Odel
mcp server

mcp server

Local
@declaw-ai1TypeScriptApache-2.0Updated 3w ago

Secure Firecracker microVM sandboxes for AI agents: network policy, PII & injection guardrails.

Declaw MCP Server

MCP server for Declaw — secure sandbox execution for AI agents with network policies, PII scanning, prompt injection defense, and audit logging.

Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool.

Quick Start

Claude Desktop / Cursor / Windsurf

Add to your MCP config:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key"
      }
    }
  }
}

Claude Code

claude mcp add declaw -- npx -y @declaw/mcp-server

Set DECLAW_API_KEY in your environment.

Tools

ToolDescription
create_sandboxCreate a secure sandbox with configurable security policies
run_commandExecute a shell command inside a sandbox
read_fileRead a file from a sandbox
write_fileWrite a file to a sandbox
list_filesList directory contents in a sandbox
kill_sandboxDestroy a sandbox
list_sandboxesList all active sandboxes

Security Presets

When creating a sandbox, choose a security preset:

  • none — No guardrails. Full internet access.
  • standard (default) — PII scanning + audit logging. Full internet access.
  • strict — PII scanning + prompt injection defense + audit logging + network deny-all.

You can also pass allowed_domains to restrict outbound traffic to specific domains:

create_sandbox with template="python", security_preset="strict", allowed_domains=["pypi.org", "github.com"]

Why Declaw?

DeclawOther Sandbox Providers
Sandbox executionYesYes
Non-bypassable network controlsYes??
PII scanningYesNo
Injection defenseYesNo
Full audit trailYesBasic
SnapshotsYesVaries
Multiple templates8 built-inVaries
Interactive stdioYesVaries

Environment Variables

VariableRequiredDescription
DECLAW_API_KEYYesYour Declaw API key
DECLAW_DOMAINNoCustom API domain (for on-prem deployments)

On-Prem

For self-hosted Declaw deployments, set the domain:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key",
        "DECLAW_DOMAIN": "declaw.internal.company.com"
      }
    }
  }
}

License

Apache-2.0