boxlite-mcp
MCP server providing isolated sandbox environments for AI agents.
The Problem
Today's AI apps don't just generate text – they write and run code, call tools, read your files, and hit the network. Running all of this directly on your machine creates real risks:
- Security - Malicious or buggy code can damage your system
- Privacy - Sensitive files and credentials are exposed
- Reliability - Runaway processes can consume resources or crash your machine
BoxLite solves this by giving AI agents their own isolated VM – full freedom inside, complete safety outside.
Powered by BoxLite
BoxLite is an embeddable virtual machine runtime that follows the SQLite philosophy - simple, lightweight, and zero-configuration.
Why BoxLite?
- Hardware-level isolation - True VM security, not just containers. Your AI agent runs in a completely isolated environment.
- No daemon required - Unlike Docker, BoxLite doesn't need a background service. Just import and use.
- Embeddable - Designed to be embedded directly into your applications, like SQLite for compute.
- Fast startup - VMs boot in seconds, not minutes.
- Cross-platform - Works on macOS and Linux.
Use Cases
- AI Agent Sandboxing - Let AI agents execute code, browse the web, and use applications safely
- Secure Code Execution - Run untrusted code without risk to your host system
- Browser Automation - Headless browser with CDP for web scraping and testing
- Development Environments - Disposable, reproducible dev environments
Demo
https://github.com/user-attachments/assets/0685d428-64e4-4a68-adfe-c24dc0dc5ae8
Available Tools
| Tool | Description |
|---|---|
computer |
Full Ubuntu desktop with XFCE. Anthropic computer use API compatible. |
browser |
Chromium browser with CDP endpoint for Puppeteer/Playwright/Selenium |
code_interpreter |
Python code execution sandbox |
sandbox |
Generic container for running shell commands |
Quick Start
Claude Code
claude mcp add boxlite -- uvx boxlite-mcp
Claude Desktop
Add to your Claude Desktop configuration (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"boxlite": {
"command": "uvx",
"args": ["boxlite-mcp"]
}
}
}
Manual Installation
pip install boxlite-mcp
Development
git clone https://github.com/boxlite-labs/boxlite-mcp.git
cd boxlite-mcp
uv sync --extra dev
uv run pytest
License
Apache-2.0
Metadata
Release files for boxlite-mcp 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| boxlite_mcp-0.3.0.tar.gz | 17.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| boxlite_mcp-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 34.3 kB
Release files / boxlite_mcp-0.3.0.tar.gz
| Download URL | boxlite_mcp-0.3.0.tar.gz |
|---|---|
| Size | 17.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
62fcb7925dc9fd7dc51dde849b31fc544d90263c289acfa139fb4e5cc5dfc920
|
|
BLAKE2b-256 checksum How to use checksums |
99015807f822d070646fda51fe50eb8c1797ae6384e6a4b30618387453ada76f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.8.5
|
Release files / boxlite_mcp-0.3.0-py3-none-any.whl
| Download URL | boxlite_mcp-0.3.0-py3-none-any.whl |
|---|---|
| Size | 16.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
40d65ef7f117798176523f1b7f36fa5e4d0820f2d50a35de9b7c93192807004c
|
|
BLAKE2b-256 checksum How to use checksums |
5b57e7d49cf4d34cd0135dc0e8e1ea8cb3b3a155678503e90cd7eeb11b737ff4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.8.5
|