Back to Browse

Declaw Ai MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Secure Firecracker microVM sandboxes for AI agents: network policy, PII & injection guardrails.

About

Secure Firecracker microVM sandboxes for AI agents: network policy, PII & injection guardrails.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (5 strong, 6 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

8 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Declaw API key (create one at https://declaw.ai).Required

Environment variable: DECLAW_API_KEY

Optional override for the Declaw API domain (for self-hosted deployments).Optional

Environment variable: DECLAW_DOMAIN

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-declaw-ai-mcp-server": {
      "env": {
        "DECLAW_DOMAIN": "your-declaw-domain-here",
        "DECLAW_API_KEY": "your-declaw-api-key-here"
      },
      "args": [
        "-y",
        "@declaw/mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Declaw MCP Server

MCP server for Declaw — secure sandbox execution for AI agents with network policies, PII scanning, prompt injection defense, and audit logging.

Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any MCP-compatible AI tool.

Quick Start

Claude Desktop / Cursor / Windsurf

Add to your MCP config:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key"
      }
    }
  }
}

Claude Code

claude mcp add declaw -- npx -y @declaw/mcp-server

Set DECLAW_API_KEY in your environment.

Tools

ToolDescription
create_sandboxCreate a secure sandbox with configurable security policies
run_commandExecute a shell command inside a sandbox
read_fileRead a file from a sandbox
write_fileWrite a file to a sandbox
list_filesList directory contents in a sandbox
kill_sandboxDestroy a sandbox
list_sandboxesList all active sandboxes

Security Presets

When creating a sandbox, choose a security preset:

  • none — No guardrails. Full internet access.
  • standard (default) — PII scanning + audit logging. Full internet access.
  • strict — PII scanning + prompt injection defense + audit logging + network deny-all.

You can also pass allowed_domains to restrict outbound traffic to specific domains:

create_sandbox with template="python", security_preset="strict", allowed_domains=["pypi.org", "github.com"]

Why Declaw?

DeclawOther Sandbox Providers
Sandbox executionYesYes
Non-bypassable network controlsYes??
PII scanningYesNo
Injection defenseYesNo
Full audit trailYesBasic
SnapshotsYesVaries
Multiple templates8 built-inVaries
Interactive stdioYesVaries

Environment Variables

VariableRequiredDescription
DECLAW_API_KEYYesYour Declaw API key
DECLAW_DOMAINNoCustom API domain (for on-prem deployments)

On-Prem

For self-hosted Declaw deployments, set the domain:

{
  "mcpServers": {
    "declaw": {
      "command": "npx",
      "args": ["-y", "@declaw/mcp-server"],
      "env": {
        "DECLAW_API_KEY": "your-api-key",
        "DECLAW_DOMAIN": "declaw.internal.company.com"
      }
    }
  }
}

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!