Capability-based WASM sandbox for MCP tools — wasmtime, WASI-isolated, fuel/memory/time/I/O capped, signed execution records. Sub-ms, 8/8 attacks blocked.
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add ephemora-cell -- python -m ephemora-cell{
"mcpServers": {
"ephemora-cell": {
"command": "python",
"args": ["-m", "pip"]
}
}
}MCP Servers overview
# Ephemora Cell
### Secure execution for untrusted AI-generated code.
Run AI-generated code, MCP tools and plugins inside an enforced capability boundary — explicit resource limits, auditable execution records.
**8/8 attack vectors blocked · 424 tests · sub-millisecond warm execution**
Built for **AI agents, MCP tools, plugins, code interpreters, and other untrusted workloads.**
Fast, capability-based WASM execution: CPU, memory, time, I/O and filesystem budgets enforced per execution, with sign-ready execution records (RFC 8785 JCS canonicalization + ES256 `sign()`/`verify()` primitives).
<p align="center">
<a href="https://pypi.org/project/ephemora-cell/">
<img src="https://img.shields.io/pypi/v/ephemora-cell" alt="PyPI">
</a>
<a href="https://www.python.org/downloads/">
<img src="https://img.shields.io/badge/python-3.10%2B-blue" alt="Python 3.10+">
</a>
<a href="https://opensource.org/licenses/Apache-2.0">
<img src="https://img.shields.io/badge/license-Apache--2.0-green" alt="License">
</a>
<a href="https://github.com/MichaelS1011/ephemora-cell">
<img src="https://img.shields.io/badge/status-stable-brightgreen" alt="Status">
</a>
<a href="https://github.com/MichaelS1011/ephemora-cell/stargazers">
<img src="https://img.shields.io/github/stars/MichaelS1011/ephemora-cell" alt="GitHub stars">
</a>
</p>
<p align="center">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="assets/hero-dark.svg">
<img src="assets/hero-light.svg" alt="AI Agent → Ephemora Cell enforcement stack → bounded result">
</picture>
</p>
## The problem
AI agents increasingly need to write and execute code, call tools, and run plugins. The question that decides whether that is safe:
**How do you let an agent execute untrusted code without giving that code access to your host, your credentials, your network, or unlimited compute?**
```text
AI Agent ──▶ Tool / MCP ──▶ Ephemora Cell ──▶ WASM ──▶ bounded result
```
**Ephemora Cell** is a small, capability-based WASM execution runtime for exactly that job: an execution primitive — not an agent framework — that sits underneath your existing agent stack, MCP server, plugin system, or application.
## Every execution leaves evidence
Every tool call answers three questions at once — attached to the result as `_meta.execution`, canonicalized (RFC 8785 JCS) and signable:
| | Answer | Example fields |
|---|---|---|
| **RESULT** | what came back | `status`, `stdout`, `exit_code` |
| **COST** | what it cost | `fuel_consumed`, `elapsed_ms` |
| **POLICY** | under which rules it ran | memory limit, preopens, network policy, `wasmtime_version` |
"Verified. Not claimed." is a data field, not a slogan. Runnable demo: `python examples/signed_record_demo.py`.
## Quick Start
Three commands: install Cell, run something untrusted, read its audited receipt.
**1 — Install** (use a virtualenv; on Ubuntu ≥ 23.04 / Fedora a bare `pip install`
is refused by PEP 668. Windows: use Git Bash or WSL, and `python` instead of `python3`):
```bash
python3 -m venv .venv && source .venv/bin/activate
python -m pip install ephemora-cell
```
**2 — Run something untrusted** (the repo ships examples, or bring any `.wasm`):
```bash
git clone https://github.com/MichaelS1011/ephemora-cell.git && cd ephemora-cell
ephemora-cell run examples/hello.wasm
```
```text
Hello from Ephemora Cell!
