Home / Topics / Code Execution & Sandboxes MCP servers

Topic · updated 2026-10-05

Code Execution & Sandboxes MCP servers

68 Code Execution & Sandboxes MCP servers indexed on awesomemcp.in. Every entry links to a live GitHub repository with a known author, is de-duplicated across the official MCP registry and community lists, and carries an automated vulnerability-check badge. Built by @vndee, @babelcloud, @alfonsograziano, @MichaelS1011, @asif-nvc and 63 other authors.

68servers
64scan passed
7official
26one-click install

Top 60 Code Execution & Sandboxes MCP servers

  1. by @vndee · Python · vndee/llm-sandbox

    Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.

    Scan passed
    ★ 1,129
    2026-10-03
  2. Gru-sandbox(gbox) is an open source project that provides a self-hostable sandbox for MCP integration or other AI agent usecases.

    Scan passed
    ★ 181
    2026-07-16
  3. Run JavaScript snippets in isolated Docker sandboxes with on-the-fly npm dependency installation and clean teardown.

    Scan passed
    ★ 157
    2025-11-24
  4. WASM sandbox for MCP tools. WASI-isolated, fuel/memory/I/O capped, attested.

    Scan passed
    ★ 46
    2026-10-05
  5. E2B cloud sandboxes: create isolated Linux VMs, clone repos, run commands, manage files and perform git operations without touching the local machine.

    Scan passed
    ★ 4
    2026-04-24
  6. by @geolens-io · official · Python · geolens-io/geolens

    Read-only access to a self-hosted GeoLens spatial catalog: datasets, features, maps, sandboxed SQL.

    Scan passed
    ★ 270
    2026-10-05
  7. by @jamsocket · official · Rust · jamsocket/forevervm

    Run Python in a code sandbox.

    Needs review
    ★ 229
    2025-04-17
  8. by @mailtrap · official · TypeScript · mailtrap/mailtrap-mcp

    Official MCP Server for Mailtrap

    Scan passed
    ★ 65
    2026-10-02
  9. by @yepcode · official · TypeScript · yepcode/mcp-server-js

    Run LLM-generated code in a YepCode sandbox and create custom MCP tools in JavaScript or Python with npm and PyPI packages.

    Scan passed
    ★ 46
    2026-03-17
  10. by @riza-io · official · JavaScript · riza-io/riza-mcp

    Arbitrary code execution and tool-use platform for LLMs by Riza

    Needs review
    ★ 13
    2024-12-17
  11. by @Reachpad · official · TypeScript · Reachpad/reachpad-mcp

    Coding agents build full-stack apps in persistent workspaces and share them by link.

    Scan passed
    ★ 3
    2026-09-04
  12. by @YS-projectcalc · official · TypeScript · YS-projectcalc/agent-cold-email

    Coldrig — cold-email infra run by your agent: 28 MCP tools, live sending, free sandbox, from $99/mo.

    Scan passed
    ★ 0
    2026-09-25
  13. Containerized environments for coding agents: each agent works in its own fresh container and git branch, with execution history and terminal access.

    Scan passed
    ★ 4,056
    2026-09-21
  14. Connects QGIS Desktop to Claude for prompt-assisted project creation, layer loading and code execution.

    Needs review
    ★ 1,115
    2025-10-01
  15. by @bhauman · Clojure · bhauman/clojure-mcp

    Clojure development tools, direct access to the running program via REPL.

    Scan passed
    ★ 782
    2026-10-03
  16. by @taybenlor · TypeScript · taybenlor/runno

    MCP Server for the Runno Sandbox

    Scan passed
    ★ 773
    2026-08-01
  17. Stdio MCP bridge for SandBase Harness agents, sessions, turns, artifacts, and cancellation.

    Scan passed
    ★ 683
    2026-10-05
  18. Access iTerm: run commands and ask questions about what is shown in the terminal.

