Skip to content
mcp/skillhub

Category

Code Execution & Sandboxes MCP servers

289 code execution & sandboxes MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 4 of 7.
  1. Aicommanderaicommander-dev

    Outbound-only remote shell, detached long-running jobs and temporary file transfer for AI agents, without exposing SSH, ports or a VPN.

    Active1Node.js
  2. Androidneem2004

    ADB-based Android access: read-only logcat, UI hierarchy, package listing and allowlisted shell commands.

    Active1Node.js
  3. Read-only local code graph for Rust, Cangjie, ArkTS, TS/JS, C/C++, Python and Shell: call graphs, quality gates, change review and impact analysis.

    Active1Rust
  4. Single exec tool running caller Python in a network-isolated locked-down sandbox.

    Maintained1Dockerstdio
  5. FIXSIMgammathreetrading

    Test FIX from Claude, ChatGPT, or Cursor: free sandbox FIX sessions or your own FIXSIM instances.

    Active1remote
  6. Freezetextjuergenkoller-software

    Screen OCR on macOS via FreezeText: freeze the screen and extract text with Apple Vision, OCR regions or images, and search capture history.

    Slowing1
  7. Godotsterion66

    The most complete Godot 4 MCP: secure sandbox, 40+ tools (projects–runtime), major MCP clients.

    Slowing1Pythonstdio
  8. Rent real GPUs from the terminal. Per-second billing, $0.50 minimum. stdio MCP server.

    Active1Node.jsstdioremote
  9. Kenweakenwea-protocol

    Signed sandbox verdicts on any artifact, plus an agent marketplace. No key, no signup, no payment.

    Active1Node.jsstdioremote
  10. Keyholel-jovi

    Give a private ChatGPT app access to selected local folders through OpenAI Secure MCP Tunnel, with per-folder permissions, hash-checked edits and recovery. No shell or public port.

    Active1Python
  11. Logwork Helpertructran2598

    Local-first MCP server and terminal CLI for safe Resource Optimiser logwork automation.

    Active1Node.jsstdio
  12. Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.

    Maintained1Node.jsstdioremote
  13. Nemetonjuergenkoller-software

    Control Nemeton, a macOS virtual machine manager built on Apple's Virtualization framework: Linux and macOS VMs, APFS snapshots, console, files and networking.

    Slowing1
  14. ProfitPlayjarvismaximum-hue

    MCP server for the live ProfitPlay BTC five-minute AI agent sandbox

    Maintained1Dockerstdio
  15. Sandboxed Python execution for AI agents. PEP 723 inline deps, multi-version Python, zero pollution.

    Stale1Pythonstdio
  16. Sanctions API docs and request validation, with account-linked synthetic sandbox testing.

    Active1remote
  17. Persistent Docker/SSH sandbox for AI agents: shell exec, file ops, audit log.

    Active1Pythonstdio
  18. SecHelixomarmohelal

    Evidence-first security review of authorized repositories. Read-only, root-confined, no shell.

    Active1Pythonstdio
  19. Money, FX, capital-market and metadata-only China macro evidence with source clocks and limits.

    Active1Pythonstdioremote
  20. Shieldrob925

    Static security scanner for MCP servers and agent tools: detects secrets, shell execution, risky tool descriptions, environment access and prompt injection.

    Maintained1Python
  21. Terrariumchryaner

    Fork, break and revert VirtualBox VMs with linked clones and RAM snapshots, and drive GUI-only guests via screenshots and input without SSH or a guest agent.

    Active1Go
  22. Turnbackmfaizr77

    Undo a coding agent turn, including shell commands and untracked files.

    Active1Node.jsstdio
  23. Vaultshellsowhati

    Injects secrets into shell commands at exec time; plaintext never reaches the LLM context

    Active1Dockerstdio
  24. Can Seehurleysk

    MCP server that gives AI agents eyes on your terminal — PNG screenshots, visual diffs, GIF recording, and full keyboard/text interaction

    Slowing0Node.jsstdio
  25. EverThreadpb-digital-llc

    Check a website's security in plain English from the terminal, or give your AI agent the tool. Free, no key.

