sandbox

40 servers · 3,208★ total

An open-source, PyTorch-like runtime for dynamic multi-agent and multi-session workflows.

Open-source CMA-compatible agent runtime for any model, with MCP tools, sandboxed sessions, audit, replay, and a local console. Includes a native DeepSeek Harness bundle over stdio MCP.

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

Open-source agent runtime — SSH-native isolation, eBPF egress policy, Kubernetes + LXC backends, GPU passthrough, MCP-native CLI

The enterprise gateway for autonomous agents. Identity management, per-channel isolation, credential vault, per-session tamper-evident audit log.

A Model Context Protocol (MCP) server that enables LLMs to run ANY code safely in isolated Docker containers.

Isolated Linux desktop workspaces for AI agents — a hidden, agent-owned desktop and browser over MCP, so an agent can do GUI and web work without touching your real desktop.

Lightweight Linux sandbox for AI agents. Kernel-native isolation (namespaces, cgroups, seccomp, Landlock) with REST API, MCP bridge, and web dashboard. Single Rust binary.

Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.

OpenHermit is the open-source platform for deploying fleets of AI agents as production services — durable state, sandboxed execution, managed at scale, and the channels you already use.

Verifiable and free cloud compute for AI agents. webMCP + MCP native. Check out our sandboxed Beta + research in the README

Local-first security scanner, MCP protocol inspector, dynamic fuzzer, Docker sandbox, and report generator for Model Context Protocol servers.

Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across MalwareBazaar, ThreatFox, URLhaus, Feodo, URLScan & VirusTotal — straight from Claude. BYOK, async, MITRE ATT&CK.

Agent-first, English-canonical handbook for DeepSeek Harness with multilingual foundations, source-backed guides, and production runbooks.

A trustless MCP server that replaces the generic shell tool with validated, sandboxed, purpose-built execution tools for AI coding agents.

Optimized, auditable execution for Codex and Claude Code: bounded repository context, verified patches, and reproducible paired benchmarks.

Sandboxed computer-use MCP — drive a real browser + desktop apps in a nested X11 window.

MCP server for Claude Desktop and other Model Context Protocol clients — sandboxed filesystem access (read/write/edit/search) plus Dev Mode-gated shell command execution, scoped to a single workspace root. Local-first, no cloud dependency, full audit logging. Built in TypeScript.

🔪 Open-source safety firewall for AI agents. Intercepts tool calls before they execute, enforces YAML policies, and kills dangerous operations in real-time. Works with OpenAI, Anthropic, LangChain, and MCP. She doesn't guard. She kills.

CLI for benchmarks & evals of AI coding agents — on tasks you already understand, using your Claude / Codex / Gemini individual subscriptions or API keys.

A Programmatic Tool Calling MCP Server allowing AI agents to build and (re)use their own API interface stack tools.

Open-source AI coding agent that survives interruptions, runs in a native sandbox, and proves its changes.

Agent-first CLI and MCP bridge for 2,000+ AI models, multimodal generation, sandboxes, and agent workflows—one command, one account.

Your dashboard is data. Any AI can build it; any human can edit it. A protocol + runtime for agent-composable dashboards — layout-as-data, one guarded control plane, sandboxed agent-authored widgets, MCP server included.

Give any AI a real computer. Open source MCP server with Ubuntu sandbox, browser automation, desktop control, and 30+ tools. Works with Claude Code, Cursor, Claude Desktop.

MCP server for FortiManager using the Code Mode pattern — 2 tools (search + execute) with QuickJS WASM sandbox instead of 590+ individual API tools

Give ChatGPT fast, safe, and auditable visibility into your VPS through MCP.

A fast, OS-sandboxed Model Context Protocol gateway with an embedded Code Mode engine and shell-output token compression, in a single Rust binary.

Turn any JavaScript module into a sandboxed MCP (Model Context Protocol) server with automatic reflection and type inference.

Compression Runtime for Universal eXecution — a 60–95% token reducer for AI coding agents (Claude Code, Cursor, Cline, …). Single Rust binary, SQLite, 11 layers, local-first.

Enterprise orchestration engine for Agentic AI. Instantly deploy highly-scalable, headless visual sandboxes for full computer automation.

Agent Run Config — an open specification for declaring, packaging, securing, and sharing portable, governed AI agents. Like a Dockerfile for agents: one reviewable Agentfile for identity, tools, boundaries, policy, and OCI packaging.

OmniBridge is an MCP server that gives AI agents an ephemeral, gVisor-isolated sandbox to run, test, and cryptographically prove their code works — before it ever reaches production.

Programmatic tool calling / Code Mode for MCP — turn any OpenAPI spec into two sandboxed tools (search + execute).

Sandbox any MCP server in one line. Firecracker microVM isolation for Claude Desktop, Cursor, Windsurf, and every MCP client.

Cage untrusted MCP servers in containers, compose them into agents, and share them over any OCI registry. Signed, sandboxed, no Docker required.

Command-line interface for Declaw — security-first sandboxing for AI agents

Autonomous AI agents inside a Qubes-isolated sandbox - tag-scoped Admin API access with dom0-mediated trust boundary.

Static MCP: your tools are files, not servers. Hash-verified static skills executed sandboxed on demand (QuickJS-wasm on Cloudflare Workers) + llms.txt gateway

Local-first MCP server that gives sandboxed Codex a narrow, auditable Git workflow surface.