SkillAgentSearch skills...

rookhold

Run short-lived Python, Node, and Bash with hard limits, live output, and verifiable receipts.

Install / Use

claude mcp add sambai-dev -- npx -y github:sambai-dev/rookhold

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

80/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of rookhold

rookhold scores 80/100 on our quality scale, 1021st of 1,122 Security skills we index.

Its MCP Server is 9.2 KB long, well organised into 14 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.

It has 10 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
4/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 3 days ago, so rookhold is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

rookhold compared with similar skills

All 4 of these similar skills score higher than rookhold; compare them before choosing.

SkillScoreStarsUpdatedFormat
rookhold (this skill)by sambai-dev80103d agoMCP Server
Agent-Reachby Panniantong10093.2ktodayCLAUDE.md
headroomby headroomlabs-ai10074.6ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md
Scraplingby D4Vinci10086.2ktodayMCP Server

Frequently asked questions

How do I install rookhold?
Run claude mcp add sambai-dev -- npx -y github:sambai-dev/rookhold. The install tabs above show the steps for each supported agent.
Which AI agents does rookhold work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is rookhold safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is rookhold still maintained?
The repository was last updated 3 days ago, so rookhold is actively maintained.

Rookhold

Run short-lived Python, Node, and Bash code with hard limits—and keep a verifiable receipt of what happened.

CI Release License

Current release: v0.8.0. Downloads and direct SDK packages are available now. Named PyPI and npm installs remain deferred while maintainer registry accounts are activated.

Rookhold is for applications, agents, evaluators, graders, and automations that receive a short piece of code but should not hand it the host machine. It is a bounded job runner—not a persistent workspace, browser environment, remote IDE, or general-purpose cloud sandbox.

Try Rookhold locally

Choose the complete Rookhold app bundle. It contains the unified rookhold command, remote client, MCP adapter, offline verifier, and setup templates.

| Your computer | App bundle | |---|---| | Windows, 64-bit | Download for Windows | | Mac with Apple Silicon | Download for Mac | | Linux x86_64 | Download for Linux |

Extract the archive, then run one trusted local job:

$ rookhold run python 'print(6 * 7)'
42

status       succeeded
network      host
isolation    none
receipt      saved to .rookhold/runs/019…/receipt.json

WARNING: isolation is none; this run did not contain untrusted code.

On macOS or Linux, run chmod +x rookhold rookhold-cli rookhold-mcp rookhold-verify once after extracting. On Windows, use rookhold.exe.

[!WARNING] With no configured endpoint, rookhold run starts a temporary loopback-only service for code you trust. It has host networking and no sandbox boundary. Do not use this mode for hostile or mutually untrusted code.

Connected to a guarded Linux service, the same command can require and report the gVisor boundary:

$ ROOKHOLD_BASE_URL=https://executor.example \
  ROOKHOLD_API_KEY=repl…[redacted] \
  rookhold run python 'print(6 * 7)' \
    --minimum-isolation gvisor-application-kernel
42

status       succeeded
network      disabled
isolation    gvisor-application-kernel
receipt      saved to .rookhold/runs/019…/receipt.json

The CLI explicitly requests allow_network: false; the guarded service must also report disabled networking and the required isolation class.

Read the quickstart · Deploy the secure boundary · Share 60-second feedback

Add Rookhold to an application

The Rookhold SDK is the client library for your code. It does not create a secure Linux execution boundary by itself; point it at a Rookhold service for untrusted workloads.

Python

Install the v0.8.0 release wheel:

pip install https://github.com/sambai-dev/rookhold/releases/download/v0.8.0/rookhold-0.8.0-py3-none-any.whl
from rookhold import Rookhold

result = Rookhold.from_env().run("python", "print(6 * 7)")
print(result.stdout)

TypeScript

Install the v0.8.0 release tarball:

npm install https://github.com/sambai-dev/rookhold/releases/download/v0.8.0/rookhold-0.8.0.tgz

Named PyPI and npm installs are temporarily deferred while maintainer registry accounts are activated. The release-hosted packages above contain the same SDKs.

import { Rookhold } from "rookhold";

const result = await Rookhold.fromEnv().run({
  language: "python",
  code: "print(6 * 7)",
});
console.log(result.stdout);

Python guide · TypeScript guide · API reference

Connect to an existing Rookhold server

The Rookhold client is the smallest download for a person or MCP host that already has a Rookhold endpoint. It does not include the local service.

| Your computer | Standalone client | |---|---| | Windows, 64-bit | Download the Windows client | | Mac with Apple Silicon | Download the Mac client | | Linux x86_64 | Download the Linux client |

Run it normally for the operator terminal, or register the same file with the mcp-server argument in Claude Code, OpenCode, Hermes, or another MCP host. The model never chooses the service URL, API key, language allowlist, or required isolation class.

rookhold setup claude-code
rookhold setup opencode
rookhold setup hermes

Adding Rookhold does not disable a host's built-in shell or other execution tools. Remove or deny those routes when a model must cross only the Rookhold boundary.

CLI guide · MCP guide · Integration templates

What Rookhold does

For every submitted job, Rookhold:

  1. authenticates the caller and checks admission policy;
  2. applies server-controlled time, memory, process, file, and output limits;
  3. runs the job using the configured execution provider;
  4. preserves bounded output, events, cancellation state, and artifacts; and
  5. records the effective runtime posture and receipt.

The API and persisted store remain the source of truth. The CLI, SDKs, MCP adapter, and dashboard are views over the same contracts.

Three useful recipes

See every recipe or start from the Next.js and FastAPI examples.

Is Rookhold right for the task?

| Use Rookhold for | Keep using the normal workspace for | |---|---| | short generated or user-supplied scripts | editing a repository | | stateless transforms, checks, and evaluators | persistent files and package installation | | jobs needing limits, cancellation, or evidence | browsers, ports, and long-running services | | execution behind a separately controlled API | trusted development already isolated well enough |

Using both is normal. Rookhold owns short execution policy and evidence; it does not replace the rest of an agent or application runtime.

Before running untrusted code

The guarded production profile is Linux x86_64-only. macOS, Windows, and other Linux architectures support only the unisolated same-trust development provider. Production uses a dedicated Linux x86_64 VM, pinned gVisor runsc, a private root filesystem, cgroup v2, scoped credentials, and non-skipping containment checks.

The service container has host-equivalent outer authority even though each job runs inside a separate gVisor workload. Do not place it on a shared multi-tenant Docker host.

Read the security boundary before accepting untrusted jobs.

Documentation

Contributing

Start with CONTRIBUTING.md. The repository separates:

  • Tier A—docs, examples, and integrations;
  • Tier B—SDK, CLI, and public API work; and
  • Tier C—authentication, execution, storage, receipts, and isolation.

Tier A changes should not inherit security-core ceremony. Tier C changes must prove the root invariant, regression, adversarial cases, and final exact-head validation.

Build from source

Prebuilt releases are the normal path. Contributors need Rust 1.98 and the job runtimes they intend to test:

git clone https://github.com/sambai-dev/rookhold.git
cd rookhold
cargo build --locked --workspace

Run the complete checks from CONTRIBUTING.md before opening a pull request.

License

Rookhold is released under the MIT License.

Related Skills

View on GitHub
GitHub Stars10
CategorySecurity
Updated3d ago
Forks0

Languages

Rust

Trust signals

92/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 low1 info
rookhold — MCP Server: Install & Safety Check | SkillAgent