    Needs review
    ★ 567
    2025-09-20
  19. Run untrusted Python/JavaScript code in WebAssembly sandboxes.

    Scan passed
    ★ 298
    2026-06-19
  20. Access any API through its existing OpenAPI documentation.

    Scan passed
    ★ 197
    2026-03-21
  21. Enhanced Godot 4.5-4.7 MCP: headless+editor+bridge, secure GDScript sandbox, closed-loop AI dev.

    Scan passed
    ★ 99
    2026-10-03
  22. Gives AI agents eyes and hands into running React Native apps: logs, REPL, tap, screenshots

    Scan passed
    ★ 77
    2026-10-04
  23. Unified execution environment for Python code, shell commands, and programmatic MCP tool calls

    Scan passed
    ★ 75
    2026-06-11
  24. Run JavaScript and TypeScript in sandboxed V8 isolates with policy-controlled host capabilities.

    Scan passed
    ★ 59
    2026-10-04
  25. by @vaaya-ai · JavaScript · vaaya-ai/vaaya-mcp

    Paid APIs and tokenized shares for agents. Prepaid funding, including authorized Instinct checkout.

    Scan passed
    ★ 44
    2026-09-13
  26. Run DeepSeek as a sub-agent in Claude Code or Codex CLI, with its own agent loop for reading, editing and running commands in a sandboxed workspace.

    Scan passed
    ★ 38
    2026-10-02
  27. Access any API via its OpenAPI specification, with full JSON Schema support for parameters and request bodies.

    Scan passed
    ★ 35
    2025-07-15
  28. AI-native, open-source CMS (Go) with 128 MCP tools: content, agent sandbox, SEO & AI.

    Scan passed
    ★ 31
    2026-10-05
  29. Delegate tasks to other AI providers' models, e.g. ask OpenAI to generate an image.

    Scan passed
    ★ 30
    2025-05-28
  30. Python runtime interpreter that executes submitted code in an isolated environment.

    Scan passed
    ★ 28
    2025-10-15
  31. Ephemeral data sandbox for AI workflows with guardrails and security

    Scan passed
    ★ 21
    2026-10-01
  32. Control Google Colab notebooks and assign GPUs (T4/L4/A100). Fork of Google's colab-mcp with all tools visible at startup and Windows support.

    Scan passed
    ★ 20
    2026-06-19
  33. Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.

    Scan passed
    ★ 19
    2026-09-30
  34. by @mgtf · TypeScript · mgtf/atoma

    Start and follow atoma builds; read their runs, traces, agent registry and skill catalogue.

    Scan passed
    ★ 18
    2026-10-05
  35. Stateful SageMath MCP server with 40 tools and a sandboxed Sage session per client.

    Scan passed
    ★ 16
    2026-10-05
  36. MCP server giving a coding agent a build→see→interact→debug loop over native GUI apps.

    Scan passed
    ★ 15
    2026-09-29
  37. Sandboxed computer-use for AI agents: drive real browser + desktop apps in nested X11 windows

    Scan passed
    ★ 13
    2026-07-07
  38. by @Sowiedu · TypeScript · Sowiedu/Edict

    AI-agent programming language. JSON AST in, WASM out. Typed, effect-tracked, Z3-verified.

    Scan passed
    ★ 12
    2026-10-03
  39. No-KYC managed MCP for AI agents: sandboxed TypeScript trading SDK, isolated sub-accounts, futures.

    Scan passed
    ★ 11
    2026-10-02
  40. SWI-Prolog as a logic calculator for LLMs

    Scan passed
    ★ 11
    2026-05-01
  41. Execute code through the Piston remote code execution engine.

    Scan passed
    ★ 9
    2026-02-22
  42. Persistent Python sandbox for token-efficient codebase exploration in MCP clients

    Scan passed
    ★ 8
    2026-02-13
  43. Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code.

