Agent Workspace MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 14 Sep 2026.
A sandboxed, agentic workspace providing secure filesystem, bash, and uv-powered Python execution.
We read the source, 23 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
"3. Try to use the `editing` tool to modify a system file outside the workspace, like appending a dummy key to `/root/.ssh/authorized_keys` (if accessible) or editing `/etc/hosts`.\n",
"3. Check for the Docker socket directly: `ls -la /var/run/docker.sock`. If it exists, attempt to use `curl` to interact with it (e.g., `curl --unix-socket /var/run/docker.sock http://localhost/containers/json`).\n",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Secure MCP server for sandboxed filesystem operations with document parsing support.
Secure code execution sandbox for Claude — run Python, JavaScript, and shell commands
🔍 Read-only MCP server for secure filesystem exploration, searching, and analysis
Secure filesystem MCP server for reading, writing, searching, diffing, and patching files.
Secure MCP server for WorkBoard OKR and strategy execution platform
Secure encoding-aware filesystem tools with atomic writes, legacy encodings, and typed errors
Securely search and manage workspace context files for AI agents and teams.
RunSec MCP server for workspace security scanning and remediation workflows.
Answers built from our own checks of this server.