```
**3 — Read the audited receipt** — same run, machine-readable. Here a hostile module
(`examples/fuel_bomb.wasm`) is given a 100-unit fuel budget and stopped, exactly as
budgeted:
```bash
ephemora-cell run examples/fuel_bomb.wasm --fuel 100 --json
```
```json
{
"status": "fuel_exhausted",
"exit_code": 0,
"fuel_consumed": 100,
"fuel_budget": 100,
"stdout_bytes": 0
}
```
Same from Python — every result carries status, cost and captured output:
```python
from ephemora_cell import run_wasm
result = run_wasm("examples/hello.wasm", max_fuel=1_000_000, timeout_seconds=30)
print(result.stdout) # captured output (10 KB cap)
print(result.status.name) # SUCCESS
print(result.elapsed_ms) # wall time
print(result.fuel_consumed) # compute actually used
```
**Where to next:** agent/tool isolation → [Secure MCP tool execution](#secure-mcp-tool-execution) (3-line setup) · CI gating for untrusted PRs → [GitHub Action](#untrusted-pr-code-in-github-actions) · CLI reference and usage recipes → [docs/recipes.md](docs/recipes.md). Something failed? The usual suspects are venv not activated, `python3` vs `python` on Windows, or a wrong `.wasm` path — [docs/recipes.md](docs/recipes.md) covers them.

*Real CLI session: install, first run, machine-readable `--json` report with the security baseline, a fuel bomb stopped at exactly 100/100 units, and an attack module (`exploit.wasm`) blocked at the WASI import layer. Verify every frame: the commands run as shown from a clone.*
## Why this matters
Agent-generated code is different from application code: it can be buggy, computationally unbounded, unexpectedly expensive — or hostile. The runtime must **enforce** boundaries, not document them. Every Cell run does:
- **Enforced, not promised** — fuel metering (CPU), memory caps, epoch-based wall-clock timeouts, output caps and I/O budgets are enforced per execution; the effective posture is attested in an execution record that is
canonicalized (RFC 8785 JCS) and sign-ready (`sign()`/`verify()` shipped).
- **Measured isolation advantage** — of the attack vectors that succeed against a stock Docker container (shell, fork, socket, host filesystem, symlink escape, …), all 8 are blocked here (live-verified, script in the repo).
- **Sub-millisecond warm execution** — 0.17 ms guest / 0.51 ms end-to-end (pooled, measured 2026-09-14; `benchmarks/results/`) makes sandboxing every call affordable instead of exceptional.
## What is enforced
Every execution runs under explicit limits — no opt-in security:
| Resource | Default |
|---|---|
| WASM memory | 128 MB (`Store.set_limits`) |
| Fuel / CPU budget | 1,000,000 (~13 fuel/iteration, R² = 1.000; 2026-09-14 re-measured, macOS arm64 — fuel counts are per-platform, not cross-platform) |
| Wall-clock timeout | 30 s (epoch interruption) |
| Captured stdout/stderr | 10 KB |
| Network | disabled — no socket APIs in WASI |
| Host filesystem | denied by default; 14 dangerous dirs blocked (`/dev`, `/proc`, `/sys`, …) |
| Process exec / fork | unavailable in WASI |
| Threading | disabled (`wasm_threads=False`) |
Additional controls: **I/O budgets** (`io_cpu_seconds=2.0` / `io_budget_bytes=64 MiB` — walls for host work, not just guest compute), **dual-ABI** (WASI Preview1 + WASI 0.2 components, opt-in), **memory64 opt-in**, **GC-heap declared cap** (recorded in the security baseline; fuel remains the effective bound), **named state** (64 entries · 256 KiB · 1 MiB per session), and an **egress sidecar** reference mediator (allowlist-validated host-side API calls — [docs/egress_patterns.md](docs/egress_patterns.md)).