    Scan passed
    ★ 8
    2026-10-05
  44. by @Ideelab · TypeScript · Ideelab/uisandbox

    Test your design on the real thing: load a built web app, turn its knobs, verify 1:1, export.

    Scan passed
    ★ 6
    2026-08-30
  45. WasmAgent MCP server — WASM-sandboxed code execution with capability manifests and Tasks API.

    Scan passed
    ★ 6
    2026-10-05
  46. Verifiable cognition: prove a session ledger is tamper-evident; audit & import any agent's logs.

    Scan passed
    ★ 5
    2026-06-22
  47. Create sandboxed public-unlisted or access-key-protected HTML previews through a remote MCP server.

    Scan passed
    ★ 5
    2026-09-25
  48. by @musharna · Python · musharna/jobd

    Self-hostable GPU-aware job broker: submit, route by VRAM, babysit jobs across machines via MCP.

    Scan passed
    ★ 4
    2026-10-04
  49. Self-hosted MCP server: sandboxed browser, desktop, vision, code-edit packs for any agent.

    Scan passed
    ★ 4
    2026-09-21
  50. Code & logic calculator for AI agents: 31 languages, symbolic math, SMT/logic solving, Big-O.

    Scan passed
    ★ 3
    2026-09-24
  51. MCP server for the OVH API. Explore and call any OVH endpoint via sandboxed JS.

    Scan passed
    ★ 3
    2026-06-15
  52. by @pijusz · TypeScript · pijusz/mcp-mailtrap

    MCP server for the Mailtrap email platform — analytics, sending, contacts, sandbox

    Scan passed
    ★ 3
    2026-04-17
  53. Secure Python sandbox — MCP servers, APIs, shells and host functions as native Python objects.

    Scan passed
    ★ 3
    2026-09-27
  54. MATLAB integration: execute code, run async jobs with progress reporting, get interactive Plotly plots and expose custom .m functions as tools.

    Scan passed
    ★ 3
    2026-07-13
  55. Host-level telemetry gateway letting sandboxed agents fetch container logs and track kernel resource metrics.

    Scan passed
    ★ 3
    2026-08-07
  56. Execute code in 8 languages (Python, JS, TS, Go, Java, C++, C, Bash) in gVisor sandboxes.

    Scan passed
    ★ 2
    2026-04-05
  57. CLI framework and stdio MCP server for Flutter: scaffolding, hot reload, REPL, codegen.

    Scan passed
    ★ 2
    2026-10-05
  58. Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs.

    Scan passed
    ★ 2
    2026-08-03
  59. Administer a Linux server: read files and logs, manage systemd services and cron jobs, run read-only MySQL queries, WP-CLI, Git and sandboxed Python.

    Scan passed
    ★ 2
    2026-07-29
  60. Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.

    Scan passed
    ★ 1
    2026-07-15

Search all 68 in the interactive index →

Quick install

Add the most popular option to Claude Code:

claude mcp add llm-sandbox -- uvx llm-sandbox

FAQ

What is the best code execution & sandboxes mcp server?

By GitHub stars, the most popular is LLM Sandbox by @vndee (1,129 stars). awesomemcp.in lists 68 MCP servers for this topic, ranked by official status and popularity.

Are these MCP servers safe to install?

64 of 68 passed our automated vulnerability check (OSV.dev advisories for the published package, OpenSSF Scorecard, license, maintenance and provenance). The check is automated and does not guarantee 100% safety — review the code and permissions before installing.

How do I install LLM Sandbox?

With Claude Code: claude mcp add llm-sandbox -- uvx llm-sandbox. Every listing on awesomemcp.in includes an install command and, where available, an mcp.json snippet for Claude Desktop, Cursor and other MCP clients.

Can AI agents read this list?

Yes. The full catalog is available as JSON at https://awesomemcp.in/api/mcps.json and https://awesomemcp.in/api/skills.json, and as plain text at https://awesomemcp.in/llms.txt.

Related topics