Atlas / MCP servers / vndee / LLM Sandbox

LLM SandboxBLOCK

mcp/vndee/llm-sandbox-1

Lightweight and portable LLM sandbox runtime (code interpreter) Python library.

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
3 2r · 1w · 0d
Transport
stdio
License
MIT
Stars
1,126
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

LLM Sandbox

Securely Execute LLM-Generated Code with Ease

[](https://sonarcloud.io/summary/newcode?id=vndeellm-sandbox)

[](https://sonarcloud.io/summary/newcode?id=vndeellm-sandbox) [](https://pypi.org/project/llm-sandbox/) [](https://img.shields.io/github/v/release/vndee/llm-sandbox) [](https://github.com/vndee/llm-sandbox/actions/workflows/main.yml?query=branch%3Amain) [](https://www.codefactor.io/repository/github/vndee/llm-sandbox) [](https://codecov.io/gh/vndee/llm-sandbox) [](https://doi.org/10.5281/zenodo.21760525) [](https://deepwiki.com/vndee/llm-sandbox)

LLM Sandbox is a lightweight and portable sandbox environment designed to run Large Language Model (LLM) generated code in a safe and isolated mode. It provides a secure execution environment for AI-generated code while offering flexibility in container backends and comprehensive language support, simplifying the process of running code generated by LLMs.

Documentation: https://vndee.github.io/llm-sandbox/

✨ New: This project now supports the [Model Context Protocol (MCP)](https://vndee.gi

Read from source at commit 5bda1b473e27OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add llm-sandbox -- uvx llm-sandbox==0.3.43
03

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
execute_codewriteExecute code in a secure sandbox environment and automatic visualization capture.
get_language_detailsreadGet the details of a language.
get_supported_languagesreadGet the list of supported languages.
04

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
docs/backends.md:337
# IMPORTANT: When using readOnlyRootFilesystem, you MUST mount
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
docs/backends.md:593
# IMPORTANT: When using readOnlyRootFilesystem, you MUST also provide
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/smoke_agent_sdks.py:76
module = importlib.import_module(name)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.bandit
.bandit
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.sonarcloud.properties
.sonarcloud.properties
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.zenodo.json
.zenodo.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
examples/security_policy_examples.py:311
"import pickle\ndata = pickle.loads(b'malicious_data')",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_advanced_security_scenarios.py:159
description="Inject malicious code through eval() function",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_advanced_security_scenarios.py:171
description="Execute system commands through exec() function",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
examples/test_security.py:120
weak_hash = hashlib.md5(password.encode() + salt).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_advanced_security_scenarios.py:377
weak_hash = hashlib.md5(password.encode() + salt).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_advanced_security_scenarios.py:704
weak_hash = hashlib.md5(password.encode() + salt).hexdigest()
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/test_security_scanner.py:672
print(f'Secret: {secret}')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/security_integration_tests.py:357
"import os\nfilename = '../../../etc/passwd'\nwith open(filename, 'r') as f:\n    print(f.read())",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_docker.py:1678
session.copy_to_runtime(temp_file.name, "../../etc/shadow")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_mixins.py:327
self.mixin._validate_container_path("../../etc/shadow")
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
examples/agent_sdks/ag2_tool.py:33
"network_mode": "none",  # no egress: injected code cannot exfiltrate or fetch a second stage
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
examples/agent_sdks/claude_agent_sdk_tool.py:31
"network_mode": "none",  # no egress: injected code cannot exfiltrate or fetch a second stage
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
examples/agent_sdks/crewai_tool.py:30
"network_mode": "none",  # no egress: injected code cannot exfiltrate or fetch a second stage
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
examples/agent_sdks/deepagents_tool.py:33
"network_mode": "none",  # no egress: injected code cannot exfiltrate or fetch a second stage
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
examples/agent_sdks/google_adk_tool.py:30
"network_mode": "none",  # no egress: injected code cannot exfiltrate or fetch a second stage
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/pool_artifact_demo.py:111
plot_path.write_bytes(base64.b64decode(plot.content_base64))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/python_artifact.py:263
f.write(base64.b64decode(plot.content_base64))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
examples/python_artifact.py:281
f.write(base64.b64decode(plot.content_base64))

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 5bda1b473e27full audit observations/trust-audit/mcp-server/vndee__llm-sandbox-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-255bda1b473e27BLOCKD67first audit
06

Questions

What is the LLM Sandbox MCP server?

Lightweight and portable LLM sandbox runtime (code interpreter) Python library.

What tools does LLM Sandbox expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is LLM Sandbox safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does LLM Sandbox need?

It reads SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LLM Sandbox run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as llm-sandbox.

How current is this page?

The grade is for one exact copy of the source (5bda1b473e27), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement