Ironclaw runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 16 Sep 2026.
Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.
We read the source, 22 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
return filepath.Join(resolved, rel)
Lost it? Stop the stack, delete ${TOKEN_FILE} from the
- /var/run/docker.sock:/var/run/docker.sock
const defaultTelegramBaseURL = "https://api.telegram.org"
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Run AI-generated code safely. gVisor-isolated Python/JS sandboxes for any MCP client. Pay per run.
Secure code execution sandbox for Claude — run Python, JavaScript, and shell commands
Persistent Docker/SSH sandbox for AI agents: shell exec, file ops, audit log.
JSON-first Coreutils CLI for AI agents. 114 commands with sandbox, dry-run, and MCP support.
Rust MCP server and CLI for Arcane Docker and container management.
Run and manage H Company's Computer-Use Agents from any MCP client.
MCP server for executing shell commands on remote hosts via SSH.
Contextual blast-radius scoring for shell commands an AI agent is about to run
Answers built from our own checks of this server.