Topic · updated 2026-10-05
Code Execution & Sandboxes MCP servers
68 Code Execution & Sandboxes MCP servers indexed on awesomemcp.in. Every entry links to a live GitHub repository with a known author, is de-duplicated across the official MCP registry and community lists, and carries an automated vulnerability-check badge. Built by @vndee, @babelcloud, @alfonsograziano, @MichaelS1011, @asif-nvc and 63 other authors.
Top 60 Code Execution & Sandboxes MCP servers
Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.
Scan passed
★ 1,129
2026-10-03Gru-sandbox(gbox) is an open source project that provides a self-hostable sandbox for MCP integration or other AI agent usecases.
Scan passed
★ 181
2026-07-16Run JavaScript snippets in isolated Docker sandboxes with on-the-fly npm dependency installation and clean teardown.
Scan passed
★ 157
2025-11-24WASM sandbox for MCP tools. WASI-isolated, fuel/memory/I/O capped, attested.
Scan passed
★ 46
2026-10-05E2B cloud sandboxes: create isolated Linux VMs, clone repos, run commands, manage files and perform git operations without touching the local machine.
Scan passed
★ 4
2026-04-24Read-only access to a self-hosted GeoLens spatial catalog: datasets, features, maps, sandboxed SQL.
Scan passed
★ 270
2026-10-05Run Python in a code sandbox.
Needs review
★ 229
2025-04-17Official MCP Server for Mailtrap
Scan passed
★ 65
2026-10-02Run LLM-generated code in a YepCode sandbox and create custom MCP tools in JavaScript or Python with npm and PyPI packages.
Scan passed
★ 46
2026-03-17Arbitrary code execution and tool-use platform for LLMs by Riza
Needs review
★ 13
2024-12-17Coding agents build full-stack apps in persistent workspaces and share them by link.
Scan passed
★ 3
2026-09-04Coldrig — cold-email infra run by your agent: 28 MCP tools, live sending, free sandbox, from $99/mo.
Scan passed
★ 0
2026-09-25Containerized environments for coding agents: each agent works in its own fresh container and git branch, with execution history and terminal access.
Scan passed
★ 4,056
2026-09-21Connects QGIS Desktop to Claude for prompt-assisted project creation, layer loading and code execution.
Needs review
★ 1,115
2025-10-01Clojure development tools, direct access to the running program via REPL.
Scan passed
★ 782
2026-10-03MCP Server for the Runno Sandbox
Scan passed
★ 773
2026-08-01Stdio MCP bridge for SandBase Harness agents, sessions, turns, artifacts, and cancellation.
Scan passed
★ 683
2026-10-05Access iTerm: run commands and ask questions about what is shown in the terminal.
Needs review
★ 567
2025-09-20Run untrusted Python/JavaScript code in WebAssembly sandboxes.
Scan passed
★ 298
2026-06-19Access any API through its existing OpenAPI documentation.
Scan passed
★ 197
2026-03-21Enhanced Godot 4.5-4.7 MCP: headless+editor+bridge, secure GDScript sandbox, closed-loop AI dev.
Scan passed
★ 99
2026-10-03Gives AI agents eyes and hands into running React Native apps: logs, REPL, tap, screenshots
Scan passed
★ 77
2026-10-04Unified execution environment for Python code, shell commands, and programmatic MCP tool calls
Scan passed
★ 75
2026-06-11Run JavaScript and TypeScript in sandboxed V8 isolates with policy-controlled host capabilities.
Scan passed
★ 59
2026-10-04Paid APIs and tokenized shares for agents. Prepaid funding, including authorized Instinct checkout.
Scan passed
★ 44
2026-09-13Run DeepSeek as a sub-agent in Claude Code or Codex CLI, with its own agent loop for reading, editing and running commands in a sandboxed workspace.
Scan passed
★ 38
2026-10-02Access any API via its OpenAPI specification, with full JSON Schema support for parameters and request bodies.
Scan passed
★ 35
2025-07-15AI-native, open-source CMS (Go) with 128 MCP tools: content, agent sandbox, SEO & AI.
Scan passed
★ 31
2026-10-05Delegate tasks to other AI providers' models, e.g. ask OpenAI to generate an image.
Scan passed
★ 30
2025-05-28Python runtime interpreter that executes submitted code in an isolated environment.
Scan passed
★ 28
2025-10-15Ephemeral data sandbox for AI workflows with guardrails and security
Scan passed
★ 21
2026-10-01Control Google Colab notebooks and assign GPUs (T4/L4/A100). Fork of Google's colab-mcp with all tools visible at startup and Windows support.
