Sandbox Env MCP runs on your own machine — the client starts it, so there is no endpoint to ping. 71 installs a week from pypi. Last commit 20 Sep 2026.
Persistent Docker/SSH sandbox for AI agents: shell exec, file ops, audit log.
We read the source, 19 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
self.exec_oneoff(name, f"rm -rf {shlex.quote(tmp_dir)}")
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
proc = subprocess.run(cmd, capture_output=True, timeout=connect_timeout)
- "${DOCKER_SOCK_PATH:-/var/run/docker.sock}:/var/run/docker.sock"
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Sandbox Env MCP and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add sandbox-env-mcp -- uvx sandbox-env-mcp
{
"mcpServers": {
"sandbox-env-mcp": {
"args": [
"sandbox-env-mcp"
],
"command": "uvx"
}
}
}
[mcp_servers.sandbox-env-mcp]
command = "uvx"
args = ["sandbox-env-mcp"]
{
"mcpServers": {
"sandbox-env-mcp": {
"args": [
"sandbox-env-mcp"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"sandbox-env-mcp": {
"args": [
"sandbox-env-mcp"
],
"command": "uvx"
}
}
}
Governed execution cells for AI agents: Docker/K8s sandboxes with policy, audit, and approvals.
Docker for AI agents — containers, compose stacks, logs and databases, locally or over SSH.
Persistent memory for AI agents — semantic + recency search, ONNX embeddings, Docker Compose.
Rust MCP and CLI server for Docker, host inspection, SSH, logs, ZFS, and safe file operations.
Execution engine for AI agents. 412 modules: browser, file, Docker, data, crypto.
MCP server for Docker — containers, health checks, Compose, logs, monitoring for AI agents
Host, Docker, Compose, SSH, logs, ZFS, and file operations over MCP and CLI.
Hosting for AI agents: your AI client deploys Docker apps to live HTTPS URLs over MCP.
Answers built from our own checks of this server.