    Active0Node.jsstdio
  26. Glasswarpglasswarp

    See and control your own Windows PC locally or remotely: UIA and screenshot observation, clicking, typing, dragging, scrolling, launching apps and Live View.

    Maintained0Node.jsremote
  27. Heliographdbhq-uk

    Run commands on machines you cannot SSH into, such as air-gapped or bastion-only hosts, via git, file shares or S3, with timestamped run logs.

    Active0Node.jsstdio
  28. INITE Clubinite-ai

    The INITE Club from a terminal: ask a member agent a question with no account, join as a member, or run as the MCP server your editor connects through.

    Active0Node.jsstdioremote
  29. Mac Controldockndevai

    Full Mac control: shell, AppleScript, files, processes and human-like GUI input with a screenshot loop, plus an optional safe mode with read-only, gated access.

    Active0Node.jsstdio
  30. Plaidpipeworx-io

    Plaid MCP — wraps Plaid Sandbox API (sandbox.plaid.com)

    Active0Node.jsstdioremote
  31. Sandbox as a Servicefstandhartinger

    Dedicated Linux VM sandboxes for untrusted, model-generated code: run commands, move files, expose a preview URL and destroy the VM.

    Maintained0Node.jsstdio
  32. ToolRouterhumanleap

    MCP server + CLI for ToolRouter — discover, search, and call AI tools from any agent or terminal

    Maintained0Node.jsstdioremote
  33. Webhook Toolkitthe-kipdev

    Receive, inspect, forward, sign and verify webhooks from your terminal, your test suite and your AI agent (CLI + library + MCP server).

    Active0Node.jsstdioremote
  34. WinCtlsitharaj88

    WinCtl — full Windows desktop control for Claude and other MCP clients: screen capture, UI Automation, synthetic input, window and process management, files and shell, behind tiered permissions with audit logging.

    Maintained0Node.jsstdio
  35. macOSdockndevai

    Read-only-by-default Mac control: files, processes, screenshots and clipboard, with opt-in allowlisted shell commands, AppleScript and GUI input.

    Active0Node.jsstdio
  36. Ask probe402's public record about an x402 endpoint before an agent pays it, and re-check a published archive head from a terminal. Reads public surfaces of probe402.com only.

    Active0Node.jsstdio
  37. sudo-proxytarides

    Run privileged commands locally or over SSH, each gated by a single-keypress human approval before sudo, with audit logging and no stored password.

    Active0Ruststdio
  38. Agent Replomaclaren

    pi-repl's shared tmux REPLs (Python, Julia, R and more) for Claude Code, Codex, OpenCode and other agents, over MCP and a CLI.

    Active0Node.jsstdio
  39. Secure Python sandbox for data optimization and Matplotlib rendering via x402 microtransactions.

    Maintained0Pythonstdio
  40. Verified merchants accepting agentic payments on Lightning/L402/BOLT12/USDT — search, verify, pay.

    Active0remote
  41. Aviation accident report parsing and prompt generation service under the SHELL framework.

    Maintained0Pythonstdio
  42. Blast Scopeatharva-jayappa

    Contextual blast-radius scoring for shell commands an AI agent is about to run

    Maintained0Pythonstdio
  43. Burrowboxburrowbox

    Persistent Linux computers for AI agents: desktop, signed-in browser, vault, apps and shell.

    Active0remote
  44. GTIN product search and feeds with tracked affiliate links, programs and deals. Free sandbox key.

    Active0remote
  45. CloudeIDEcloudeide

    Deploy from your terminal, and give an AI coding agent the same abilities over MCP.

    Active0Node.jsstdio
  46. Execute Python, JavaScript, SQL code in a sandbox. x402 micropayment.

    Maintained0remote
  47. Run AI customer support from your terminal: conversations, knowledge base, and chat widget.

    Maintained0remote
  48. Devxident-io

    Xident build-time MCP server — docs lookup, sandbox test verifications, webhook debugging.

    Maintained0Node.jsstdio

Related categories