mcp-sandbox
Sandbox any MCP server in one line. Firecracker microVM isolation for Claude Desktop, Cursor, Windsurf, and every MCP client.
Install / Use
claude mcp add declaw-ai -- npx -y github:declaw-ai/mcp-sandboxIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of mcp-sandbox
mcp-sandbox scores 81/100 on our quality scale, 651st of 856 Security skills we index.
Its MCP Server is 6.4 KB long, well organised into 26 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 5 days ago, so mcp-sandbox is actively maintained.
- Our last check on 2026-09-20 found the source still online.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
mcp-sandbox compared with similar skills
All 4 of these similar skills score higher than mcp-sandbox; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| mcp-sandbox (this skill)by declaw-ai | 81 | 3 | 5d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 86.1k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.1k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install mcp-sandbox?
- Run
claude mcp add declaw-ai -- npx -y github:declaw-ai/mcp-sandbox. The install tabs above show the steps for each supported agent. - Which AI agents does mcp-sandbox work with?
- It is written for Claude Code, Claude Desktop, Cursor and Windsurf, as a MCP Server file. Other agents that read the same format can often use it too.
- Is mcp-sandbox safe to use?
- It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is mcp-sandbox still maintained?
- The repository was last updated 5 days ago, so mcp-sandbox is actively maintained.
Skill content
View source on GitHubmcp-sandbox
Sandbox any MCP server in one line. Firecracker microVM isolation for Claude Desktop, Cursor, Windsurf, Claude Code, and every MCP client.
Before / After
Before — no sandbox:
{
"mcpServers": {
"github": {
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-github"],
"env": { "GITHUB_PERSONAL_ACCESS_TOKEN": "ghp_..." }
}
}
}
Your GitHub token is accessible to the MCP server and its entire dependency tree — 847 transitive npm packages running with full host access.
After — sandboxed in a Firecracker microVM:
{
"mcpServers": {
"github": {
"command": "declaw",
"args": ["mcp", "--env", "GITHUB_PERSONAL_ACCESS_TOKEN", "--network-allow", "registry.npmjs.org,api.github.com,github.com,codeload.github.com", "--", "npx", "-y", "@modelcontextprotocol/server-github"],
"env": { "GITHUB_PERSONAL_ACCESS_TOKEN": "ghp_..." }
}
}
}
Same MCP server. Same functionality. But now your token can only reach GitHub — even if a dependency is compromised, it can't exfiltrate credentials anywhere else. Only the env vars you explicitly forward with --env reach the sandbox.
Why
MCP servers that connect to external APIs handle your most sensitive credentials — GitHub tokens, Slack bot tokens, API keys, database credentials. These servers run as subprocesses with full host access: your files, your SSH keys, your network.
This isn't theoretical:
- Claude Desktop Extensions had a zero-click RCE rated CVSS 10/10 (LayerX, Feb 2026)
- Cursor had CVE-2025-54135 (CurXecute, CVSS 9.8) and CVE-2025-54136 (MCPoison, CVSS 8.8)
declaw mcp wraps any stdio MCP server in a Firecracker microVM with network deny-all by default. The server works identically — it just can't reach anything you didn't explicitly allow.
When to use this
declaw mcp is designed for MCP servers that talk to external APIs with credentials:
| Server | Credentials at risk | Why sandbox it |
|--------|-------------------|----------------|
| GitHub | GITHUB_PERSONAL_ACCESS_TOKEN | Token can only reach api.github.com, not exfiltrated elsewhere |
| Slack | SLACK_BOT_TOKEN | Bot token confined to api.slack.com |
| Brave Search | BRAVE_API_KEY | API key confined to api.search.brave.com |
| Database | DATABASE_URL | Connection string can't be sent to external hosts |
| Any API server | API keys, tokens, secrets | Network allowlist = credential containment |
Not a fit for: MCP servers that need local host access (filesystem, SQLite, etc.) — these need your local files to be useful, which a cloud sandbox intentionally prevents.
Install
# macOS / Linux
curl -fsSL https://raw.githubusercontent.com/declaw-ai/declaw-cli/main/install.sh | sh
# or with Go
go install github.com/declaw-ai/declaw-cli/cmd/declaw@latest
# or download binary
# https://github.com/declaw-ai/declaw-cli/releases
Then sign up and authenticate:
# 1. Create a free account at https://console.declaw.ai
# 2. Copy your API key from the dashboard
# 3. Authenticate:
declaw auth login
Client Setup
Claude Desktop
Config path: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
{
"mcpServers": {
"github": {
"command": "declaw",
"args": ["mcp", "--env", "GITHUB_PERSONAL_ACCESS_TOKEN", "--network-allow", "registry.npmjs.org,api.github.com,github.com,codeload.github.com", "--", "npx", "-y", "@modelcontextprotocol/server-github"],
"env": { "GITHUB_PERSONAL_ACCESS_TOKEN": "ghp_..." }
}
}
}
Cursor
Config path: ~/.cursor/mcp.json — same JSON structure as above.
Windsurf
Config path: ~/.codeium/windsurf/mcp_config.json — same JSON structure as above.
Claude Code
claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=ghp_... -- declaw mcp --env GITHUB_PERSONAL_ACCESS_TOKEN --network-allow registry.npmjs.org,api.github.com,github.com,codeload.github.com -- npx -y @modelcontextprotocol/server-github
Examples
See examples/ for ready-to-use configs:
github— GitHub API (repos, issues, PRs, code search)brave-search— Web search via Brave Search APIfetch— Web content fetching and conversion
How it works
declaw mcp is a transparent stdio forwarder. It creates a Firecracker microVM, starts the MCP server inside it, and forwards JSON-RPC messages between the MCP client and the sandboxed server. The client doesn't know anything changed. The server doesn't know it's sandboxed.
Network is deny-all by default. Use --network-allow to open specific hosts the server needs. This is the key security property: credentials passed to the server can only reach hosts you explicitly permit.
Flags
| Flag | Default | Description |
|------|---------|-------------|
| --network-allow <hosts> | deny-all | Comma-separated outbound hostname allowlist |
| --template <name> | mcp-server | Sandbox template (default includes Node.js + Python) |
| --timeout <seconds> | 86400 | Sandbox timeout (default 24h) |
| --env KEY or --env KEY=VAL | — | Environment variable to forward (repeatable). KEY reads from host env; KEY=VAL sets explicitly. |
| --verbose | off | Diagnostic logging to stderr |
Custom dependencies
The default mcp-server template includes Node.js and Python, which covers most MCP servers. If your server needs additional system packages (e.g., ffmpeg, native libraries), build a custom template:
# Create a Dockerfile
echo 'FROM declaw/mcp-server:latest
RUN apt-get update && apt-get install -y ffmpeg' > Dockerfile
# Build it (returns a template ID)
declaw template build --dockerfile Dockerfile
# Use the template ID from the build output
declaw mcp --template <template-id> -- your-server-command
See declaw template build --help for details.
Links
License
Apache 2.0
Related Skills
Agent-Reach
86.1kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.1kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.5k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
