Skip to content
appsgit

LLM Sandbox

LLM Sandbox is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends. It has 1,129 GitHub stars, is released under the MIT license and runs locally with uvx llm-sandbox.

github.com/vndee/llm-sandbox (opens in a new tab)

Install LLM Sandbox

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "llm-sandbox": {
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env BACKEND=your-value --env DOCKER_HOST=your-value --env KUBECONFIG=your-value --env NAMESPACE=your-value --env COMMIT_CONTAINER=your-value --env KEEP_TEMPLATE=your-value --transport stdio llm-sandbox -- uvx llm-sandbox

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "llm-sandbox": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "servers": {
    "llm-sandbox": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
BACKENDNoContainer backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s.
DOCKER_HOSTNoDocker or Podman socket URL, e.g. unix:///var/run/docker.sock
KUBECONFIGNoPath to kubeconfig file when BACKEND=kubernetes.
NAMESPACENoKubernetes namespace used for sandbox pods when BACKEND=kubernetes.
COMMIT_CONTAINERNoCommit the container after a run so installed libraries persist between sessions.
KEEP_TEMPLATENoKeep the base image after the session ends to avoid re-pulling it on the next run.
SANDBOX_NETWORK_MODENoNetwork mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only.
SANDBOX_READ_ONLYNoMount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only.
SANDBOX_CAP_DROPNoComma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only.
SANDBOX_SECURITY_OPTNoComma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only.
SANDBOX_MEMORYNoMemory limit for the sandbox container, e.g. 4g. Docker and Podman backends only.
SANDBOX_CPUSNoFractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only.

Tools (3)

Parsed from the Tools section of the README; check the repository for the current list.

  • execute_code

    Execute code in a secure sandbox with automatic visualization capture

  • get_supported_languages

    Get the list of supported programming languages

  • get_language_details

    Get detailed information about a specific language

About LLM Sandbox

Securely Execute LLM-Generated Code with Ease LLM Sandbox is a lightweight and portable sandbox environment designed to run Large Language Model (LLM) generated code in a safe and isolated mode. It provides a secure execution environment for AI-generated code while offering flexibility in container backends and comprehensive language support, simplifying the process of running code generated by LLMs.

  • code-generation
  • code-interpreter
  • large-language-models
  • llm-sandbox

FAQ

LLM Sandbox FAQ

Still curious? Email info@appsgit.com.

What is LLM Sandbox?

LLM Sandbox is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends. It has 1,129 GitHub stars, is released under the MIT license and runs locally with uvx llm-sandbox. The source code is at github.com/vndee/llm-sandbox.

How do I install the LLM Sandbox MCP server?

Add the command uvx llm-sandbox to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is LLM Sandbox free?

The server is open source under the MIT license, so running it is free. It does not declare any required API key.

Is LLM Sandbox actively maintained?

The most recent commit was on Oct 1, 2026. The latest release is 0.3.45, published Sep 28, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.