Skip to main content
Glama

sandbox-mcp

MCP service that exposes sandboxed code execution tools. Delegates execution to a sandbox-runner VM running Firecracker microVMs on Proxmox (nested KVM).

Tools

Tool

Description

shell_run

Run bash script in isolated microVM

python_run

Run Python 3 code in isolated microVM

node_run

Run Node.js code in isolated microVM

All tools: no network access, 256MB RAM, 0.5 CPU, configurable timeout (default 15s).

Related MCP server: Netmind Code Interpreter

Environment Variables

Variable

Required

Description

SANDBOX_MCP_INTERNAL_TOKEN

Yes

Auth token for MCP clients

SANDBOX_RUNNER_URL

No

URL of sandbox-runner VM (e.g. http://sandbox-runner:8080)

SANDBOX_RUNNER_TOKEN

No

Bearer token for sandbox-runner auth

PORT

No

HTTP port (default 3001)

SANDBOX_TIMEOUT_MS

No

Default execution timeout ms (default 15000)

Sandbox Runner Contract

The service expects a sandbox-runner HTTP API (deployed separately on Proxmox):

POST /run
  Body: { lang: "bash" | "python" | "node", code: string, timeoutMs: number }
  Response: { stdout: string, stderr: string, exitCode: number, durationMs: number }

GET /health
  Response: { status: "ok", poolSize: number, available: number }

Without Proxmox (pre-deployment)

If SANDBOX_RUNNER_URL is not set, the service starts normally but all tool calls return a 503 not configured message. The feature flag sandbox_exec should remain disabled until the runner is deployed.

Endpoints

  • GET /health — health check, includes runnerConfigured boolean

  • POST /mcp — MCP JSON-RPC (StreamableHTTP)

  • GET /mcp — MCP SSE transport

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    A
    maintenance
    Provides sandboxed code execution for AI agents with support for Python, JavaScript, and shell commands. Includes comprehensive safety features like destructive pattern blocking, timeout protection, and restricted file access for secure production use.
    15
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Runs AI-generated code in secure Firecracker microVMs with opt-in network policy enforcement, PII scanning, prompt injection defense, and audit logging. Exposes MCP tools for running commands, managing files, and the full sandbox lifecycle.
    30
    1
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Execute code in 8 languages (Python, JS, TS, Go, Java, C++, C, Bash) in gVisor sandboxes.

  • Host static HTML pages, generate PDFs, screenshots, scrape JS sites, run sandboxed JavaScript.

  • Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/paulleungtc-git/mcp-sandbox'

If you have feedback or need assistance with the MCP directory API, please join our Discord server