LLM Sandbox
io.github.vndee/llm-sandbox · Status: active
If you find your own account name here: write informally to German.saas@web.de, stating the identifier concerned. No reason has to be given. How to object
- Registry name
io.github.vndee/llm-sandbox- Package coordinate
pypi:llm-sandbox- Version
0.3.43- Listed in the registry
- 2026-08-03
- Changed in the registry
- 2026-08-03
- First seen by tracevero
- 2026-08-06
- Vendor's website
- https://vndee.github.io/llm-sandbox/
Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends.
Vendor's own description, untranslated and unverified
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Credentials required | no Raw declaration – Required secret variables (raw): confirmed absent Raw declaration – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
|---|---|
| Execution location | local Raw declaration – Transports (raw): stdio Source: MCP-Register · collected on 2026-08-06 · derived |
| Path argument present | no Raw declaration – Path arguments (raw): confirmed absent Raw declaration – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-08-06 · derived |
| Repository URL listed | yes Raw declaration – Repository (raw): https://github.com/vndee/llm-sandbox Source: MCP-Register · collected on 2026-08-06 · derived |
| Version | 0.3.43 Source: MCP-Register · collected on 2026-08-06 · self-declared |
Position within the holdings
How many of the 24,507 published entries carry the same measured value. A reference figure, not an assessment.
- Credentials requiredno20,303 of 24,507 carry this value (83 %)View these entries
- Execution locationlocal12,078 of 24,507 carry this value (49 %)View these entries
- Path argument presentno24,278 of 24,507 carry this value (99 %)View these entries
- Repository URL listedyes19,097 of 24,507 carry this value (78 %)View these entries
All 4 values together are carried by 8,546 of 24,507 entries.
This entry appears in these selections
- MCP servers without credentials20,303
- Locally executed MCP servers12,078
- MCP servers with a repository URL19,097
- Local MCP servers without credentials9,218
- Local MCP servers with a repository URL11,472
- MCP servers over stdio only9,833
- MCP servers as a PyPI package only3,081
- Local MCP servers as a PyPI package only3,062
- MCP servers available as a package only10,633
- MCP servers with uvx as their only runtime hint994
The source's raw values23
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Environment variables (raw) | BACKEND, DOCKER_HOST, KUBECONFIG, NAMESPACE, COMMIT_CONTAINER, KEEP_TEMPLATE, SANDBOX_NETWORK_MODE, SANDBOX_READ_ONLY, SANDBOX_CAP_DROP, SANDBOX_SECURITY_OPT, SANDBOX_MEMORY, SANDBOX_CPUS Source: MCP-Register · collected on 2026-08-06 · self-declared |
|---|---|
| Required secret variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Transports (raw) | stdio Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Repository (raw) | https://github.com/vndee/llm-sandbox Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Package registries (raw) | pypi Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-08-03 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Last changed in the registry (raw) | 2026-08-03 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-10-17/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | paket Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | llm-sandbox Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 0.3.43 Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Runtime hints (raw) | uvx Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | BACKEND=Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s. · COMMIT_CONTAINER=Commit the container after a run so installed libraries persist between sessions. · DOCKER_HOST=Docker or Podman socket URL, e.g. unix:///var/run/docker.sock · KEEP_TEMPLATE=Keep the base image after the session ends to avoid re-pulling it on the next run. · KUBECONFIG=Path to kubeconfig file when BACKEND=kubernetes. · NAMESPACE=Kubernetes namespace used for sandbox pods when BACKEND=kubernetes. · SANDBOX_CAP_DROP=Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only. · SANDBOX_CPUS=Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only. · SANDBOX_MEMORY=Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only. · SANDBOX_NETWORK_MODE=Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only. · SANDBOX_READ_ONLY=Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only. · SANDBOX_SECURITY_OPT=Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only. Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
Changes
| 2026-08-16 | Last changed in the registry (raw): – → 2026-08-03 |
|---|---|
| 2026-08-16 | First listed in the registry (raw): – → 2026-08-03 |
| 2026-08-16 | Registry status message (raw): – → – |
| 2026-08-16 | Schema version of the raw record (raw): – → https://static.modelcontextprotocol.io/schemas/2025-10-17/server.schema.json |
| 2026-08-16 | Icon formats (raw): – → – |
| 2026-08-16 | Environment variable descriptions (raw): – → BACKEND=Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s. · COMMIT_CONTAINER=Commit the container after a run so installed libraries persist between sessions. · DOCKER_HOST=Docker or Podman socket URL, e.g. unix:///var/run/docker.sock · KEEP_TEMPLATE=Keep the base image after the session ends to avoid re-pulling it on the next run. · KUBECONFIG=Path to kubeconfig file when BACKEND=kubernetes. · NAMESPACE=Kubernetes namespace used for sandbox pods when BACKEND=kubernetes. · SANDBOX_CAP_DROP=Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only. · SANDBOX_CPUS=Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only. · SANDBOX_MEMORY=Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only. · SANDBOX_NETWORK_MODE=Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only. · SANDBOX_READ_ONLY=Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only. · SANDBOX_SECURITY_OPT=Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only. |
| 2026-08-16 | Environment variable formats (raw): – → – |
| 2026-08-16 | Delivery form (raw): – → paket |
| 2026-08-16 | Remote hosts (raw): – → – |
| 2026-08-16 | Remote URLs (raw): – → – |
These are the 10 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-vndee-llm-sandbox