sandbox-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@sandbox-mcprun a python script that prints the first 10 Fibonacci numbers"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
sandbox-mcp
MCP service that exposes sandboxed code execution tools. Delegates execution to a
sandbox-runner VM running Firecracker microVMs on Proxmox (nested KVM).
Tools
Tool | Description |
| Run bash script in isolated microVM |
| Run Python 3 code in isolated microVM |
| Run Node.js code in isolated microVM |
All tools: no network access, 256MB RAM, 0.5 CPU, configurable timeout (default 15s).
Related MCP server: Netmind Code Interpreter
Environment Variables
Variable | Required | Description |
| Yes | Auth token for MCP clients |
| No | URL of sandbox-runner VM (e.g. |
| No | Bearer token for sandbox-runner auth |
| No | HTTP port (default |
| No | Default execution timeout ms (default |
Sandbox Runner Contract
The service expects a sandbox-runner HTTP API (deployed separately on Proxmox):
POST /run
Body: { lang: "bash" | "python" | "node", code: string, timeoutMs: number }
Response: { stdout: string, stderr: string, exitCode: number, durationMs: number }
GET /health
Response: { status: "ok", poolSize: number, available: number }Without Proxmox (pre-deployment)
If SANDBOX_RUNNER_URL is not set, the service starts normally but all tool calls
return a 503 not configured message. The feature flag sandbox_exec should remain
disabled until the runner is deployed.
Endpoints
GET /health— health check, includesrunnerConfiguredbooleanPOST /mcp— MCP JSON-RPC (StreamableHTTP)GET /mcp— MCP SSE transport
This server cannot be deployed
Maintenance
Related MCP Connectors
Execute code in 8 languages (Python, JS, TS, Go, Java, C++, C, Bash) in gVisor sandboxes.
Run Python code in a secure sandbox without local setup. Declare inline dependencies and execute s…
- mcp-serverOAuthai.cdbx
Build Apps and run code in 30 languages — sandboxed, with persistent sessions for agent loops.
MCP server for Superserve sandboxes: create, exec, and manage Firecracker microVMs
Related MCP Servers
FlicenseNot gradedqualityCmaintenanceEnables AI assistants to execute Python, JavaScript, Bash, and Go code in blazing-fast (~0.1ms startup), isolated cloud containers with secure, ephemeral environments that auto-destroy after use.156-- AlicenseNot gradedqualityDmaintenanceEnables secure cloud-based execution of code across 14+ programming languages within a sandboxed environment. It supports file management, standard input/output handling, and automatic generation of visual artifacts like plots and charts.MIT
- AlicenseNot gradedqualityAmaintenanceProvides sandboxed code execution for AI agents with support for Python, JavaScript, and shell commands. Includes comprehensive safety features like destructive pattern blocking, timeout protection, and restricted file access for secure production use.9 npm113 PyPIMIT

declaw-mcp-serverofficial
AlicenseAqualityCmaintenanceRuns AI-generated code in secure Firecracker microVMs with opt-in network policy enforcement, PII scanning, prompt injection defense, and audit logging. Exposes MCP tools for running commands, managing files, and the full sandbox lifecycle.727 npm1Apache 2.0