OpenRod moves your MCP servers into sandboxes without copying secrets
ilai456 · reddit · 2026-10-07
The builder of OpenRod (open source, Apache-2.0) explains how the tool ports MCP servers and Skills from Claude Code, Codex, or Cursor into NVIDIA OpenShell sandboxes without copying tokens or giving each MCP open internet access:
- Discovery: reads user-level configs on demand without touching source files.
- Stripping: env values, auth headers, and tokens are removed; manual review before saving; secret detection is best-effort.
- Intentional blocks: unsupported launchers, credential-dependent configs, binary assets, and unsafe links are blocked with reasons.
- Preparation: npm servers installed in throwaway sandboxes with lifecycle scripts disabled and pinned deps; only MCP initialization is checked, not tools.
- Network: each setup gets one managed allow rule of the hosts its MCPs actually reach; credential-receiving hosts stay out, and real secrets are injected outside the sandbox.
- OAuth: desktop sessions are never copied — re-authenticate inside the sandbox via the agent.
Try it with npx openrod (Node 22.13+, Docker, macOS Apple Silicon or Linux). The author proposes a manifest field for MCP servers to declare runtime hosts.
More from coding & agent
- Cursor's create-verification-skill makes agents run your app and film proof — gaganghotra_ · 2026-10-07
- YC demos recording walkthrough videos straight to cloud coding agents — ycombinator · 2026-10-07
- Atlassian and OpenAI team up to ground frontier models in enterprise context via Teamwork Graph — davidhoang · 2026-10-07
- Mirage's Tesseract + Opus 5.5 generated its entire launch video, exported to After Effects — aziz4ai · 2026-10-07
- Redditor proposes graph-based deterministic modeling to make LLM finance agents trustworthy — jonnylegs · 2026-10-07
- COLM 2026 poster presents scaling test-time compute for agentic coding — dan_fried · 2026-10-07