How Plugsky MCP works in practice
Everything in this guide runs on Plugskyโs live MCP endpoint (https://plugsky.com/mcp) or the npm bridge (npx -y @plugsky/mcp). A client request flows: JSON-RPC over Streamable-HTTP → auth (API key or OAuth 2.1 + Dynamic Client Registration with fine-grained scopes) → tool router → the service you asked for. Model calls run behind a 7-tier provider failover chain; browsing renders with headless Chromium; transcripts come from real captions and Groq Whisper; images generate on FLUX; code runs in a sandbox with no network; memory persists in your account (Postgres-backed); and every tool call is metered per user on your dashboard.
Relevant live tools for this article: plugsky_code_run โ sandboxed Python: no network, 256MB, 30s, metered.
How to run Python from Claude or Cursor (code sandbox MCP)
Direct answer
To run Python from Claude or Cursor in 2026, install a code-sandbox MCP: E2B (best cold-start), Daytona (persistent envs), Modal, Cloudflare Sandbox, Vercel Sandbox, or Plugsky's
plugsky_code_run(roadmap Q4 2026, GPU-optional, sovereign). The MCP spawns an isolated micro-VM, runs your code, and returns stdout + generated files. This is the killer capability behind ChatGPT Advanced Data Analysis โ now bring it to any MCP-aware client.
Key facts
| Best MCPs today | E2B, Daytona, Modal, Cloudflare Sandbox, Vercel Sandbox |
| Best cold-start | E2B (<1s) |
| Best persistent envs | Daytona (dev environments live for days) |
| GPU-capable | Modal, Cloudflare, Plugsky (Q4 2026) |
| Auth | Bearer (all), OAuth (Daytona, Cloudflare) |
| Free tier | Modest on all; self-host E2B open-source for unlimited |
| Package installs supported | โ all |
| Persistent files | โ (with session/persist flags) |
| Best for data analysis | E2B + matplotlib/pandas preinstalled |
TL;DR
- Code-sandbox MCPs give agents a real Python/Node runtime without leaving the client.
- E2B wins on cold-start speed; Daytona wins on persistent state; Cloudflare/Modal/Plugsky win on GPU.
- Enterprise pattern: use Plugsky Sovereign to run code on your own GPUs โ no code leaves your VPC.
- Best pairing: sandbox MCP + web MCP + Plugsky models = a full data-analysis agent.
How it works
Option 1: E2B
{ "mcpServers": { "e2b": { "url": "https://mcp.e2b.dev", "headers": {"Authorization":"Bearer e2b_..."} } } }
Fast cold-start. Great for one-shot analysis.
Option 2: Plugsky plugsky_code_run (Q4 2026)
When shipped, plugsky_code_run gives you sandboxed Python/Node inside the same MCP that already exposes 36 models and your RAG. GPU-optional, sovereign-optional.
Option 3: Daytona for persistent envs
Best when the agent needs a long-lived environment (multi-day project, warm-cached deps).
Winning patterns
- CSV analysis โ upload via Plugsky RAG, then
plugsky_code_runpandas over it. - Chart generation โ matplotlib output as PNG returned as MCP resource.
- API testing โ write curl-equivalents in Python, run instantly.
- Data pipeline prototyping โ hit a DB, transform, write CSV back to a collection.
- ML experiments โ with GPU-enabled sandbox (Plugsky, Modal), fine-tune small models mid-chat.
Security considerations
- Sandbox isolation: micro-VMs are the safest โ kernel isolation, no shared filesystem, ephemeral by default.
- Egress control: enterprise deployments should pin which domains sandboxes can reach.
- Time limits: cap execution time (all sandboxes support this).
- Data leaving your network: use Plugsky Sovereign or self-hosted E2B to keep code+data on-prem.
Comparison โ code sandbox MCPs
| Cold-start | <1s | ~10s | ~3s | ~1s | ~2s | ~1s |
| Persistent envs | โ ๏ธ | โ | โ ๏ธ | โ | โ | โ |
| GPU | โ | โ ๏ธ | โ | โ | โ | โ |
| Sovereign / on-prem | Self-host | โ | โ | โ | โ | โ |
| Free tier | Modest | Modest | Modest | Modest | Modest | Yes (roadmap) |
| OAuth 2.1 | โ ๏ธ | โ | โ ๏ธ | โ | โ ๏ธ | โ |
FAQ
Q: Is running Python from Claude safe?
A: The code runs in an isolated micro-VM โ not on your machine. Safe as long as you trust the sandbox provider and set egress limits.
Q: Does Plugsky already have plugsky_code_run?
A: On the roadmap for Q4 2026. Today, pair Plugsky's models with an E2B or Daytona MCP.
Q: Can the sandbox access my local files?
A: Not by default โ sandboxes are isolated. To share files, upload them via Plugsky RAG (plugsky_documents_ingest) and let the sandbox fetch from the collection.
Q: Can I install pip packages?
A: Yes. Each sandbox supports pip install. First call in a fresh VM is slower; subsequent calls in a persistent env are instant.
Q: What about Node.js?
A: All the top sandbox MCPs support Node. E2B, Modal, and Plugsky all offer Node runtimes.
Q: GPU access?
A: Modal and (upcoming) Plugsky offer GPU sandboxes. Use for ML experiments, embeddings, or vision workloads.
Trust & sources
- Author: Mustafa Hasan.
- Last updated: {DATE}.
- References: E2B docs, Daytona docs, Modal docs.
- Related: [Best MCP servers 2026](/blog/best-mcp-servers-2026) ยท [Plugsky MCP roadmap](/plugsky-mcp-playbook).
Plugsky (2026). “How to run Python from Claude or Cursor (code sandbox MCP)”. Plugsky. Available at: https://plugsky.com/articles/run-python-from-claude-cursor-code-sandbox-mcp (last updated 2026-09-30).