trackmcp
Back to directory
mcpc-tech

code-runner-mcp

View on GitHub

Run JavaScript/Python code in a secure sandbox with support for `any package import`.

5 stars TypeScriptOthers Updated May 22, 2026

Documentation

Code Runner MCP

JSR
npm

Let AI execute JavaScript/Python code with any package imports!

Core Value

  • Secure Sandbox: Isolated execution environment protecting your host system
  • Install-on-Demand: Dynamically import any npm/PyPI packages
  • Reduce Hallucinations: Let AI verify logic by executing code
  • Quick Validation: Test if packages meet your needs without local

installation

Installation

Install the bundled agent skill so your AI assistant knows how to use

`code-runner-mcp` out of the box:

bash
npx skills add mcpc-tech/code-runner-mcp

This installs the skill into your project's `.agent/skills/` directory.

Compatible with Claude Code, Cursor, Windsurf, GitHub Copilot, VS Code, and

more.

JSR

bash
deno add jsr:@mcpc/code-runner-mcp

Package: `@mcpc/code-runner-mcp`

npm

bash
npm install @mcpc-tech/code-runner-mcp

Package: `@mcpc-tech/code-runner-mcp`

Quick Start

json
{
  "mcpServers": {
    "code-runner": {
      "command": "deno",
      "args": ["run", "--allow-all", "jsr:@mcpc/code-runner-mcp/bin"],
      "env": {
        "DENO_PERMISSION_ARGS": "--allow-net",
        "NODEFS_ROOT": "/tmp",
        "NODEFS_MOUNT_POINT": "/tmp"
      },
      "transportType": "stdio"
    }
  }
}

Option 2: Using Node.js

json
{
  "mcpServers": {
    "code-runner": {
      "command": "npx",
      "args": [
        "-y",
        "deno",
        "run",
        "--allow-all",
        "npm:@mcpc-tech/code-runner-mcp@latest"
      ],
      "env": {
        "DENO_PERMISSION_ARGS": "--allow-net",
        "NODEFS_ROOT": "/tmp",
        "NODEFS_MOUNT_POINT": "/tmp"
      },
      "transportType": "stdio"
    }
  }
}

> Note: Uses `npx` to install and run Deno on demand — no separate Deno

> installation required. `--experimental-wasm-stack-switching` cannot be passed

> via `NODE_OPTIONS` (Node.js rejects it), but works as a direct CLI flag.

Use Cases

JavaScript/TypeScript

javascript
// Import npm packages directly to test functionality
import { z } from "npm:zod";
import { serve } from "jsr:@std/http";

const schema = z.object({ name: z.string() });
console.log(schema.parse({ name: "test" }));

Python

python
# Dynamically install and use Python packages
import requests
response = requests.get("https://api.github.com")
print(f"Status code: {response.status_code}")

Package Mapping

When import names differ from PyPI package names, use the `packages` parameter:

python
# sklearn -> scikit-learn, PIL -> Pillow
from sklearn.datasets import load_iris
data = load_iris()
print(data.feature_names)

Use `packages: {"sklearn": "scikit-learn"}`

File System Access

python
# Access host file system (via NODEFS_ROOT and NODEFS_MOUNT_POINT)
import os
files = os.listdir('/tmp')  # List files at the mount point
print(f"Found {len(files)} files")

Environment Variables

VariableDescriptionDefault
`ALLOWED_TOOLS`Selectively enable tools: `all`, `python`, `javascript`, `js`, or comma-separated (e.g., `python,javascript`)`all`
`DENO_PERMISSION_ARGS`Additional Deno permissions for JS/TS execution (e.g., `--allow-net`, `--allow-all`)-
`NODEFS_ROOT`Host file system root directory path for Python access-
`NODEFS_MOUNT_POINT`Mount point path in Python environment (defaults to `NODEFS_ROOT`)-
`PYODIDE_PACKAGE_BASE_URL`Custom package download source for Pyodide (e.g., private mirror CDN)-
`PYODIDE_PACKAGE_CACHE_DIR`Custom package cache directory for Pyodide packages (Pyodide v0.28.1+)-
`SILENT`Suppress console log output. Set to `"true"` or `"1"` to silence server-side logs (e.g., package install messages)-

Tool Selection Examples

json
// Enable only Python
{ "ALLOWED_TOOLS": "python" }

// Enable only JavaScript
{ "ALLOWED_TOOLS": "javascript" }

// Enable both (default)
{ "ALLOWED_TOOLS": "python,javascript" }

Security Features

  • Deno Sandbox: Strict permission control with explicit authorization
  • Pyodide WASM: WebAssembly isolated environment
  • File System Isolation: Controlled host file access

Technical Architecture

  • JavaScript/TypeScript: Powered by Deno runtime
  • Python: Powered by Pyodide WebAssembly technology
  • Package Management: Dynamic installation from npm, JSR, and PyPI

Issues & Feedback:

GitHub Issues\

Repository:

GitHub Repository

Frequently asked questions

What is code-runner-mcp?

code-runner-mcp is Run JavaScript/Python code in a secure sandbox with support for `any package import`.

How do I install code-runner-mcp?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is code-runner-mcp open source?

Yes — it is hosted on GitHub at https://github.com/mcpc-tech/code-runner-mcp and has 5 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP