Server data from the Official MCP Registry
Give an agent a real Linux VM: run commands, move files, expose a preview URL, destroy it.
About
Give an agent a real Linux VM: run commands, move files, expose a preview URL, destroy it.
Security Report
This MCP server is well-structured and implements proper authentication via API keys. It functions as a thin client to a backend service where authorization and quotas are enforced server-side. Code quality is good with proper error handling and input validation. The server's permissions (network_http, env_vars) are appropriate for its purpose as a sandbox management tool. Minor issues include broad exception handling and lack of sensitive data filtering in error responses. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).
3 files analyzed · 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: AAS_API_KEY
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"com-sandbox-as-a-service-mcp": {
"env": {
"AAS_API_KEY": "your-aas-api-key-here"
},
"args": [
"-y",
"sandbox-as-a-service-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
sandbox-as-a-service-mcp
An MCP server that gives an agent a real Linux virtual machine it can break.
Eleven tools: create a sandbox, run shell commands in it, write and read files, list what a run produced, expose a port on a public preview URL, extend the lifetime, destroy it, and check what it all cost.
Each sandbox is a dedicated VM with its own kernel — not a container sharing a host with other people's code. It is never reused between accounts and is destroyed when it expires, whether or not anything remembered to ask.
Use it
AAS_API_KEY=aas_sk_... npx -y https://sandbox-as-a-service.com/mcp.tgz
Get a key at sandbox-as-a-service.com — new accounts start with free credit and no card.
Claude Desktop / Claude Code
{
"mcpServers": {
"sandbox": {
"command": "npx",
"args": ["-y", "https://sandbox-as-a-service.com/mcp.tgz"],
"env": { "AAS_API_KEY": "aas_sk_..." }
}
}
}
The tools
| Tool | What it does |
|---|---|
create_sandbox | Creates a VM and returns its id once it is ready. |
run_command | Runs a shell command as an unprivileged user. Returns stdout, stderr, exit code. |
write_file | Writes a file. Content travels out of band, so quotes and binary survive. |
read_file | Reads a file back — how an agent gets at what its code produced. |
list_files | Lists a directory tree, so an agent can find what a run produced. |
expose_port | Gives a server inside the sandbox a public https URL to share. |
get_sandbox | Status, size and expiry. |
list_sandboxes | Everything on the account, newest first — useful for finding strays. |
extend_sandbox | Pushes the expiry out when a job outgrows its timeout. |
destroy_sandbox | Destroys it and stops billing. |
get_usage | Remaining credit and recent usage. |
Notes for agents
- Code runs as an unprivileged user. There is no
sudo, soapt-getwill not work; usepip install --user --break-system-packagesornpm install, both of which do. run_commandwaits for the command to finish. Start a server with&or it will hold the call open until the timeout.- A sandbox is destroyed when its timeout expires whether or not
destroy_sandboxis called, so a forgotten sandbox costs minutes, not money forever. Calling it anyway returns the minutes you were not going to use.
Environment
| Variable | |
|---|---|
AAS_API_KEY | Required. Your API key. |
AAS_BASE_URL | Optional. Defaults to https://sandbox-as-a-service.com/v1. |
MIT licensed. The service it talks to is at sandbox-as-a-service.com; docs.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
