freshcrate
Skin:/
Home > MCP Servers > mcpsandbox

mcpsandbox

Let your agent write code and execute code directly in the browser with WASM

Why this rank:Strong adoptionRelease freshnessHealthy release cadence

Description

Let your agent write code and execute code directly in the browser with WASM

README

mcpbash

Build tiny sandboxes from MCP tools, TypeScript functions, CLIs, and just-bash.

mcpbash gives you a small shell-first sandbox object. Instead of provisioning a VM or container, you map capabilities into commands and run them through a controlled runtime.

Install

pnpm add mcpbash
# or
npm install mcpbash

Why use it?

  • Map MCP tools to shell commands
  • Map TypeScript functions to shell commands
  • Wrap existing binaries
  • Choose an in-memory, read-only, or read-write filesystem
  • Opt into git support when you need it
  • Control outbound MCP access with a simple network policy
  • Resolve secrets at runtime instead of hardcoding them

Quick start

This example creates one command, slugify, and runs it inside the sandbox.

import { createSandbox, fn } from "mcpbash";

const sandbox = await createSandbox({
  filesystem: { mode: "memory" },
  commands: {
    slugify: fn({
      input: { text: "$1" },
      handler: ({ text }: { text: string }) =>
        text.toLowerCase().replace(/\s+/g, "-"),
    }),
  },
});

const result = await sandbox.run('slugify "Hello World"');

console.log(result.stdout); // hello-world
console.log(result.exitCode); // 0

await sandbox.dispose();

Common patterns

Run a real MCP-backed command

This example is fully runnable. It starts a tiny local HTTP server that behaves like an MCP tool endpoint, maps that tool into the sandbox as repos.search, and calls it like a shell command.

import http from "node:http";
import { createSandbox, mcp } from "mcpbash";

async function startToolServer(): Promise<{ url: string; close(): Promise<void> }> {
  return new Promise((resolve) => {
    const server = http.createServer((req, res) => {
      if (req.method !== "POST" || req.url !== "/tools/search_repositories") {
        res.statusCode = 404;
        res.end("not found");
        return;
      }

      let body = "";
      req.on("data", (chunk) => {
        body += chunk.toString("utf8");
      });
      req.on("end", () => {
        const { input } = JSON.parse(body) as { input?: { q?: string } };
        const query = input?.q ?? "";

        res.setHeader("content-type", "application/json");
        res.end(
          JSON.stringify({
            result: {
              query,
              repos: [
                `${query}-api`,
                `${query}-web`,
                `${query}-worker`,
              ],
            },
          })
        );
      });
    });

    server.listen(0, "127.0.0.1", () => {
      const address = server.address();
      if (!address || typeof address === "string") {
        throw new Error("failed to start tool server");
      }

      resolve({
        url: `http://127.0.0.1:${address.port}`,
        close: () =>
          new Promise<void>((done, reject) => {
            server.close((error) => {
              if (error) reject(error);
              else done();
            });
          }),
      });
    });
  });
}

const toolServer = await startToolServer();

try {
  const sandbox = await createSandbox({
    filesystem: { mode: "memory" },
    network: {
      allow: ["127.0.0.1"],
    },
    commands: {
      "repos.search": mcp({
        server: toolServer.url,
        tool: "search_repositories",
        input: { q: "$1" },
      }),
    },
  });

  const result = await sandbox.run('repos.search "billing"');
  console.log(result.stdout);
  // {
  //   "query": "billing",
  //   "repos": ["billing-api", "billing-web", "billing-worker"]
  // }

  await sandbox.dispose();
} finally {
  await toolServer.close();
}

See also: packages/mcpbash/examples/mcp-demo.ts

Wrap a local CLI

import { cli, createSandbox } from "mcpbash";

const sandbox = await createSandbox({
  commands: {
    upper: cli({
      command: process.execPath,
      args: [
        "-e",
        "process.stdout.write((process.argv[1] ?? '').toUpperCase())",
        "$1",
      ],
    }),
  },
});

console.log((await sandbox.run('upper "hello"')).stdout); // HELLO

Work in a writable directory with git

import { createSandbox } from "mcpbash";

const sandbox = await createSandbox({
  filesystem: {
    mode: "readwrite",
    root: "./workspace",
  },
  integrations: {
    git: true,
  },
});

await sandbox.run("git init -q");
await sandbox.fs.write("README.md", "# demo\n");

const status = await sandbox.git?.status(["--short"]);
console.log(status?.stdout);

