
LLM Sandbox MCP Server
by vndeeio.github.vndee/llm-sandboxv0.3.43
Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.
context tax
queued
security
queued
cold start
queued
freshness
Active9d ago
Install LLM Sandbox MCP server
Install in Claude Code
claude mcp add llm-sandbox -- uvx llm-sandboxInstall in Cursor
{
"mcpServers": {
"llm-sandbox": {
"command": "uvx",
"args": [
"llm-sandbox"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"llm-sandbox": {
"command": "uvx",
"args": [
"llm-sandbox"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"llm-sandbox": {
"type": "stdio",
"command": "uvx",
"args": [
"llm-sandbox"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"llm-sandbox": {
"command": "uvx",
"args": [
"llm-sandbox"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| BACKEND | — | — | Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s. |
| DOCKER_HOST | — | — | Docker or Podman socket URL, e.g. unix:///var/run/docker.sock |
| KUBECONFIG | — | — | Path to kubeconfig file when BACKEND=kubernetes. |
| NAMESPACE | — | — | Kubernetes namespace used for sandbox pods when BACKEND=kubernetes. |
| COMMIT_CONTAINER | — | — | Commit the container after a run so installed libraries persist between sessions. |
| KEEP_TEMPLATE | — | — | Keep the base image after the session ends to avoid re-pulling it on the next run. |
| SANDBOX_NETWORK_MODE | — | — | Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only. |
| SANDBOX_READ_ONLY | — | — | Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only. |
| SANDBOX_CAP_DROP | — | — | Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only. |
| SANDBOX_SECURITY_OPT | — | — | Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only. |
| SANDBOX_MEMORY | — | — | Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only. |
| SANDBOX_CPUS | — | — | Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only. |
Freshness
Active — last maintenance signal 9d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-01 · 9d ago · GitHub
Latest release
2026-09-28 · 12d ago · GitHub · 0.3.45
Package published
no data · npm/PyPI
Registry entry updated
2026-08-03 · 2mo ago · official registry · v0.3.43
FAQ
›How do I install the LLM Sandbox MCP server in Claude Code?
Run: claude mcp add llm-sandbox -- uvx llm-sandbox. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does LLM Sandbox require an API key?
No required environment variables are declared in its published metadata.
›Can I use LLM Sandbox as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is LLM Sandbox in the official MCP registry?
Yes, as io.github.vndee/llm-sandbox.
Alternatives to LLM Sandbox
Other ai & llm tools MCP servers.