Why sandbox MCP tools
Many MCP servers that run code or shell commands execute them on your own machine, with your files, your SSH keys and your network. A sandbox-backed MCP server gives the assistant a real Linux machine to work in, and nothing on your laptop is in reach.
cpuos provides an MCP server to early-access teams. The example below builds a minimal one with the official TypeScript MCP SDK, so you can see exactly which tools the client gets and adapt them.
A minimal MCP server
npm install @modelcontextprotocol/sdk zod @cpuos/sdkimport { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js"import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js"import { Sandbox } from "@cpuos/sdk"import { z } from "zod"const server = new McpServer({ name: "cpuos-sandbox", version: "0.1.0" })let current: Sandbox | undefinedconst sandbox = async () => (current ??= await Sandbox.create({ template: "devbox", timeout: "1h" }))server.registerTool( "run_command", { description: "Run a shell command in an isolated Linux sandbox.", inputSchema: { command: z.string() }, }, async ({ command }) => { const run = await (await sandbox()).exec(command, { timeout: "5m" }) const text = [ "exit_code=" + run.exitCode, run.stdout.slice(-8000), run.stderr.slice(-4000), ].join("\n") return { content: [{ type: "text", text }] } })server.registerTool( "write_file", { description: "Write a text file in the sandbox.", inputSchema: { path: z.string(), content: z.string() }, }, async ({ path, content }) => { await (await sandbox()).files.write(path, content) return { content: [{ type: "text", text: "Wrote " + path }] } })server.registerTool( "preview_url", { description: "Public HTTPS URL for a port opened in the sandbox.", inputSchema: { port: z.number().int() }, }, async ({ port }) => ({ content: [{ type: "text", text: (await sandbox()).url(port) }], }))await server.connect(new StdioServerTransport())cpuos is in early access: @cpuos/sdk (npm) and cpuos (PyPI) ship to early-access teams first, and read the API key from CPUOS_API_KEY. The calls on this page show the current API shape.
Connect a client
Claude Desktop, Cursor and most MCP clients read a JSON file with an mcpServers map. Build the server, then point the client at it and pass the cpuos key in its environment.
{ "mcpServers": { "cpuos": { "command": "node", "args": ["/path/to/server.js"], "env": { "CPUOS_API_KEY": "<your cpuos key>" } } }}With a local model in an MCP-capable assistant such as Continue, both halves stay under your control: the model on your GPUs through gpuOS, the tools in cpuos sandboxes.
Official documentation: modelcontextprotocol.io