WASM sandbox for MCP tools. WASI-isolated, fuel/memory/I/O capped, attested.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Ephemora Cell is a lightweight security and execution primitive for running untrusted code inside AI agents, MCP tools, plugins, and applications.
Built for AI agents, MCP tools, plugins, code interpreters, and other untrusted workloads.
~0.5 ms warm Β· ~3M executions/hour per core (one-liner) up to ~5.5M pooled Β· deterministic, not "isolated and hoped for"
Quick Start Β· Security Β· MCP Β· GitHub Action Β· Benchmarks Β· Docs
Status (2026-09-25): latest release v1.0.4.3 (2026-09-25, docs & hardening release β changelog) Β· full functional audit 2026-09-24, findings fixed and released the same day Β· latest reproducible evidence: 2026-09-25 (probe classes,
benchmarks/results/) Β· 532 tests passing, 86% coverage (see CI badge β refreshed per release)
Ephemora Cell is an embeddable execution and security primitive for running untrusted WASM code: WASM/WASI isolation, explicit capability control, enforced CPU/fuel, memory, I/O and time limits, bounded output, and structured β optionally signed β execution records. Runtime + security primitive + accounting in one pip install. It uses Wasmtime to implement that boundary β WASM is the mechanism, the controlled execution of untrusted code is the product.
Wasmtime gives you a WASM runtime.
Ephemora Cell builds an application-level execution boundary around it:
The problem this answers: AI agents increasingly need to write and execute code, call tools, and run plugins. The question that decides whether that is safe: how do you let an agent execute untrusted code without giving that code access to your host, your credentials, your network, or unlimited compute β with nothing pre-opened by default? Raw runtimes leave that boundary to you. Cell is that boundary.
Agent-generated code is different from application code: it can be buggy, computationally unbounded, unexpectedly expensive β or hostile. The runtime must enforce boundaries, not document them. Every Cell run does:
benchmarks/results/).Why now β 2026 evidence that detection and containers are not enough (literature β measured:false for Cell; the measured rows live in the evidence ladder and never mix with these). SABER β the SandboxEscapeBench program (UK AI Security Institute & Oxford, ICML 2026) shows frontier models reliably escaping Docker containers through common misconfigurations β the same benchmark this repo maps to WASM in the Security section. Trail of Bits researchers (Judson & Hess, 2026) bypassed five agent-skill scanners and sandbox defenses in one study, and the DDIPE skill-poisoning attack (arXiv 2604.03081) measures 11.6β33.5% bypass rates against agent skill ecosystems. The pattern across all three: scanning and container defaults fail; the boundary that holds is the one enforced between the code and the host β the layer Cell ships (per-claim provenance: docs/security_posture.md).
Every execution answers three questions at once β attached to the result as _meta.execution, canonicalized (RFC 8785 JCS) and signable:
| Answer | Example fields | |
|---|---|---|
| RESULT | what came back | status, stdout, exit_code |
| COST | what it cost | fuel_consumed, elapsed_ms |
| POLICY | under which rules it ran | memory limit, preopens, network policy, wasmtime_version |
"Verifying. Not claimed." is data, not a slogan: any record can be re-checked β rewrite one field and verify() fails. Runnable demo: python examples/signed_record_demo.py.
Cell assumes that guest code is untrusted. The host explicitly decides what the guest can access β and the runtime enforces that decision per execution.
By default: no network Β· no arbitrary filesystem access Β· no process spawning Β· no unrestricted environment access β and bounded CPU/fuel, memory, execution time and output.
Security is never opt-in. Every execution β in-process or isolated β runs under enforced limits (CPU fuel, memory, wall-clock time, output caps β always on, neither the guest nor the caller can switch them off). The one thing you choose is the process boundary: add --isolated (or call run_isolated()) when the module comes from outside your own build β agent output, third-party plugins, PR-contributed code. The in-process path stays for modules you build and trust. The enforced defaults:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ephemora-cell-mcp-wasm-sandbox)<a href="https://allmcps.com/mcp/ephemora-cell-mcp-wasm-sandbox"><img src="https://allmcps.com/api/badge/ephemora-cell-mcp-wasm-sandbox?style=directory" alt="Ephemora Cell MCP β WASM Sandbox on AllMCPs" /></a>