Skip to main content
Glama
slicervm
by slicervm

@slicervm/mcp

A Model Context Protocol server that gives an AI agent its own fleet of disposable Linux microVMs on hardware you control.

When an agent executes code, it runs on something. Run it on your laptop and a bad rm -rf, a leaked key, or a runaway process is your problem. This server puts that execution inside a real VM boundary instead: the agent spawns an isolated microVM, runs commands in it, cold-forks a prepared VM into many branches to explore changes in parallel, and destroys them when done — all on your own box, sub-second, with the daemon's egress policy in force.

Tools

Tool

What it does

slicer_spawn

Boot a fresh isolated microVM, wait until ready, return name + IP

slicer_exec

Run a shell command in a VM; return stdout, stderr, exit code

slicer_fork

Cold-fork a prepared VM into N children that each start from its exact disk state

slicer_list

List the microVMs with status, IP, and tags

slicer_destroy

Permanently delete a microVM and its disk

slicer_fork is the differentiated one: set an environment up once (install deps, clone a repo, warm a cache), then fork it so an agent can try ten approaches in parallel from an identical starting point. Only on-disk state carries over — write anything you want inherited to a real path, not /tmp.

Related MCP server: RelayMe

Requirements

  • A running Slicer daemon (your laptop, homelab, or a server) reachable over HTTP or a Unix socket.

  • Node.js 18+.

Configure

Set three environment variables:

  • SLICER_URL — daemon API URL or socket path (required)

  • SLICER_TOKEN — bearer token, if the daemon requires auth

  • SLICER_HOSTGROUP — host group to launch into (auto-selected when the daemon has one group, or the sbox group; otherwise set it explicitly)

Claude Code

claude mcp add slicer -- npx -y @slicervm/mcp \
  -e SLICER_URL=http://127.0.0.1:8080 \
  -e SLICER_TOKEN=... \
  -e SLICER_HOSTGROUP=sbox

Claude Desktop / Cursor (mcp.json)

{
  "mcpServers": {
    "slicer": {
      "command": "npx",
      "args": ["-y", "@slicervm/mcp"],
      "env": {
        "SLICER_URL": "http://127.0.0.1:8080",
        "SLICER_TOKEN": "...",
        "SLICER_HOSTGROUP": "sbox"
      }
    }
  }
}

Try it

Once wired in, ask your agent:

Spawn a Linux VM, install cowsay, snapshot it, then fork it three ways and have each fork say something different. Clean up after yourself.

Development

This package depends on cold-fork support in @slicervm/sdk >= 0.2.0, which is pending publish. For local development, link the SDK build:

(cd ../sdk-ts && npm run build && npm link)
npm link @slicervm/sdk

Then build this server:

npm install
npm run build
node dist/index.js   # with SLICER_URL etc. set

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to safely run bounded, sandboxed tasks on remote machines with persistent state and reviewable artifacts.
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI clients to perform sandboxed filesystem, directory, Ubuntu system, network, git, and code/text operations through 38 typed tools confined to a workspace. Ships with a browser-based web console that provides an interactive Linux terminal, a live tool playground, and real-time CPU, memory, and disk monitoring.
    38
    2
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to operate disposable Linux computers via MCP, providing tools for shell, file read/write, directory listing, and port exposure. It also supports browser automation and integration with any MCP-compatible client.
    Apache 2.0