Scan passed
★ 20
2026-06-19Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.
Scan passed
★ 19
2026-09-30Start and follow atoma builds; read their runs, traces, agent registry and skill catalogue.
Scan passed
★ 18
2026-10-05Stateful SageMath MCP server with 40 tools and a sandboxed Sage session per client.
Scan passed
★ 16
2026-10-05MCP server giving a coding agent a build→see→interact→debug loop over native GUI apps.
Scan passed
★ 15
2026-09-29Sandboxed computer-use for AI agents: drive real browser + desktop apps in nested X11 windows
Scan passed
★ 13
2026-07-07AI-agent programming language. JSON AST in, WASM out. Typed, effect-tracked, Z3-verified.
Scan passed
★ 12
2026-10-03No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.
Scan passed
★ 11
2026-10-02SWI-Prolog as a logic calculator for LLMs
Scan passed
★ 11
2026-05-01Execute code through the Piston remote code execution engine.
Scan passed
★ 9
2026-02-22Persistent Python sandbox for token-efficient codebase exploration in MCP clients
Scan passed
★ 8
2026-02-13Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code.
Scan passed
★ 8
2026-10-05Test your design on the real thing: load a built web app, turn its knobs, verify 1:1, export.
Scan passed
★ 6
2026-08-30WasmAgent MCP server — WASM-sandboxed code execution with capability manifests and Tasks API.
Scan passed
★ 6
2026-10-05Verifiable cognition: prove a session ledger is tamper-evident; audit & import any agent's logs.
Scan passed
★ 5
2026-06-22Create sandboxed public-unlisted or access-key-protected HTML previews through a remote MCP server.
Scan passed
★ 5
2026-09-25Self-hostable GPU-aware job broker: submit, route by VRAM, babysit jobs across machines via MCP.
Scan passed
★ 4
2026-10-04Self-hosted MCP server: sandboxed browser, desktop, vision, code-edit packs for any agent.
Scan passed
★ 4
2026-09-21Code & logic calculator for AI agents: 31 languages, symbolic math, SMT/logic solving, Big-O.
Scan passed
★ 3
2026-09-24MCP server for the OVH API. Explore and call any OVH endpoint via sandboxed JS.
Scan passed
★ 3
2026-06-15MCP server for the Mailtrap email platform — analytics, sending, contacts, sandbox
Scan passed
★ 3
2026-04-17Secure Python sandbox — MCP servers, APIs, shells and host functions as native Python objects.
Scan passed
★ 3
2026-09-27MATLAB integration: execute code, run async jobs with progress reporting, get interactive Plotly plots and expose custom .m functions as tools.
Scan passed
★ 3
2026-07-13Host-level telemetry gateway letting sandboxed agents fetch container logs and track kernel resource metrics.
Scan passed
★ 3
2026-08-07Execute code in 8 languages (Python, JS, TS, Go, Java, C++, C, Bash) in gVisor sandboxes.
Scan passed
★ 2
2026-04-05CLI framework and stdio MCP server for Flutter: scaffolding, hot reload, REPL, codegen.
Scan passed
★ 2
2026-10-05Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs.
Scan passed
★ 2
2026-08-03Administer a Linux server: read files and logs, manage systemd services and cron jobs, run read-only MySQL queries, WP-CLI, Git and sandboxed Python.
Scan passed
★ 2
2026-07-29Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.
Scan passed
★ 1
2026-07-15
Search all 68 in the interactive index →
Quick install
Add the most popular option to Claude Code:
claude mcp add llm-sandbox -- uvx llm-sandbox
FAQ
What is the best code execution & sandboxes mcp server?
By GitHub stars, the most popular is LLM Sandbox by @vndee (1,129 stars). awesomemcp.in lists 68 MCP servers for this topic, ranked by official status and popularity.
Are these MCP servers safe to install?
64 of 68 passed our automated vulnerability check (OSV.dev advisories for the published package, OpenSSF Scorecard, license, maintenance and provenance). The check is automated and does not guarantee 100% safety — review the code and permissions before installing.
How do I install LLM Sandbox?
With Claude Code: claude mcp add llm-sandbox -- uvx llm-sandbox. Every listing on awesomemcp.in includes an install command and, where available, an mcp.json snippet for Claude Desktop, Cursor and other MCP clients.
Can AI agents read this list?
Yes. The full catalog is available as JSON at https://awesomemcp.in/api/mcps.json and https://awesomemcp.in/api/skills.json, and as plain text at https://awesomemcp.in/llms.txt.