API at a glance

import { createSandbox, mcp, fn, cli, provider, secret } from "mcpbash";
  • createSandbox(...) creates a sandbox
  • mcp(...) maps an MCP tool to a command
  • fn(...) maps a TypeScript handler to a command
  • cli(...) wraps a local binary
  • provider(...) is an alias for cli(...) for external runtimes
  • secret.env("NAME") resolves a secret at runtime
  • sandbox.run(...) executes a command
  • sandbox.fs exposes read, write, list, and exists
  • sandbox.git exposes status, diff, and log when git is enabled

Filesystem modes

  • memory: isolated in-memory sandbox
  • readonly: overlay an existing directory without writes
  • readwrite: back the sandbox with a real directory

Examples in this repo

  • packages/mcpbash/examples/mixed-demo.ts
  • packages/mcpbash/examples/mcp-demo.ts
  • packages/mcpbash/examples/git-demo.ts
  • packages/mcpbash/examples/benchmark.ts

Run them:

pnpm install
pnpm --filter mcpbash demo:mixed
pnpm --filter mcpbash demo:mcp
pnpm --filter mcpbash demo:git
pnpm --filter mcpbash bench

Advanced usage

See ADVANCED.md for:

  • filesystem allow/deny rules
  • secrets
  • network policy
  • MCP auth and OAuth patterns
  • provider examples with Daytona, Upstash Box, and Docker
  • current limitations

Performance

Local benchmark on April 9, 2026, on an Apple M4 Pro with Bun 1.3.5:

Operation Mean P50 P95
createSandbox() 0.067 ms 0.040 ms 0.090 ms
built-in shell command (echo) 0.460 ms 0.406 ms 0.687 ms
mapped fn(...) command 0.350 ms 0.319 ms 0.550 ms
mapped provider(...) command (true) 2.143 ms 2.038 ms 3.298 ms
mapped cli(...) command (node -e) 4.160 ms 3.878 ms 7.314 ms

The important takeaway is category-level: mcpbash stays on the local fast path. It does not provision a VM, container, or remote session just to dispatch a mapped command, so startup and dispatch stay in the low-millisecond range.

Run the benchmark locally:

pnpm --filter mcpbash bench

Development

pnpm install
pnpm --filter mcpbash typecheck
pnpm --filter mcpbash build
pnpm --filter mcpbash test

Release History

VersionChangesUrgencyDate
v1.1.0## [1.1.0](https://github.com/buremba/1mcp/compare/v1.0.0...v1.1.0) (2025-11-22) ### Features * add new calculator tools to the AI SDK example and refactor React fragment to span in docs component. ([6d186c2](https://github.com/buremba/1mcp/commit/6d186c2fdf4a389cf3d2963f2c40c3c7e18be228)) * replace sentry and context7 feature endpoints with github ([cf28e48](https://github.com/buremba/1mcp/commit/cf28e4802ee791ec0e87fb318a0a17f3cb654060))Low11/22/2025
v1.0.0## 1.0.0 (2025-11-22) ### Features * add Apache 2.0 license and enable npm publishing ([a8d7b92](https://github.com/buremba/1mcp/commit/a8d7b926dd743e6e8c0b192053055d37fe6c3fd2)) * Add GitHub Actions workflow for Cloudflare Pages deployment ([e6115f3](https://github.com/buremba/1mcp/commit/e6115f3a02528008ef0eb48819292208f21af27f)) * Add interactive code highlighting and an interactive configuration display to the features section, and remove HowItWorksSection from the main app layout. ([f6a7Low11/22/2025

Dependencies & License Audit

Loading dependencies...

Similar Packages

node9-proxyThe Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.v1.65.0
MediaWiki-MCP-ServerModel Context Protocol (MCP) Server to connect your AI with any MediaWikiv0.14.0
airbrokeđŸ”Ĩ Lightweight, Airbrake/Sentry-compatible, PostgreSQL-based Open Source Error Catcherv1.2.19
codexCLIA command-line information store for quick reference of frequently used data, with dot notation paths, shell completions, and MCP server for AI agent integration.v1.3.0
XcodeBuildMCPA Model Context Protocol (MCP) server and CLI that provides tools for agent use when working on iOS and macOS projects.v2.7.0

More in MCP Servers

supersetCode Editor for the AI Agents Era - Run an army of Claude Code, Codex, etc. on your machine
kreuzbergA polyglot document intelligence framework with a Rust core. Extract text, metadata, images, and structured information from PDFs, Office documents, images, and 91+ formats. Available for Rust, Python
ai-engineering-from-scratchLearn it. Build it. Ship it for others.
CodeGraphContextAn MCP server plus a CLI tool that indexes local code into a graph database to provide context to AI assistants.