Skip to main content
Glama

sandbox-mcp

MCP service that exposes sandboxed code execution tools. Delegates execution to a sandbox-runner VM running Firecracker microVMs on Proxmox (nested KVM).

Tools

Tool

Description

shell_run

Run bash script in isolated microVM

python_run

Run Python 3 code in isolated microVM

node_run

Run Node.js code in isolated microVM

All tools: no network access, 256MB RAM, 0.5 CPU, configurable timeout (default 15s).

Related MCP server: Code Executor MCP Server

Environment Variables

Variable

Required

Description

SANDBOX_MCP_INTERNAL_TOKEN

Yes

Auth token for MCP clients

SANDBOX_RUNNER_URL

No

URL of sandbox-runner VM (e.g. http://sandbox-runner:8080)

SANDBOX_RUNNER_TOKEN

No

Bearer token for sandbox-runner auth

PORT

No

HTTP port (default 3001)

SANDBOX_TIMEOUT_MS

No

Default execution timeout ms (default 15000)

Sandbox Runner Contract

The service expects a sandbox-runner HTTP API (deployed separately on Proxmox):

POST /run
  Body: { lang: "bash" | "python" | "node", code: string, timeoutMs: number }
  Response: { stdout: string, stderr: string, exitCode: number, durationMs: number }

GET /health
  Response: { status: "ok", poolSize: number, available: number }

Without Proxmox (pre-deployment)

If SANDBOX_RUNNER_URL is not set, the service starts normally but all tool calls return a 503 not configured message. The feature flag sandbox_exec should remain disabled until the runner is deployed.

Endpoints

  • GET /health — health check, includes runnerConfigured boolean

  • POST /mcp — MCP JSON-RPC (StreamableHTTP)

  • GET /mcp — MCP SSE transport

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to execute Python, JavaScript, Bash, and Go code in blazing-fast (~0.1ms startup), isolated cloud containers with secure, ephemeral environments that auto-destroy after use.
    156
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides sandboxed code execution for AI agents with support for Python, JavaScript, and shell commands. Includes comprehensive safety features like destructive pattern blocking, timeout protection, and restricted file access for secure production use.
    11 npm
    40 PyPI
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to safely execute Python, JavaScript, and Bash code in an isolated Docker sandbox with strict security constraints.
    1
    -
  • A
    license
    A
    quality
    C
    maintenance
    Ephemeral MicroVM-isolated code execution for AI agents. Run Python, Node, or bash — fresh hardware-isolated VM per call, hard-purged after. No state persists between calls.
    1
    34 npm
    MIT