← 목록

Response to 'gVisor vs Firecracker for AI Agent Sandboxing' — what we learned auditing 8,764 MCP servers

devto 2026-07-08 원문 보기 ↗


I read @chunxiaoxx's excellent post MCP Security Patterns 2026: gVisor vs Firecracker for AI Agent Sandboxing and wanted to share what we actually found running gVisor in production.

We built MarketNow — a marketplace for MCP servers where every server gets audited. Our L2.5 layer uses gVisor (runsc) exactly as the article describes.

What the article gets right

The article correctly identifies the key tradeoff:

What we learned running gVisor on GitHub Actions

1. gVisor install needs sudo

The runner user can't write to /etc/docker/daemon.json without sudo:

sudo wget -q https://storage.googleapis.com/gvisor/releases/nightly/latest/runsc -O /usr/local/bin/runsc
sudo chmod +x /usr/local/bin/runsc
echo '{"runtimes":{"runsc":{"path":"/usr/local/bin/runsc"}}}' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker

2. Build-time network is needed

Don't put --network none on docker build — it blocks npm install from reaching registry.npmjs.org. Runtime isolation (docker run --network none) is what matters.

3. gVisor catches what seccomp can't predict

We found:

4. gVisor has compatibility issues

About 50% of MCP servers fail to start under gVisor because they use syscalls gVisor doesn't implement. This is a feature, not a bug — but it means you need a fallback (we use enhanced seccomp).

5. The fallback (enhanced seccomp) is also valuable

When gVisor isn't available, we use a strict seccomp profile that blocks:

Our roadmap (matching the article's recommendation)

The article suggests gVisor now, Firecracker later. That's exactly our plan:

Why Firecracker later? Because it needs KVM access, which GitHub Actions runners don't provide. We'd need to self-host runners on AWS (Firecracker is what powers Lambda and Fargate).

The 6-layer pipeline

For context, our full audit:

Results so far

8,764 MCP servers audited. 206 went through L2.5 gVisor sandbox:

Try it

Full methodology: marketnow.site/security

Example audit (Anthropic's filesystem MCP, 10/10): GitHub

If you want your MCP server audited: open an issue

Thanks to @chunxiaoxx for the original analysis — it's a great primer on the sandboxing landscape.