boxlite-mcp
MCP server providing isolated sandbox environments for AI agents.
The Problem
Today's AI apps don't just generate text – they write and run code, call tools, read your files, and hit the network. Running all of this directly on your machine creates real risks:
- Security - Malicious or buggy code can damage your system
- Privacy - Sensitive files and credentials are exposed
- Reliability - Runaway processes can consume resources or crash your machine
BoxLite solves this by giving AI agents their own isolated VM – full freedom inside, complete safety outside.
Powered by BoxLite
BoxLite is an embeddable virtual machine runtime that follows the SQLite philosophy - simple, lightweight, and zero-configuration.
Why BoxLite?
- Hardware-level isolation - True VM security, not just containers. Your AI agent runs in a completely isolated environment.
- No daemon required - Unlike Docker, BoxLite doesn't need a background service. Just import and use.
- Embeddable - Designed to be embedded directly into your applications, like SQLite for compute.
- Fast startup - VMs boot in seconds, not minutes.
- Cross-platform - Works on macOS and Linux.
Use Cases
- AI Agent Sandboxing - Let AI agents execute code, browse the web, and use applications safely
- Secure Code Execution - Run untrusted code without risk to your host system
- Browser Automation - Headless browser with CDP for web scraping and testing
- Development Environments - Disposable, reproducible dev environments
Demo
https://github.com/user-attachments/assets/0685d428-64e4-4a68-adfe-c24dc0dc5ae8
Available Tools
| Tool | Description |
|---|---|
computer |
Full Ubuntu desktop with XFCE. Anthropic computer use API compatible. |
browser |
Chromium browser with CDP endpoint for Puppeteer/Playwright/Selenium |
code_interpreter |
Python code execution sandbox |
sandbox |
Generic container for running shell commands |
Quick Start
Claude Code
claude mcp add boxlite -- uvx boxlite-mcp
Claude Desktop
Add to your Claude Desktop configuration (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"boxlite": {
"command": "uvx",
"args": ["boxlite-mcp"]
}
}
}
Manual Installation
pip install boxlite-mcp
Development
git clone https://github.com/boxlite-labs/boxlite-mcp.git
cd boxlite-mcp
uv sync --extra dev
uv run pytest
Connect Local Server to Claude Code
claude mcp add boxlite -s local \
-e BOXLITE_HOME=$HOME/.boxlite-mcp \
-- uv run --directory /path/to/boxlite-mcp python -m server
Note: Environment variables must be passed via
-e, not inline in the args. MCP stdio servers bypass the shell, soVAR=value commandsyntax won't work.
Connect Local Server to Claude Desktop
Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"boxlite": {
"command": "uv",
"args": ["run", "--directory", "/path/to/boxlite-mcp", "python", "-m", "server"],
"env": {
"BOXLITE_HOME": "/path/to/.boxlite-mcp"
}
}
}
}
License
Apache-2.0
Metadata
Release files for iflow-mcp_boxlite-ai-boxlite-mcp 0.2.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5.tar.gz | 17.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.3 kB
Release files / iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5.tar.gz
| Download URL | iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5.tar.gz |
|---|---|
| Size | 17.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f4941e6fc40be567da7e1f1061d09512cc523d189a49f19cd92bc6de424c9def
|
|
BLAKE2b-256 checksum How to use checksums |
c2b2804c640c0dde2ddf0259432def85bf7d4c736e8a26b0d937799fee969e7d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5-py3-none-any.whl
| Download URL | iflow_mcp_boxlite_ai_boxlite_mcp-0.2.5-py3-none-any.whl |
|---|---|
| Size | 17.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8b843ddf59b1aee098f91cd7d29dbc110f81f7f48f9ffe950672d7454601575a
|
|
BLAKE2b-256 checksum How to use checksums |
5bf7773acb7cc10862e15b7d2e843e03b2c5195ecfb44dcc5d3b8c58e8ce4dbf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.0 {"installer":{"name":"uv","version":"0.10.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|