rookhold
Run short-lived Python, Node, and Bash with hard limits, live output, and verifiable receipts.
Install / Use
claude mcp add sambai-dev -- npx -y github:sambai-dev/rookholdIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of rookhold
rookhold scores 80/100 on our quality scale, 1021st of 1,122 Security skills we index.
Its MCP Server is 9.2 KB long, well organised into 14 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 3 days ago, so rookhold is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
rookhold compared with similar skills
All 4 of these similar skills score higher than rookhold; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| rookhold (this skill)by sambai-dev | 80 | 10 | 3d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 93.2k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.2k | today | MCP Server |
Frequently asked questions
- How do I install rookhold?
- Run
claude mcp add sambai-dev -- npx -y github:sambai-dev/rookhold. The install tabs above show the steps for each supported agent. - Which AI agents does rookhold work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is rookhold safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is rookhold still maintained?
- The repository was last updated 3 days ago, so rookhold is actively maintained.
Skill content
View source on GitHubRookhold
Run short-lived Python, Node, and Bash code with hard limits—and keep a verifiable receipt of what happened.
Current release: v0.8.0. Downloads and direct SDK packages are available now. Named PyPI and npm installs remain deferred while maintainer registry accounts are activated.
Rookhold is for applications, agents, evaluators, graders, and automations that receive a short piece of code but should not hand it the host machine. It is a bounded job runner—not a persistent workspace, browser environment, remote IDE, or general-purpose cloud sandbox.
Try Rookhold locally
Choose the complete Rookhold app bundle. It contains
the unified rookhold command, remote client, MCP adapter, offline verifier,
and setup templates.
| Your computer | App bundle | |---|---| | Windows, 64-bit | Download for Windows | | Mac with Apple Silicon | Download for Mac | | Linux x86_64 | Download for Linux |
Extract the archive, then run one trusted local job:
$ rookhold run python 'print(6 * 7)'
42
status succeeded
network host
isolation none
receipt saved to .rookhold/runs/019…/receipt.json
WARNING: isolation is none; this run did not contain untrusted code.
On macOS or Linux, run chmod +x rookhold rookhold-cli rookhold-mcp rookhold-verify once after extracting. On Windows, use rookhold.exe.
[!WARNING] With no configured endpoint,
rookhold runstarts a temporary loopback-only service for code you trust. It has host networking and no sandbox boundary. Do not use this mode for hostile or mutually untrusted code.
Connected to a guarded Linux service, the same command can require and report the gVisor boundary:
$ ROOKHOLD_BASE_URL=https://executor.example \
ROOKHOLD_API_KEY=repl…[redacted] \
rookhold run python 'print(6 * 7)' \
--minimum-isolation gvisor-application-kernel
42
status succeeded
network disabled
isolation gvisor-application-kernel
receipt saved to .rookhold/runs/019…/receipt.json
The CLI explicitly requests allow_network: false; the guarded service must
also report disabled networking and the required isolation class.
Read the quickstart · Deploy the secure boundary · Share 60-second feedback
Add Rookhold to an application
The Rookhold SDK is the client library for your code. It does not create a secure Linux execution boundary by itself; point it at a Rookhold service for untrusted workloads.
Python
Install the v0.8.0 release wheel:
pip install https://github.com/sambai-dev/rookhold/releases/download/v0.8.0/rookhold-0.8.0-py3-none-any.whl
from rookhold import Rookhold
result = Rookhold.from_env().run("python", "print(6 * 7)")
print(result.stdout)
TypeScript
Install the v0.8.0 release tarball:
npm install https://github.com/sambai-dev/rookhold/releases/download/v0.8.0/rookhold-0.8.0.tgz
Named PyPI and npm installs are temporarily deferred while maintainer registry accounts are activated. The release-hosted packages above contain the same SDKs.
import { Rookhold } from "rookhold";
const result = await Rookhold.fromEnv().run({
language: "python",
code: "print(6 * 7)",
});
console.log(result.stdout);
Python guide · TypeScript guide · API reference
Connect to an existing Rookhold server
The Rookhold client is the smallest download for a person or MCP host that already has a Rookhold endpoint. It does not include the local service.
| Your computer | Standalone client | |---|---| | Windows, 64-bit | Download the Windows client | | Mac with Apple Silicon | Download the Mac client | | Linux x86_64 | Download the Linux client |
Run it normally for the operator terminal, or register the same file with the
mcp-server argument in Claude Code, OpenCode, Hermes, or another MCP host.
The model never chooses the service URL, API key, language allowlist, or
required isolation class.
rookhold setup claude-code
rookhold setup opencode
rookhold setup hermes
Adding Rookhold does not disable a host's built-in shell or other execution tools. Remove or deny those routes when a model must cross only the Rookhold boundary.
CLI guide · MCP guide · Integration templates
What Rookhold does
For every submitted job, Rookhold:
- authenticates the caller and checks admission policy;
- applies server-controlled time, memory, process, file, and output limits;
- runs the job using the configured execution provider;
- preserves bounded output, events, cancellation state, and artifacts; and
- records the effective runtime posture and receipt.
The API and persisted store remain the source of truth. The CLI, SDKs, MCP adapter, and dashboard are views over the same contracts.
Three useful recipes
- Run an LLM-generated function—submit generated source without evaluating it inside the agent process.
- Apply a user-defined JSON transform—send structured input and read structured output.
- Grade code against hidden tests—bound evaluation time and retain the result record.
See every recipe or start from the Next.js and FastAPI examples.
Is Rookhold right for the task?
| Use Rookhold for | Keep using the normal workspace for | |---|---| | short generated or user-supplied scripts | editing a repository | | stateless transforms, checks, and evaluators | persistent files and package installation | | jobs needing limits, cancellation, or evidence | browsers, ports, and long-running services | | execution behind a separately controlled API | trusted development already isolated well enough |
Using both is normal. Rookhold owns short execution policy and evidence; it does not replace the rest of an agent or application runtime.
Before running untrusted code
The guarded production profile is Linux x86_64-only. macOS, Windows, and
other Linux architectures support only the unisolated same-trust development
provider. Production uses a dedicated Linux x86_64 VM, pinned gVisor runsc, a
private root filesystem, cgroup v2, scoped credentials, and non-skipping
containment checks.
The service container has host-equivalent outer authority even though each job runs inside a separate gVisor workload. Do not place it on a shared multi-tenant Docker host.
Read the security boundary before accepting untrusted jobs.
Documentation
- Getting started
- Installation choices
- Execution model
- Receipts and verification
- Deployment and operations
- Compatibility
- Feedback
- Release process
Contributing
Start with CONTRIBUTING.md. The repository separates:
- Tier A—docs, examples, and integrations;
- Tier B—SDK, CLI, and public API work; and
- Tier C—authentication, execution, storage, receipts, and isolation.
Tier A changes should not inherit security-core ceremony. Tier C changes must prove the root invariant, regression, adversarial cases, and final exact-head validation.
Build from source
Prebuilt releases are the normal path. Contributors need Rust 1.98 and the job runtimes they intend to test:
git clone https://github.com/sambai-dev/rookhold.git
cd rookhold
cargo build --locked --workspace
Run the complete checks from CONTRIBUTING.md before opening a pull request.
License
Rookhold is released under the MIT License.
Related Skills
Agent-Reach
93.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.6kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.2k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
