← Back to Plugins
MCP Server MCP

io.github.IronSecCo/ironclaw

github By github 👁 1 views ▲ 0 votes

Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.

Homepage Verified source GitHub

Install

oci:ghcr.io/ironsecco/ironclaw-mcp:v0.1.499

Configuration Example

{
  "remotes": [],
  "packages": [
    {
      "registryType": "oci",
      "identifier": "ghcr.io/ironsecco/ironclaw-mcp:v0.1.499",
      "runtimeHint": "docker",
      "transport": {
        "type": "stdio"
      },
      "runtimeArguments": [
        {
          "description": "Remove the container when the MCP session ends (ephemeral by design).",
          "type": "named",
          "name": "--rm"
        },
        {
          "description": "Keep stdin open for the MCP stdio transport.",
          "type": "named",
          "name": "-i"
        },
        {
          "description": "Forward the control-plane URL from your own environment into the container; the value never appears in this listing.",
          "isRequired": true,
          "value": "IRONCLAW_CONTROLPLANE_URL",
          "type": "named",
          "name": "-e"
        },
        {
          "description": "Forward the control-plane API token from your own environment into the container; the value never appears in this listing.",
          "isRequired": true,
          "value": "IRONCLAW_API_TOKEN",
          "type": "named",
          "name": "-e"
        }
      ],
      "environmentVariables": [
        {
          "description": "Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.",
          "isRequired": true,
          "format": "string",
          "placeholder": "http://127.0.0.1:8787",
          "name": "IRONCLAW_CONTROLPLANE_URL"
        },
        {
          "description": "Bearer token for the control-plane API (the value the control-plane was started with).",
          "isRequired": true,
          "format": "string",
          "isSecret": true,
          "name": "IRONCLAW_API_TOKEN"
        }
      ]
    }
  ]
}
mcp model-context-protocol oci

Comments

Sign in to leave a comment

Loading comments...