCP Servers
- AlicenseAqualityDmaintenanceRun AI agents in VM-isolated sandboxes on your Mac.151MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to safely run bounded, sandboxed tasks on remote machines with persistent state and reviewable artifacts.Apache 2.0
- AlicenseAqualityCmaintenanceEnables AI clients to perform sandboxed filesystem, directory, Ubuntu system, network, git, and code/text operations through 38 typed tools confined to a workspace. Ships with a browser-based web console that provides an interactive Linux terminal, a live tool playground, and real-time CPU, memory, and disk monitoring.382MIT
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to operate disposable Linux computers via MCP, providing tools for shell, file read/write, directory listing, and port exposure. It also supports browser automation and integration with any MCP-compatible client.Apache 2.0