History of LLM Sandbox
io.github.vndee/llm-sandbox · Registry status: active
Every published change to this entry, most recent first.
| 2026-09-08 | Connection paths (source structure): – → {"packages":[{"registryType":"pypi","identifier":"llm-sandbox","version":"0.3.43","runtimeHint":"uvx","transport":"stdio","environment":[{"name":"BACKEND","description":"Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s.","required":false,"secret":false},{"name":"DOCKER_HOST","description":"Docker or Podman socket URL, e.g. unix:///var/run/docker.sock","required":false,"secret":false},{"name":"KUBECONFIG","description":"Path to kubeconfig file when BACKEND=kubernetes.","required":false,"secret":false},{"name":"NAMESPACE","description":"Kubernetes namespace used for sandbox pods when BACKEND=kubernetes.","required":false,"secret":false},{"name":"COMMIT_CONTAINER","description":"Commit the container after a run so installed libraries persist between sessions.","required":false,"secret":false},{"name":"KEEP_TEMPLATE","description":"Keep the base image after the session ends to avoid re-pulling it on the next run.","required":false,"secret":false},{"name":"SANDBOX_NETWORK_MODE","description":"Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only.","required":false,"secret":false},{"name":"SANDBOX_READ_ONLY","description":"Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only.","required":false,"secret":false},{"name":"SANDBOX_CAP_DROP","description":"Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only.","required":false,"secret":false},{"name":"SANDBOX_SECURITY_OPT","description":"Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only.","required":false,"secret":false},{"name":"SANDBOX_MEMORY","description":"Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only.","required":false,"secret":false},{"name":"SANDBOX_CPUS","description":"Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only.","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
|---|---|
| 2026-08-26 | Description (raw): – → Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends. |
| 2026-08-16 | Last changed in the registry (raw): – → 2026-08-03 |
| 2026-08-16 | First listed in the registry (raw): – → 2026-08-03 |
| 2026-08-16 | Registry status message (raw): – → – |
| 2026-08-16 | Schema version of the raw record (raw): – → https://static.modelcontextprotocol.io/schemas/2025-10-17/server.schema.json |
| 2026-08-16 | Icon formats (raw): – → – |
| 2026-08-16 | Environment variable descriptions (raw): – → BACKEND=Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s. · COMMIT_CONTAINER=Commit the container after a run so installed libraries persist between sessions. · DOCKER_HOST=Docker or Podman socket URL, e.g. unix:///var/run/docker.sock · KEEP_TEMPLATE=Keep the base image after the session ends to avoid re-pulling it on the next run. · KUBECONFIG=Path to kubeconfig file when BACKEND=kubernetes. · NAMESPACE=Kubernetes namespace used for sandbox pods when BACKEND=kubernetes. · SANDBOX_CAP_DROP=Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only. · SANDBOX_CPUS=Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only. · SANDBOX_MEMORY=Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only. · SANDBOX_NETWORK_MODE=Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only. · SANDBOX_READ_ONLY=Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only. · SANDBOX_SECURITY_OPT=Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only. |
| 2026-08-16 | Environment variable formats (raw): – → – |
| 2026-08-16 | Delivery form (raw): – → package |
| 2026-08-16 | Remote hosts (raw): – → – |
| 2026-08-16 | Remote URLs (raw): – → – |
| 2026-08-16 | Runtime hints (raw): – → uvx |
| 2026-08-16 | Package versions (raw): – → 0.3.43 |
| 2026-08-16 | Package identifiers (raw): – → llm-sandbox |
| 2026-08-16 | Repository subfolder (raw): – → – |
| 2026-08-16 | Repository platform (raw): – → github |
| 2026-08-16 | Path environment variables (raw): – → – |
| 2026-08-16 | Required secret headers (raw): – → – |
| 2026-08-06 | Declared version: – → 0.3.43 |
| 2026-08-06 | Repository URL listed: – → yes |
| 2026-08-06 | Path argument present: – → no |
| 2026-08-06 | Execution location: – → local |
| 2026-08-06 | Required secrets declared: – → no |
| 2026-08-06 | Package registries (raw): – → pypi |
| 2026-08-06 | Repository (raw): – → https://github.com/vndee/llm-sandbox |
| 2026-08-06 | Path arguments (raw): – → – |
| 2026-08-06 | Transports (raw): – → stdio |
| 2026-08-06 | Required secret variables (raw): – → – |
| 2026-08-06 | Environment variables (raw): – → BACKEND, DOCKER_HOST, KUBECONFIG, NAMESPACE, COMMIT_CONTAINER, KEEP_TEMPLATE, SANDBOX_NETWORK_MODE, SANDBOX_READ_ONLY, SANDBOX_CAP_DROP, SANDBOX_SECURITY_OPT, SANDBOX_MEMORY, SANDBOX_CPUS |
tracevero · https://tracevero.com/mcp/io-github-vndee-llm-sandbox/aenderungen