Developer · Local MCP server
Exec Sandbox
Single exec tool running caller Python in a network-isolated locked-down sandbox.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.inhuman/mcp-exec- Version
- 0.5.4
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-07-20
- Updated
- 2026-07-20
- Publisher
- inhuman (GitHub) · 3 servers with pages here
- Repository
- github.com/inhuman/mcp-exec
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker)runtime: docker | docker.io/idconstruct/mcp-exec:v0.5.4 | — | stdio |
How to connect Exec Sandbox
Exec Sandbox runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: docker.io/idconstruct/mcp-exec:v0.5.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e MCP_EXEC_TRANSPORT -e MCP_EXEC_DEFAULT_TIMEOUT_S -e MCP_EXEC_MAX_TIMEOUT_S -e MCP_EXEC_MAX_OUTPUT_BYTES -e MCP_EXEC_MAX_STDIN_BYTES -e MCP_EXEC_AUTH_TOKEN docker.io/idconstruct/mcp-exec:v0.5.4. It reads these environment variables: MCP_EXEC_TRANSPORT, MCP_EXEC_DEFAULT_TIMEOUT_S, MCP_EXEC_MAX_TIMEOUT_S, MCP_EXEC_MAX_OUTPUT_BYTES, MCP_EXEC_MAX_STDIN_BYTES and MCP_EXEC_AUTH_TOKEN (secret); set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"mcp-exec": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"MCP_EXEC_TRANSPORT",
"-e",
"MCP_EXEC_DEFAULT_TIMEOUT_S",
"-e",
"MCP_EXEC_MAX_TIMEOUT_S",
"-e",
"MCP_EXEC_MAX_OUTPUT_BYTES",
"-e",
"MCP_EXEC_MAX_STDIN_BYTES",
"-e",
"MCP_EXEC_AUTH_TOKEN",
"docker.io/idconstruct/mcp-exec:v0.5.4"
],
"env": {
"MCP_EXEC_TRANSPORT": "<value>",
"MCP_EXEC_DEFAULT_TIMEOUT_S": "<value>",
"MCP_EXEC_MAX_TIMEOUT_S": "<value>",
"MCP_EXEC_MAX_OUTPUT_BYTES": "<value>",
"MCP_EXEC_MAX_STDIN_BYTES": "<value>",
"MCP_EXEC_AUTH_TOKEN": "<secret>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from inhuman (GitHub)
| Server | Runs |
|---|---|
| Kubernetes Ephemeral JobRuns a command in a throwaway Kubernetes pod and returns exit code, output and artifacts. | Local · stdio |
| SSH FleetCurated ssh_probe diagnostics and single-host ssh_exec over an allowlisted SSH fleet. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| ExactGroundCheck npm/PyPI packages exist and that a function or method exists in an exact package version. | Remote · HTTP |
| ExcalidrawSecurity-hardened Excalidraw MCP server with auth, rate limiting, and 14 tools. | Local · stdio |
| Excel MCP ServerCreate, read and edit Excel workbooks without Microsoft Excel. | Local · stdio |
| Excel MCP Server (FsOpenXmlDsl)Excel tools for AI agents: read/write, decompile to F#/C#/XML/JSON, or build from XML/JSON. | Local · stdio |
| ExecBroGives AI agents eyes and hands into running React Native apps: logs, REPL, tap, screenshots. | Local · stdio |
| ExeckitStateful, structured, safe shell sessions for AI agents over local, SSH, and Docker. | Local · stdio |
| ExerciseapiGive your AI coding agent direct access to 2,198+ exercises via exerciseapi.dev. | Local · stdio |
| Exit1 Uptime MonitoringSet up uptime monitoring from your editor: create checks, configure alerts, query uptime history. | Remote & Local · HTTP, stdio |