Skip to content
mcp/skillhub

Category

Code Execution & Sandboxes MCP servers

289 code execution & sandboxes MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 2 of 7.
  1. Mastyf AImastyf-ai

    Runtime security proxy for MCP that blocks prompt injection, SSRF, shell/SQL injection and credential exfiltration, plus trust scores for npm MCP packages.

    Active21Node.jsstdio
  2. Terminalaybelatchane

    Interact with TUI/CLI applications through a structured terminal state tree with element detection, like Playwright for terminals.

    Stale21Node.jsstdio
  3. Developervertexstudio

    Developer tools for file editing, shell command execution and screen capture.

    Abandoned21Rust
  4. M1ndmaxkle1nz

    The shell around your coding agent: a neuro-symbolic code graph with calibrated trust, via MCP.

    Active21Node.jsstdio
  5. Spotdbaliengiraffe

    Ephemeral data sandbox for AI workflows with guardrails and security

    Stale21Dockerstdio
  6. MCP server that gives AI agents (Claude Code, Cursor, Windsurf) real interactive terminal sessions — run REPLs, SSH, databases, Docker, and any interactive CLI with clean output and smart completion detection

    Stale19Node.jsstdio
  7. ptyraychao-oao

    Interactive PTY sessions for AI agents: local shells, persistent SSH sessions with attach/detach, and serial ports.

    Active19Gostdio
  8. Ironclawironsecco

    Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.

    Active19Dockerstdio
  9. Code Runneraxliupore

    Run code in multiple programming languages locally via Docker.

    Abandoned18Node.js
  10. Term MCP Deepseekothmaneblial

    Approval-first local terminal control: policy-based command planning and approval, DeepSeek as an advisor, and signed execution receipts.

    Maintained18Python
  11. Ostapondoostapondo

    Mac window manager and menu bar utilities: arrange windows across displays, snap to custom zones, save workspaces, window screenshots and on-device OCR.

    Active17Node.jsstdio
  12. Inspect, debug and drive running WPF apps without source changes: visual tree, dependency properties, bindings, DataContext, screenshots, clicks and text input.

    Maintained17.NETstdio
  13. glassfixed-width

    Drive native GUI apps under development: launch, screenshot, read the accessibility tree, inject input, tail logs and diff frames on desktop, Android and iOS.

    Active17Rust
  14. SysKnifelacs-project

    Linux system administration via typed actions instead of shell strings, with a signed audit log, one-time approval receipts and automatic rollback.

    Active16Ruststdio
  15. Octofsmuvon

    Standalone MCP filesystem tools server — view, edit, shell, workdir.

    Active16Node.jsstdio
  16. YADEyusong652

    YADE discrete element method (DEM) simulation: search API docs, run code via a REPL or background tasks, monitor progress and review task history.

    Active15Pythonstdio
  17. GNOME desktop automation via D-Bus: screenshots, window management, mouse and keyboard input, clipboard, workspaces and notifications on GNOME 45 to 49.

    Slowing15Python
  18. Openwandsunnylich

    Read-only desktop context through OpenWand: current selection, clipboard, active window, browser page and screen.

    Active15Python
  19. Untermzhitongblog

    The terminal AI agents can drive: spawn panes, run commands, read screens, scrolling screenshots.

    Active14
  20. Computer Usemunimtechnologies

    Accessibility-first computer use on macOS, Windows and Linux: element IDs instead of pixels, background input, a pointer overlay and its own Chrome tab group.

    Deprecated13Node.jsstdio
  21. Edict Langsowiedu

    Agent-oriented programming language: agents emit a JSON AST that the compiler validates, type- and effect-checks, verifies with Z3/SMT and compiles to WASM.

    Active13Node.jsstdio
  22. Self-hosted SSH and Kubernetes access broker: ephemeral per-operation credentials the model never sees, per-command firewall, human approvals and audit log.

    Active13Dockerstdio
  23. Rizariza-io

    Arbitrary code execution and tool-use platform for LLMs by Riza

    Abandoned13
  24. Tuinvms

    Launch, screenshot and interact with any TUI app.

    Maintained13Node.js
  25. Aletheiavikasny30

    Deterministic pre-execution filter for agent tool calls that blocks scope creep (credential reads, SSRF, destructive shell/SQL) and prompt injection.

