{"servers":[{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.216","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.216","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-05T22:11:46.437816Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.217","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.217","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-06T06:11:25.696807Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.218","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.218","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-06T09:40:20.786433Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.219","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.219","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-06T09:45:54.204775Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.220","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.220","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-06T11:02:21.892984Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.221","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.221","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-06T11:25:06.636642Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.223","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.223","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-07T04:12:47.066011Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.227","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.227","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-07T04:17:50.094392Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.228","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.228","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-07T04:23:14.298099Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.230","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-controlplane:v0.1.230","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"IronClaw launches each sandbox_exec run as a sibling gVisor container; it needs the host Docker socket to do so. This grants the MCP server control of the host Docker daemon -- review before enabling.","isRequired":true,"value":"/var/run/docker.sock:/var/run/docker.sock","type":"named","name":"-v"},{"description":"Override the control-plane daemon entrypoint to run the bundled ironctl MCP server instead.","value":"ironctl","type":"named","name":"--entrypoint"}],"packageArguments":[{"value":"mcp","type":"positional"},{"value":"serve","type":"positional"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"deprecated","statusChangedAt":"2026-07-07T07:08:22.434788Z","statusMessage":"Superseded: this listing launched IronClaw via a host Docker-socket mount, which we do not endorse. A socket-free ironclaw-mcp image is in progress (IRO-414); the listing will be re-published against it.","publishedAt":"2026-07-07T06:23:48.237388Z","updatedAt":"2026-07-07T07:08:22.434788Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.404","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.404","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-28T23:44:39.866294Z","publishedAt":"2026-07-28T23:44:39.866294Z","updatedAt":"2026-07-28T23:44:39.866294Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.407","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.407","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T00:03:03.727008Z","publishedAt":"2026-07-29T00:03:03.727008Z","updatedAt":"2026-07-29T00:03:03.727008Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.413","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.413","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T05:03:39.688108Z","publishedAt":"2026-07-29T05:03:39.688108Z","updatedAt":"2026-07-29T05:03:39.688108Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.414","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.414","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T05:18:49.903296Z","publishedAt":"2026-07-29T05:18:49.903296Z","updatedAt":"2026-07-29T05:18:49.903296Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.416","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.416","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T05:37:13.534392Z","publishedAt":"2026-07-29T05:37:13.534392Z","updatedAt":"2026-07-29T05:37:13.534392Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.417","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.417","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T08:44:25.20111Z","publishedAt":"2026-07-29T08:44:25.20111Z","updatedAt":"2026-07-29T08:44:25.20111Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.418","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.418","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T09:08:30.277964Z","publishedAt":"2026-07-29T09:08:30.277964Z","updatedAt":"2026-07-29T09:08:30.277964Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.419","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.419","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T09:23:23.627756Z","publishedAt":"2026-07-29T09:23:23.627756Z","updatedAt":"2026-07-29T09:23:23.627756Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.420","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.420","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T12:03:04.190198Z","publishedAt":"2026-07-29T12:03:04.190198Z","updatedAt":"2026-07-29T12:03:04.190198Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.421","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.421","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T12:09:13.183477Z","publishedAt":"2026-07-29T12:09:13.183477Z","updatedAt":"2026-07-29T12:09:13.183477Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.423","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.423","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T14:24:04.715453Z","publishedAt":"2026-07-29T14:24:04.715453Z","updatedAt":"2026-07-29T14:24:04.715453Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.425","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.425","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T21:12:19.764714Z","publishedAt":"2026-07-29T21:12:19.764714Z","updatedAt":"2026-07-29T21:12:19.764714Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.426","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.426","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T21:29:21.041309Z","publishedAt":"2026-07-29T21:29:21.041309Z","updatedAt":"2026-07-29T21:29:21.041309Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.428","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.428","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-29T22:46:49.583126Z","publishedAt":"2026-07-29T22:46:49.583126Z","updatedAt":"2026-07-29T22:46:49.583126Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.430","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.430","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T02:28:39.490787Z","publishedAt":"2026-07-30T02:28:39.490787Z","updatedAt":"2026-07-30T02:28:39.490787Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.432","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.432","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T02:47:11.71981Z","publishedAt":"2026-07-30T02:47:11.71981Z","updatedAt":"2026-07-30T02:47:11.71981Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.433","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.433","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T03:18:26.502853Z","publishedAt":"2026-07-30T03:18:26.502853Z","updatedAt":"2026-07-30T03:18:26.502853Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.434","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.434","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T03:41:42.166318Z","publishedAt":"2026-07-30T03:41:42.166318Z","updatedAt":"2026-07-30T03:41:42.166318Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.437","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.437","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T04:57:11.448603Z","publishedAt":"2026-07-30T04:57:11.448603Z","updatedAt":"2026-07-30T04:57:11.448603Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.IronSecCo/ironclaw","description":"Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.","repository":{"url":"https://github.com/IronSecCo/ironclaw","source":"github"},"version":"0.1.438","websiteUrl":"https://ironclaw.sh","packages":[{"registryType":"oci","identifier":"ghcr.io/ironsecco/ironclaw-mcp:v0.1.438","runtimeHint":"docker","transport":{"type":"stdio"},"runtimeArguments":[{"description":"Remove the container when the MCP session ends (ephemeral by design).","type":"named","name":"--rm"},{"description":"Keep stdin open for the MCP stdio transport.","type":"named","name":"-i"},{"description":"Forward the control-plane URL from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_CONTROLPLANE_URL","type":"named","name":"-e"},{"description":"Forward the control-plane API token from your own environment into the container; the value never appears in this listing.","isRequired":true,"value":"IRONCLAW_API_TOKEN","type":"named","name":"-e"}],"environmentVariables":[{"description":"Base URL of your running IronClaw control-plane, e.g. http://127.0.0.1:8787. This image is a thin client with no host privilege: it delegates every sandbox_exec run to the control-plane, which owns the hardened gVisor launch. Unset means no backend and the tool fails closed.","isRequired":true,"format":"string","placeholder":"http://127.0.0.1:8787","name":"IRONCLAW_CONTROLPLANE_URL"},{"description":"Bearer token for the control-plane API (the value the control-plane was started with).","isRequired":true,"format":"string","isSecret":true,"name":"IRONCLAW_API_TOKEN"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-07-30T05:02:45.133825Z","publishedAt":"2026-07-30T05:02:45.133825Z","updatedAt":"2026-07-30T05:02:45.133825Z","isLatest":false}}}],"metadata":{"nextCursor":"io.github.IronSecCo/ironclaw:0.1.438","count":30}}
