Persistent Docker/SSH sandbox for AI agents: shell exec, file ops, audit log.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
MCP server that gives AI agents a real working environment: persistent shells, a filesystem, and multi-machine management — backed by Docker containers or remote SSH hosts.
env tool exposes capabilities step by
step. Agents call env(action="help") to see what's available..ssh, .aws, .env*)
without blocking access. Pre-write syntax lint for JSON/YAML/TOML.On first run a default container (python:3.14-slim, named admin)
starts automatically with a persistent bash shell. No other setup.
Requirements: Python 3.12+, Docker SDK, running Docker daemon.
SSH mode needs openssh-client.
All tools target the default machine unless an explicit machine
parameter is passed.
| Tool | What it does |
|---|---|
shell_exec | Run a command in a persistent shell. Blocks until the command finishes (wait=true, 10 s timeout) or fire-and-forget with wait=false. |
shell_read | Read buffered output from a running or finished command. |
shell_new | Create a fresh shell on a machine. Returns a shell_id. |
shell_remove | Terminate and remove a shell by shell_id. |
shell_list | List all shells with state, machine, uptime, last command. |
write_stdin | Write raw bytes to a running shell — interrupt with Ctrl-C (\x03) or feed input to interactive programs like read / Read-Host. On Windows/PowerShell, Ctrl-C is unsupported (pipe mode has no terminal driver); kill the shell instead. |
machine_list | List all registered machines with backend, status, purpose, shell count. |
default_set | Set the default machine or default shell for a machine. |
file_read | Read a file with line numbers. Supports offset + limit pagination. |
file_write | Write content atomically. Creates parent directories automatically. |
file_patch | Targeted edits with fuzzy matching. mode=replace (find-and-replace) or mode=patch (unified diff). |
file_search | Search file contents (ripgrep) or find files (glob). Sorted by modification time. |
env | Progressive-discovery portal. Start with env(action="help"). |
audit_query is exposed when the audit log is a SQLite database —
it lets the agent search historical tool calls.
Every shell is in one of four states:
| State | What it means | What the agent can do |
|---|---|---|
init | Shell just created; booting up. Times out → terminated at 10 s. | Wait — shell_exec returns an error until ready. |
ready | At a prompt, accepting commands. | Send commands, read output, write stdin. |
waiting | A command is running. | Poll output with shell_read. Send Ctrl-C with write_stdin. |
terminated | Shell process exited (signal, exit, timeout, broken pipe). Last output is preserved. | Read remaining output, then shell_remove + shell_new to continue. Default shells are never auto-replaced. |
Key shell_exec parameters:
wait (default true): block until the command completes.timeout (default 10 s): on expiry returns status="waiting"
with a hint to switch to wait=false + shell_read for
long-running commands.max_output (default 50000 bytes): caps returned output;
excess is shown as the tail (last N bytes).env(action="help") lists what's available. env(action="help", topic="<action>") returns full docs for a specific action.
| Action | Params | Description |
|---|---|---|
help | topic? | List actions or get docs for one. |
status | — | Default machine, machines, shells. |
list_targets | — | Pre-defined SSH targets from config. |
machine_list | — | Registered machines. |
shell_list | machine? | Shells, optionally filtered. |
shell_new | machine?, purpose? | New shell session. |
shell_remove | shell_id | Terminate and remove. |
default_set | machine or shell_id | Set default machine or shell. |
| Action | Required params | Description |
|---|---|---|
docker_run | name, image, purpose | Create/start container. Reattaches on name collision. |
docker_ps | — | List managed containers. |
docker_images | — | List all images on daemon. |
docker_image_history | image | Layer-by-layer build history. |
docker_build | image_tag, machine | Build from a Dockerfile in /workspace. |
docker_commit | machine, image_tag | Commit container as new image. |
docker_stop | machine | Stop (state preserved). |
docker_start | machine | Start a stopped container. |
docker_remove | machine | Stop + remove container and its shells. |
docker_inspect | machine | Curated config. kind=image for images. |
docker_logs | machine | Logs with tail, since, until. |
docker_diff | machine | Filesystem changes vs image. |
docker_stats | machine | CPU/memory/network/IO snapshot. |
docker_restart | machine | Stop + start + verify. |
| Action | Required params | Description |
|---|---|---|
connect | name | Connect to a configured target. |
close | name | Disconnect and unregister. |
Available when [ssh.targets] is configured.
| Tool | Key params | Highlights |
|---|---|---|
file_read | path, offset, limit | Line-numbered. Rejects files > 50 KB with a hint. |
file_write | path, content | Atomic (temp + rename), auto-creates parent dirs, post-write verification. |
file_patch | path, old_string, new_string (replace mode) or patch (unified diff) | Fuzzy matching. Preserves BOM and line endings. |
file_search | pattern, search_type, path, file_glob, limit | Powered by ripgrep. Results sorted by modification time. |
Safety warnings are surfaced for sensitive paths (.ssh, .aws,
.env*, /etc/shadow, etc.) — advisory only, agents still have full
access. Writes to .json, .yaml, .yml, .toml are
syntax-checked before writing (fail-closed).
Config lives at ~/.sandbox-mcp/config.toml (copy
config/config.example.toml). Every field can be overridden with
SANDBOX_MCP_<SECTION>_<KEY> env vars.
Containers get bind mounts for workspace isolation:
work_home/<name>/ → /workspace (rw)work_home/<share_subdir>/ → /share/ (ro, shared across peers)work_home/<share_subdir>/<name>/ → /share/<name>/ (rw overlay)When a container's name matches admin_machine, it also gets
work_home/ → /host (rw) — a global view of all workspaces.
Server startup auto-reconciles with the Docker daemon: surviving containers are re-adopted into the registry.
Connects over SSH with ControlMaster for connection reuse. Windows targets get automatic code-page probing and encoded-command execution.
HTTP mode reads bearer tokens from auth_tokens_file (hot-reload on
every request). If the file is empty or missing and
auto_generate_if_empty=true, a random token is printed to stderr at
startup.
Every tool call is recorded: timestamp, machine, action, status,
duration, and hashed parameters. Defaults to SQLite at
~/.sandbox-mcp/audit.db. Set log_path="" for JSON-line stderr
output instead.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/sandbox-env-mcp)<a href="https://allmcps.com/mcp/sandbox-env-mcp"><img src="https://allmcps.com/api/badge/sandbox-env-mcp?style=directory" alt="Sandbox Env MCP on AllMCPs" /></a>