Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.
What it says
The record the registry holds
How you get it
There is no address to call. This one is a package you install and run yourself, wherever your assistant runs.
ghcr.io/ironsecco/ironclaw-mcp:v0.1.499 · oci
the recordCopied from the official MCP registry, exactly as it holds it.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.IronSecCo/ironclaw",
"description": "Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.",
"repository": {
"url": "https://github.com/IronSecCo/ironclaw",
"source": "github"
},
"version": "0.1.499",
"websiteUrl": "https://ironclaw.sh",
"packages": [
{
"registryType": "oci",
"identifier": "ghcr.io/ironsecco/ironclaw-mcp:v0.1.499",
"runtimeHint": "docker",
"transport": {
"type": "stdio"
},
"runtimeArguments": [
{
"description": "Remove the container when the MCP session ends (ephemeral by design).",
"type": "named",
"name": "--rm"
},
{
"description": "Keep stdin open for the MCP stdio transport.",
"type": "named",
"name": "-i"
},
{
"description": "Forward the control-plane URL from your own environment into the container; the value never appears in this listing.",
"isRequired": true,
"value": "IRONCLAW_CONTROLPLANE_URL",
"type": "named",
"name": "-e"
},
{
"description": "Forward the control-plane API token from your own environment into the container; the value never appears in this listing.",
"isRequired": true,
"value": "IRONCLAW_API_TOKEN",
"type": "named",
"name": "-e"
}
],
"environmentVariables": [
{
"description": "Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.",
"isRequired": true,
"format": "string",
"placeholder": "http://127.0.0.1:8787",
"name": "IRONCLAW_CONTROLPLANE_URL"
},
{
"description": "Bearer token for the control-plane API (the value the control-plane was started with).",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "IRONCLAW_API_TOKEN"
}
]
}
]
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-08-02T06:36:09.599065Z",
"publishedAt": "2026-08-02T06:36:09.599065Z",
"updatedAt": "2026-08-02T06:36:09.599065Z",
"isLatest": true
}
}
}
Make it installable
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
What this is
MCP server
application/mcp-server-record+jsonlocal · you run it yourselfversion 0.1.499last seen 2026-08-23
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.