BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

onlyboxes

Skill Communication Poor
Works inClaude Code
Poor Scanned — metadata only

Provides a sandboxed code execution environment for individuals and small teams via MCP, enabling safe AI-driven code execution without infrastructure comple…

Onlyboxes is a self-hosted code-execution sandbox for individuals and small teams. It runs a control-plane console plus horizontally scalable worker nodes and exposes its tools over both a REST API and MCP — pythonExec (run Python), terminalExec (stateful terminal sessions), and readImage (model-readable images) — so a client like Claude Code can run code in isolated, per-account containers.

41 starsAGPL-3.0 (check with legal)FreeQuick setup
Below standard — Significant caveats apply. Not recommended without careful review of the security and evaluation sections.

Provides a sandboxed code execution environment for individuals and small teams via MCP, enabling safe AI-driven code execution without infrastructure complexity.

Small teams and individual developers who need isolated code execution environments for AI workflows without managing cloud infrastructure.

Claude Code Claude Cowork Claude Chat

https://github.com/Coooolfan/onlyboxes

By Coooolfan

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Instructions to paste into Claude
# Self-hosted, not a Claude plugin. Single-machine Linux deploy (needs Docker, Compose v2, systemd, Python 3):
curl -fsSL https://onlybox.es/install.sh | bash
# then add the MCP endpoint http://127.0.0.1:8089/mcp in Claude with an access token
First thing to try

After installing, paste this into Claude:

Help me run Python from Claude in an isolated container via the pythonExec MCP tool
CostFree

Trust Signals Auto-scanned

Stars41Contributors2Last updated2026-07-31LicenseAGPL-3.0 (check with legal)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-05 · scanner vattempted-no-data

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 33 GitHub stars; 2 contributors; last commit 16d ago; license AGPL-3.0.

Things to check

  • Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.
  • License (AGPL-3.0) may restrict commercial use. Check with your legal team.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
1/5
Versatility
2/5
Reliability
3/5
Security
3/5
Overall score2.05 / 5.00 PoorEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 33 GitHub stars; 2 contributors; last commit 16d ago; license AGPL-3.0.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →