# LLM Sandbox (MCP server)

> LLM Sandbox is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Securely run LLM-generated code in isolated containers across 7 languages and 3 container backends. It has 1,129 GitHub stars, is released under the MIT license and runs locally with uvx llm-sandbox.

Securely Execute LLM-Generated Code with Ease LLM Sandbox is a lightweight and portable sandbox environment designed to run Large Language Model (LLM) generated code in a safe and isolated mode. It provides a secure execution environment for AI-generated code while offering flexibility in container backends and comprehensive language support, simplifying the process of running code generated by LLMs.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/vndee/llm-sandbox |
| GitHub stars | 1,129 |
| License | MIT |
| Language | Python |
| Transport | stdio |
| Packages | pypi: llm-sandbox |
| Remote URL | none |
| Needs API key | no |
| Official | no |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Developer tools |
| Latest release | 0.3.45 (Sep 28, 2026) |
| Last commit | Oct 1, 2026 |
| MCP registry name | io.github.vndee/llm-sandbox |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "llm-sandbox": {
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --env BACKEND=your-value --env DOCKER_HOST=your-value --env KUBECONFIG=your-value --env NAMESPACE=your-value --env COMMIT_CONTAINER=your-value --env KEEP_TEMPLATE=your-value --transport stdio llm-sandbox -- uvx llm-sandbox
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "llm-sandbox": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "servers": {
    "llm-sandbox": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "llm-sandbox"
      ],
      "env": {
        "BACKEND": "your-value",
        "DOCKER_HOST": "your-value",
        "KUBECONFIG": "your-value",
        "NAMESPACE": "your-value",
        "COMMIT_CONTAINER": "your-value",
        "KEEP_TEMPLATE": "your-value"
      }
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Environment variables

- `BACKEND`: Container backend to use. Must match the installed extra: mcp-docker, mcp-podman, or mcp-k8s.
- `DOCKER_HOST`: Docker or Podman socket URL, e.g. unix:///var/run/docker.sock
- `KUBECONFIG`: Path to kubeconfig file when BACKEND=kubernetes.
- `NAMESPACE`: Kubernetes namespace used for sandbox pods when BACKEND=kubernetes.
- `COMMIT_CONTAINER`: Commit the container after a run so installed libraries persist between sessions.
- `KEEP_TEMPLATE`: Keep the base image after the session ends to avoid re-pulling it on the next run.
- `SANDBOX_NETWORK_MODE`: Network mode for the sandbox container. Set to 'none' for hardened isolation. Docker and Podman backends only.
- `SANDBOX_READ_ONLY`: Mount the sandbox root filesystem read-only. Recommended: true. Docker and Podman backends only.
- `SANDBOX_CAP_DROP`: Comma-separated Linux capabilities to drop. Recommended: ALL. Docker and Podman backends only.
- `SANDBOX_SECURITY_OPT`: Comma-separated container security options, e.g. no-new-privileges. Docker and Podman backends only.
- `SANDBOX_MEMORY`: Memory limit for the sandbox container, e.g. 4g. Docker and Podman backends only.
- `SANDBOX_CPUS`: Fractional CPU allocation for the sandbox container, e.g. 1.5. Docker and Podman backends only.

## Tools

- `execute_code`: Execute code in a secure sandbox with automatic visualization capture
- `get_supported_languages`: Get the list of supported programming languages
- `get_language_details`: Get detailed information about a specific language

## Similar MCP servers

- [Gemini CLI](https://appsgit.com/mcp-servers/gemini-cli): An open-source AI agent that brings the power of Gemini directly into your terminal. (107,240 stars, Apache-2.0)
- [Front-End Checklist](https://appsgit.com/mcp-servers/front-end-checklist): Review frontend code and live pages against 386 quality-gated web development rules. (74,390 stars, MIT)
- [Claude Flow](https://appsgit.com/mcp-servers/claude-flow): AI orchestration with hive-mind swarms, neural networks, and 87 MCP tools for enterprise dev. (74,016 stars, MIT, needs API key)
- [Codebase Memory](https://appsgit.com/mcp-servers/codebase-memory): Codebase knowledge graph for AI agents — 162 languages, sub-ms queries, 99% fewer tokens. (45,917 stars, MIT)
- [Bytedance Filesystem](https://appsgit.com/mcp-servers/bytedance-filesystem): MCP server for filesystem access. (39,206 stars, Apache-2.0)
- [GitHub](https://appsgit.com/mcp-servers/github): Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language. (33,414 stars, MIT, official, needs API key)

---

Canonical page: https://appsgit.com/mcp-servers/llm-sandbox
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
