mcp-v8

Infrastructure · tested 2026-08-19 · re-test due 2026-11-19 · by the Hlido desk, not the vendor

In short: A code-execution MCP server that hands an agent one run_js tool inside a locked-down V8 isolate — an ambitious 'agents write code, not tool-calls' bet with a serious security story.

Quick answer

mcp-v8 scores 80/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-19). STEADY (80) for a well-architected code-execution MCP server with sandbox-by-default capabilities (OPA/Rego-gated network/FS/subprocess), durable heap-snapshot state, JWKS auth and production transports, marked low-mediu

mcp-v8 is a Model Context Protocol server that executes JavaScript and TypeScript inside a V8 isolate. Instead of exposing dozens of narrow tools, it gives an agent a single run_js tool: the agent writes code that can loop, branch, transform data and chain other MCP servers, which the vendor argues costs fewer tokens than equivalent tool-call sequences. In its default stateful mode it persists the V8 heap as a content-addressed snapshot so state survives across calls — a genuinely useful primitive for multi-turn agent work. The security framing is the strongest part of the surface: network fetch, filesystem, subprocess, WASM and ES-module imports are all off by default and each is gated by OPA/Rego policy, requests can be authenticated with JWT/JWKS, and the server can form a Raft cluster to replicate session metadata. It speaks stdio, Streamable HTTP and SSE with a REST sidecar. This is documentation, not a running audit — Hlido did not execute code against a live instance, so the isolation and policy enforcement are described capabilities rather than tested ones. But the design is coherent, the sandbox-first defaults are the right ones for handing an LLM an execution surface, and the docs are structured (install / tutorials / how-to / concepts / reference) rather than hype.

Why STEADY

STEADY (80) for a well-architected code-execution MCP server with sandbox-by-default capabilities (OPA/Rego-gated network/FS/subprocess), durable heap-snapshot state, JWKS auth and production transports, marked low-medium confidence because the review is surface-only — the isolation, policy gating and clustering are documented, not exercised against a live instance by Hlido. Not VITAL absent hands-on verification of the sandbox that is the whole value proposition.

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-a83a7a4d13ed9846-r33drichards-github-io). Our own captures — not vendor marketing material.

mcp-v8 — run screenshot 1 (home.png)
home.png
mcp-v8 — run screenshot 2 (page_.png)
page_.png
mcp-v8 — run screenshot 3 (page_.png)
page_.png
mcp-v8 — run screenshot 4 (page__.png)
page__.png

What it does well

What it fails at

Red flags

Best for

  • Agent builders who want a code-interpreter tool that composes other MCP servers and persists state across calls
  • Teams comfortable authoring OPA/Rego policies to scope exactly what agent-run code may touch
  • Advanced MCP deployments needing auth (JWKS) and multi-node replication

Not recommended for

  • Anyone wanting a zero-config tool — the security depends on policies you write
  • Environments that cannot accept agent-driven code execution under any sandbox
  • Users needing a vendor-audited, certified isolation guarantee

Related agents

Agent relevance

API MCP Behavioral-testable

Agentic-Commerce Readiness 59/100 · INTEGRABLE

Independent readiness for agent delegation & transaction. How it’s scored · check live

Runs as an MCP server (stdio, Streamable HTTP or SSE, plus a REST sidecar). An MCP client calls a single run_js tool; capabilities beyond compute are granted per OPA/Rego policy and requests can be JWKS-authenticated.

Agent-friendly score: 9/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-2+editorial-narrative-v2 · Methodology version 2026.05 · Next review due 2026-11-19

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/r33drichards-mcp-js.svg)](https://hlido.eu/check/?agent=r33drichards-mcp-js)

HTML

<a href="https://hlido.eu/check/?agent=r33drichards-mcp-js"><img src="https://hlido.eu/badge/r33drichards-mcp-js.svg" alt="Hlido trust score"></a>