Developer · Local MCP server
LLM Sandbox
Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.vndee/llm-sandbox- Version
- 0.3.43
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- PyPI
- Published
- 2026-08-03
- Updated
- 2026-08-03
- Publisher
- vndee (GitHub)
- Website
- vndee.github.io/llm-sandbox/
- Repository
- github.com/vndee/llm-sandbox
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| PyPIruntime: uvx | llm-sandbox | 0.3.43 | stdio |
How to connect LLM Sandbox
LLM Sandbox runs locally from a Python package published to PyPI: llm-sandbox version 0.3.43. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Python; clients usually start it with uvx (from uv) or after pip install — the usual command is uvx llm-sandbox. It reads these environment variables: BACKEND, DOCKER_HOST, KUBECONFIG, NAMESPACE, COMMIT_CONTAINER, KEEP_TEMPLATE, SANDBOX_NETWORK_MODE, SANDBOX_READ_ONLY, SANDBOX_CAP_DROP, SANDBOX_SECURITY_OPT, SANDBOX_MEMORY and SANDBOX_CPUS; set them in the client's configuration for this server. Required arguments: --from.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"llm-sandbox": {
"command": "uvx",
"args": [
"llm-sandbox"
],
"env": {
"BACKEND": "<value>",
"DOCKER_HOST": "<value>",
"KUBECONFIG": "<value>",
"NAMESPACE": "<value>",
"COMMIT_CONTAINER": "<value>",
"KEEP_TEMPLATE": "<value>",
"SANDBOX_NETWORK_MODE": "<value>",
"SANDBOX_READ_ONLY": "<value>",
"SANDBOX_CAP_DROP": "<value>",
"SANDBOX_SECURITY_OPT": "<value>",
"SANDBOX_MEMORY": "<value>",
"SANDBOX_CPUS": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| LLM Provider MCPDelegate asynchronous coding jobs between Claude Code, Codex, Cursor Agent, and Pi. | Local · stdio |
| LLM PulseAI visibility analytics for brand mentions, citations, sentiment, and GEO reports. | Remote · HTTP |
| LLM Red-Team Scanner35-probe LLM/agent security red-team scan (injection, jailbreak, MCP abuse) with report. | Remote · HTTP |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Local · stdio |
| LLM SEO MCP — Elephant AccountabilityLLM SEO and Agent Discoverability for B2B SaaS. Pricing, fit assessment, audit requests. | Remote · HTTP |
| LLM UsageLocal-first, multi-provider tool that captures LLM API spend and exposes it to coding agents via MCP. | Local · stdio |
| Llm Wiki MCPMCP server for Karpathy-style LLM wikis: persistent markdown your agent grows over time. | Local · stdio |
| llm-oracleUp-to-date LLM pricing + availability catalog with cited sources for AI agent routing. | Local · stdio |