
LLM Sandbox is a Python library for developers building AI agents and applications that need to execute model-generated code. It runs that code in isolated containers on infrastructure you control, with Docker and Podman backends or Kubernetes for cluster deployments. The project is open source under the MIT license.
Container isolation separates generated code from the host system. You can limit CPU use, memory and execution time, control network access, and define custom security policies. Podman supports rootless containers. These controls address risks such as destructive file operations, unwanted network connections and code that consumes resources indefinitely.
The runtime supports Python, JavaScript, Java, C++ and Go, with dependency management for generated programs. It can capture plots and visualizations automatically and transfer files into and out of the sandbox. Custom container images let applications use their own execution environments. For notebook-style work, interactive Python sessions retain interpreter state between calls. Container pooling reuses prepared environments to reduce startup overhead when an application runs code frequently.
An MCP server gives assistants such as Claude Desktop access to sandboxed code execution and returns generated visualizations. LLM Sandbox also integrates with LangChain, LangGraph and LlamaIndex, and includes examples for the OpenAI Agents SDK and Claude Agent SDK.
Claim this page and we'll verify you by hand. LLM Sandbox gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find LLM Sandbox?Promote it
Something wrong or outdated on this page?
9.5KUpdated 2 days agoApache-2.0
Docker · Web#Guardrails#MCP#Tool calling
Higress is a self-hosted AI gateway for developers and teams managing model APIs and the tools their AI agents call. It puts LLM traffic and MCP servers behind a shared entry point, with authentication, traffic controls and monitoring. The open-source edition uses the Apache 2.0 license and runs locally in Docker without registration. Alibaba Cloud also offers a fully managed gateway.
15.6KUpdated 17 hours agoApache-2.0
Docker#Code execution#MCP
27.6KUpdated 1 day agoMIT
macOS · Windows · Linux#Code execution#MCP#Tool calling
12.8KUpdated 4 days agoApache-2.0
Docker#Agent Skills#Code execution#Distributed execution
1.2KUpdated 2 days agoApache-2.0
Linux · Docker#Code execution#Git integration#Guardrails
Coding Tools MCP gives AI chat apps and agents access to a codebase on your own machine through the Model Context Protocol (MCP). It's for developers who want their existing client to read files, edit code and run tests, with access confined to a chosen workspace. The Python server is open source under Apache 2.0 and can also run in Docker.
42.5KUpdated 10 hours agoApache-2.0
Docker · Web#Guardrails#Human approval#LLM tracing
OpenSandbox gives AI agents isolated working environments on infrastructure you control. It's open source under Apache 2.0 and runs locally with Docker or on a Kubernetes cluster. It's for developers building coding agents, browser automation, or applications that execute model-generated code.
Cua gives AI agents access to computers they can inspect and operate, with tools for desktop automation, local virtual machines, and hosted fleets. It's for developers building agents that work across native apps and browsers, or evaluating how well those agents complete computer tasks. You bring the agent and model.
AX is Google's self-hosted AI agent orchestrator for teams running autonomous workloads on a Kubernetes cluster. It uses Agent Substrate to isolate agent execution and manages the workspaces and model settings each task needs. The project is open source under Apache 2.0.
Agno is a Python framework and runtime for developers building customer-facing or internal AI agents. You can run its agent platform locally with Docker, on your own servers or in your cloud. The open-source framework uses the Apache 2.0 license, and the platform keeps sessions, memory, knowledge and traces in your database.