IronClaw

Sandboxed shell exec for MCP clients: runs untrusted agent commands in a gVisor container.

ironsecco 14
Claude CodeClaude DesktopGeneric
View source ↗

IronClaw is a self-hosted platform for running AI agents in gVisor-sandboxed containers, so untrusted commands cannot access the host or persist beyond the session. Each agent session gets network isolation and an encrypted per-session message queue, and configuration changes require human approval through a gateway. IronClaw is open source under AGPLv3, with a commercial license available for teams that need different terms.

Source

Repository: https://github.com/ironsecco/ironclaw

Maintain IronClaw?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[IronClaw on getagentictools](https://getagentictools.com/mcp/ironsecco-ironclaw?ref=badge)