## Security
The guest receives only the capabilities explicitly made available to it. Live verification of eight attack classes ([`benchmarks/verify_8_vectors.py`](benchmarks/verify_8_vectors.py)):
| Attack class | Docker | Ephemora Cell |
|---|---|---|
| Shell (`os.system`) / fork / network sockets | ALLOWED | **BLOCKED** — APIs don't exist in WASI |
| fsync (`os.fsync`) | ALLOWED | **BLOCKED** — import-level rejection |
| Host filesystem (`/etc/passwd`) | ALLOWED | **BLOCKED** — preopen default-deny |
| Symlink escape | ALLOWED | **BLOCKED** — dangerous directory filter |
| Multi-threading | ALLOWED | **BLOCKED** — `wasm_threads=False` |
| Environment access | ALLOWED | **BLOCKED** — controlled via `allow_env` |
**Result: 8/8 attack vectors blocked (live-verified); Docker baselines are measured live per run — never hardcoded.**

*Same eight attack primitives, measured live (Docker probe 2026-09-02, Cell probe 2026-09-12 — now with a positive control proving the preopen grant works): a stock `python:3.12-slim` container lets every one through (0/8 blocked), the Ephemora Cell boundary blocks all eight (8/8). Reproduce both columns:*
```bash
python assets/demo_attack_probe.py # left column -> 0/8 blocked (stock Docker)
python benchmarks/verify_8_vectors.py # right column -> 8/8 blocked (Ephemora Cell)
```
**How the 8/8 is measured.**
- **Environment:** MacBook Pro M5, macOS arm64, wasmtime 47.0.1
- **Docker probe (2026-09-02):** stock `python:3.12-slim` via `docker run --rm` — the measured exit code decides ALLOWED vs BLOCKED, nothing hardcoded
- **Cell probe (2026-09-12):** `verify_8_vectors.py` against the live runtime, same eight attack intents expressed per platform (WASM guests for the Cell side, `python3 -c` bodies for Docker; verification method detailed in [`docs/security_posture.md`](docs/security_posture.md))
- **Workload:** self-contained payloads, no downloads, no credentials
- **Attack classes (8):** shell (`os.system`), fork, network socket, fsync, host filesystem read (`/etc/passwd`), symlink escape, threading, environment leak
- **Positive control:** each blocked vector is paired with a granted-capability control that **must succeed** on the same sandbox config (e.g. the symlink test's real target file must open errno 0) — if the control fails, the harness is broken, not the sandbox, and the run does not count
- **Raw evidence:** `benchmarks/results/2026-09-02/01_docker_attack_probe.json` + `02_cell_8_vector_verify.json`
**MCP CVE replays.** The official MCP reference servers have real, patched CVEs against this exact surface. [`benchmarks/mcp_cve_replay.py`](benchmarks/mcp_cve_replay.py) replays themWhat people ask about ephemora-cell
What is MichaelS1011/ephemora-cell?
+
MichaelS1011/ephemora-cell is mcp servers for the Claude AI ecosystem. Capability-based WASM sandbox for MCP tools — wasmtime, WASI-isolated, fuel/memory/time/I/O capped, signed execution records. Sub-ms, 8/8 attacks blocked. It has 39 GitHub stars and its last recorded update is dated 2026-09-17.
How do I install ephemora-cell?
+
You can install ephemora-cell by cloning the repository (https://github.com/MichaelS1011/ephemora-cell) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is MichaelS1011/ephemora-cell safe to use?
+
Our security agent has analyzed MichaelS1011/ephemora-cell and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains MichaelS1011/ephemora-cell?
+
MichaelS1011/ephemora-cell is maintained by MichaelS1011. The last recorded GitHub activity is dated 2026-09-17, with 5 open issues.
Are there alternatives to ephemora-cell?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy ephemora-cell to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/michaels1011-ephemora-cell)<a href="https://claudewave.com/repo/michaels1011-ephemora-cell"><img src="https://claudewave.com/api/badge/michaels1011-ephemora-cell" alt="Featured on ClaudeWave: MichaelS1011/ephemora-cell" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ
The fastest path to AI-powered full stack observability, even for lean teams.