mcp-v8 runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 8 Sep 2026.
Run JavaScript and TypeScript in sandboxed V8 isolates with policy-controlled host capabilities.
We read the source, 9 h ago · rules 3dff92dd89df
A value the model can set ends up inside a file or shell call. That is not a flaw by itself — for a terminal server it is the job — but it is where things go wrong when it is not.
std::fs::write(
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
subprocess.check_output(cmd)
execFileSync(process.execPath, ['node_modules/typescript/bin/tsc', '-p', 'tsconfig.build.json'], { stdio: 'inherit' });
Found in continuous integration, deployment or infrastructure files, or in a neighbouring package of the same monorepo. None of this is installed when you add the server: it describes how the project is built and released. We list it because a leaked key in a build pipeline is still a real problem, but it is not something this server does on your machine.
- name: Select matrix package
id: select
env:
EVENT_NAME: ${{ github.event_name }}
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
That is not a flaw by itself — but it is where things go wrong when it is not the job. We re-read this code on every release. Watch it and you hear from us the day another one appears.
Controlled SQL access gateway with policy, cost limits, tenant isolation, and safe tools.
MCP server for Python, JavaScript, and TypeScript code analysis with Ruff, ty, Vulture, and Biome
Code mode (preview): the AI writes a script against a typed foundry.* API and runs it in a sandbox.
A typed, policy-controlled OS capability layer for AI agents.
.NET assembly introspection MCP server with advanced reflection and type analysis capabilities
Host static HTML pages, generate PDFs, screenshots, scrape JS sites, run sandboxed JavaScript.
WasmAgent MCP server — WASM-sandboxed code execution with capability manifests and Tasks API.
High-quality Rust SDK for Model Context Protocol (MCP) with full TypeScript SDK compatibility
Answers built from our own checks of this server.