    Active12Node.jsstdio
  26. Clawtouchtinqiao-oss

    Physical USB HID keyboard and mouse control via a Raspberry Pi Pico 2: move, click, drag, type, key combos and scroll, with a mock mode for testing.

    Active12Pythonstdio
  27. Execkitblinkingbit-oss

    Stateful, auditable shell sessions over local, SSH and Docker, with secret redaction, output budgeting and a read-only live transcript viewer.

    Active12Pythonstdio
  28. Prolog Reasonerrikarazome

    SWI-Prolog execution for LLMs with CLP(FD), negation as failure and recursion.

    Slowing12Pythonstdio
  29. Cli Execjakenuts

    A powerful CLI command execution MCP server that enables running shell commands with structured output

    Abandoned12Node.jsstdio
  30. Cli Execjakenuts

    A powerful CLI command execution MCP server that enables running shell commands with structured output

    Abandoned12Node.jsstdio
  31. MCP PTY server providing AI agents with real interactive terminal access

    Active12Node.jsstdio
  32. Terminalmkpvishnu

    MCP server for interactive terminal sessions — SSH, REPLs, database CLIs, TUI apps

    Maintained12Pythonstdio
  33. Local command wrapper for AI coding agents: runs shell commands, stores history locally and returns compressed terminal output to reduce context noise.

    Active11Node.jsstdio
  34. dwic — a product designer inside your terminal. MCP server + CLI that audits your design tokens + markup for WCAG contrast failures, mandated-accent drift, and structural gaps, then remembers findings across sessions.

    Active11Node.jsstdio
  35. Remote SSHfaizbawa

    SSH access with persistent sessions, SFTP and port forwarding, with secrets injected via stdin and redacted from output before reaching the LLM.

    Maintained11Python
  36. Pistonalvii147

    Execute code through the Piston remote code execution engine.

    Stale9Python
  37. Shell Execdomdomegg

    Execute bash commands with background job support.

    Active9Node.jsstdioremote
  38. Petsonalitynanami-he

    An MBTI-powered terminal pet companion for Claude Code and OpenClaw.

    Slowing8Node.jsstdio
  39. RLM Toolsstefanoshea

    Persistent Python sandbox for token-efficient codebase exploration in MCP clients

    Stale8Pythonstdio
  40. Cygnus SSHcygnussystems

    SSH control of remote Linux, macOS and Windows servers: line-level file editing, background tasks, sudo, host aliases, and directory and archive operations.

    Active7Pythonstdio
  41. backscrollsoren-achebe

    Search, retrieve and diff the output of past terminal commands, recorded locally with exit codes, cwd and duration, with secret redaction by default.

    Maintained7Gostdio
  42. Aether Codedannyphantomx64

    Uncensored AI coding agent for your terminal — Claude Code alternative with MCP support. Reads code, writes files, runs commands. Drives IDA Pro, Roblox Studio, Wireshark, Blender, and any MCP server. No refusal layer.

    Maintained7Node.jsstdio
  43. Seristacktechxplorelabs

    Run YAML-defined shell command stacks as MCP tools

    Active7stdio
  44. Yapitalismaytuncyildizli

    Drive terminal coding agents by voice, with receipts that never claim more than they proved.

    Maintained7Pythonstdio
  45. SSHhypnosis

    Remote server work via the local OpenSSH client: run commands, transfer files with checksums, search logs and audit hosts, with destructive commands blocked.

    Maintained6Node.jsstdio
  46. Aitermkitepon-rgb

    Persistent terminal MCP with one harness-based launcher for Claude Code, Codex CLI, Grok CLI, and Cursor Agent CLI, plus durable PTYs for SSH, containers, and REPLs.

    Active6Node.jsstdio
  47. Telleroutlooktelleroutlook

    Code-mode MCP server: collapses user-defined tools into code execution plus docs search, sandboxed in node:vm, WASM or remote microVMs.

    Active6Node.js
  48. Wasmagentwasmagent

    WasmAgent MCP server — WASM-sandboxed code execution with capability manifests and Tasks API.

    Active6Node.jsstdio

Related categories