Coding agent starter stack
A terminal coding agent plus current library docs, GitHub access, a real browser and a sandbox, connected over MCP, with the configuration choices that keep it safe.
Use case
Give a coding agent current library docs, repository access, a real browser and an isolated place to run code.
Components
| Role | Component | Why |
|---|---|---|
| Harness | Claude Code | Agentic coding in the terminal with a built-in MCP client, Agent Skills and an optional OS-enforced Bash sandbox. Swap in another harness from the comparison if you prefer a different model or license. |
| Project instructions | AGENTS.md | One AGENTS.md at the repo root that most harnesses read (Claude Code reads it alongside CLAUDE.md), holding build, test and style rules. |
| Library docs | Context7 | Pulls up-to-date, version-specific library documentation into context, so the agent stops guessing APIs. Hosted at mcp.context7.com/mcp. |
| Repository access | GitHub MCP Server | Issues, pull requests, code search and Actions from the agent, either hosted at api.githubcopilot.com/mcp with a token or as a local Docker server with OAuth. |
| Browser | Playwright MCP | Drives a real browser through accessibility snapshots, for checking the UI the agent just changed. |
| Sandbox | E2B | A disposable Firecracker microVM for running untrusted or generated code away from your machine, with outbound network you can switch off. |
Setting it up
Start with the harness and one MCP server, confirm it works, then add the next. With Claude Code:
claude mcp add --transport http context7 https://mcp.context7.com/mcp
claude mcp add --transport http github https://api.githubcopilot.com/mcp \
--header "Authorization: Bearer $GITHUB_PAT"
claude mcp add playwright -- npx @playwright/mcp@latest
claude mcp list
The Claude Code MCP guide covers scopes, keeping tokens out of .mcp.json, and troubleshooting. For other harnesses, see the remote MCP guide and the coding agents comparison.
Keep it safe
- Scope the GitHub token. Use a fine-grained token limited to the repositories the agent works on, with read-only permissions unless it needs to open pull requests.
- Turn on the harness sandbox. Claude Code's Bash sandbox is off by default (
/sandboxenables it); Codex CLI sandboxes by default. AdddenyReadrules for credential files, since sandboxed commands can still read most of your home directory by default. - Review
.mcp.jsonin repos you didn't write. Project-scoped servers load without a prompt inclaude -pand SDK runs. - Run generated code elsewhere. Send anything that installs packages from the internet or runs untrusted code to the sandbox; the sandboxing guide explains how.
Directory entries in this stack
- Claude Code: Anthropic's agentic coding tool that reads your codebase, edits files, runs commands and integrates with dev tools; available in terminal, IDE, desktop and browser.
- AGENTS.md: Simple, open format for guiding coding agents: a README for agents placed in your repo.
- Context7: Upstash's MCP server and platform that pulls up-to-date, version-specific library documentation and code examples into AI coding tools.
- GitHub MCP Server: GitHub's official MCP server: lets agents read repos and code, manage issues and PRs, analyze code and monitor Actions workflows.
- Playwright MCP: Microsoft's MCP server for browser automation with Playwright, letting LLMs act on web pages via structured accessibility snapshots instead of screenshots.
- E2B: Open-source, secure cloud sandboxes for AI agents: an isolated machine per agent to run code, browse and use tools.
- OpenAI Codex CLI: OpenAI's lightweight open-source coding agent that runs in your terminal.
- Gemini CLI: Open-source AI agent from Google that brings Gemini models directly into your terminal.
- OpenCode: The open-source AI coding agent, built for the terminal.
Related
- Add MCP servers to Claude Code (Guide)
- Terminal coding agents compared (Comparison)
- Run agent-generated code safely in a sandbox (Guide)
- Code sandboxes for AI agents (Comparison)
- Connect an agent to a remote MCP server (Guide)
Sources
- Claude Code docs, Connect Claude Code to tools via MCP, accessed
- Claude Code docs, Memory (CLAUDE.md and AGENTS.md), accessed
- GitHub MCP server, Install in Claude applications, accessed
- Playwright MCP README, accessed
- E2B docs, Internet access, accessed