THRONE
See report Verify server

registry / record

@e2b/mcp-server

npm / sealed 2026-06-16 / No. 37a04a1c

Does @e2b/mcp-server MCP work in Claude Code and Cursor? Throne executed @e2b/mcp-server mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: fit. Is @e2b/mcp-server mcp safe? Static security scan: no findings under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @e2b/mcp-server sealed
Upstream notice: the maintainer has deprecated this packagePackage no longer supported. Contact Support at https://www.npmjs.com/support for more info.
receiptsealed evidence
scan id
37a04a1ce5a44eb0a378f89e9d27e1ba
target
@e2b/mcp-server
sealed at
2026-06-16 17:28:46Z
evidence hash
sha256:6e6bf00ddb698fa8f0253224ca614b88ed41931d1c1dd446c8cd35c49fab24d2
01connectPASS714ms

initialize ok: server e2b-mcp-server 0.1.0, negotiated protocolVersion 2025-06-18, capabilities ['resources', 'tools']

02discoverPASS7ms

supported: tools/list (1 tools); method not found (tolerated): resources/list, prompts/list

03validate_schemasPASS1ms

all 1 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS327ms

called 1 of 1 tools (cap 10, strategy=serial): 0 ok, 1 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.5s

structured error responses, connection survived, wrong_type_args: run_code:error(-32602); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: error(-32601); recovery: accepted (returned result); cancellation: error(-32601); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE1ms

resources capability not declared

08concurrent_callsWARN83ms

ladder 1 overlapping run_code calls: max_observed_stable_concurrency=1; all ids answered exactly once, but every call returned an error (error -32603: 401: authorization header is missing), the tool may need runtime dependencies this sandbox does not provide

09reconnectPASS686ms

transport closed and relaunched; re-handshake ok (protocolVersion 2025-06-18, first session was 2025-06-18)

01connectPASS1.3s

initialize ok: server e2b-mcp-server 0.1.0, negotiated protocolVersion 2025-06-18, capabilities ['resources', 'tools'] [request_strategy=pipelined, connection_count=2, second connection established]

02discoverPASS6ms

supported: tools/list (1 tools); method not found (tolerated): resources/list, prompts/list; notes: connection 2 confirms 1 tools

03validate_schemasPASS0ms

all 1 tool inputSchemas are valid JSON Schema

04smoke_test_toolsPASS101ms

called 1 of 1 tools (cap 10, strategy=pipelined): 0 ok, 1 returned tool-level errors (expected for synthesized args)

05error_handlingPASS4.5s

structured error responses, connection survived, wrong_type_args: run_code:error(-32602); unknown_method: error(-32601); invalid_id: no response (silent), connection alive; oversized_input: error(-32601); recovery: accepted (returned result); cancellation: error(-32601); old_version: accepted old version 2024-10-07, negotiated 2024-10-07, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE1ms

resources capability not declared

08concurrent_callsWARN732ms

ladder 1/2/4/6 overlapping run_code calls: max_observed_stable_concurrency=6; all ids answered exactly once, but every call returned an error (error -32603: 401: authorization header is missing), the tool may need runtime dependencies this sandbox does not provide

09reconnectPASS1.3s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-06-18, first session was 2025-06-18)

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
No findings under security ruleset v1
VERDICT: FIT14 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 0 fail / 2 warn (14 of 18 steps exercised across 2 clients) / security: clean, 0 findingssealed by THRONE / No. 37a04a1c / 2026-06-16
scopeattestation tuple
target
@e2b/mcp-server npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
14 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 17:28:46Z
evidence hash
sha256:6e6bf00ddb698fa8f0253224ca614b88ed41931d1c1dd446c8cd35c49fab24d2
valid until
2026-09-14
THRONE: FITwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT](https://api.usethrone.dev/api/badge/%40e2b%2Fmcp-server)](https://usethrone.dev/server/e2b-mcp-server)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.