SandboxBLOCK
Fast cold-boot MicroVM sandboxes for AI agents on cocoon
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MicroVM sandboxes for AI agents, built on cocoon: a fast-boot guest stack, an in-guest product daemon, a per-node control plane with warm pools, and SDKs for Go and Python. Warm claims are sub-millisecond; a pool miss clones from a golden snapshot in tens of milliseconds; cold boot is ~0.2–0.4 s on bare metal.
SDK (Go/Python) sandboxd (per node) guest microVM client.New/new ─ HTTP ─► claim: warm pool / golden clone Cloud Hypervisor exec/files/... ─ HTTP upgrade (kept) ─► byte relay ─ vsock ─► silkd :2048 memberlist mesh: warm-count gossip, MOVED-style redirect to the owning node
Cloud Hypervisor serves both network lanes. net=none has no NIC and uses vsock-only I/O (hardened default); net=egress attaches a bridge/CNI NIC.
Documentation: cocoonstack.github.io/sandbox (deployment, clusters, HTTP API, Go + Python SDK references, the MCP server, the OpenAI Agents SDK and LangChain adapters, silkd protocol, performance) — source in docs/.
Layout
silkd/— in-guest product daemon (Rust, tokio): exec with context,
persistent shell sessions, streaming fs, tar-stream tree push/pull, find/replace, watch (ready-acked), pty, structured git, guest port relay (port_forward), and an LSP broker for flavor-shipped language servers — newline-JSON frames over vsock 2048, RPCs back to back on one connection; baked into the base image
sandboxd/— per-node control plane (Go): warm pools refilled from golden
snapshot exports (online-retunable), claim/release/renew/hibernate/fork/ promote/checkpoint HTTP API, operator-catalog dataset volumes (read-only or writable), signed preview URLs, the HTTP-upgrade byte relays to silkd and to any guest port, claim env with host-side credential injection and per-claim upstream proxies, runtime tenants, config reload (SIGHUP),
9a89ec586f6aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add cocoonstack-sandbox -- uvx cocoonstack-sandbox
{
"mcpServers": {
"cocoonstack-sandbox": {
"command": "uvx",
"args": [
"cocoonstack-sandbox"
]
}
}
}Exposed tools (10)
7 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
branch_checkpoint | read | |
checkpoint | read | |
delete_checkpoint | destructive | |
exec | write | |
fork | read | |
hibernate | read | |
list_dir | read | |
read_file | read | |
release | read | |
write_file | write |
Trust audit
BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
func (p Policy) Eval(host, method string, port uint16) (Rule, Decision) {Eval(host, method string, port uint16) (Rule, Decision)
func (c composite) Eval(host, method string, port uint16) (Rule, Decision) {'Environment=no_proxy=localhost,127.0.0.1,::1,169.254.169.254' \
' iif != "lo" ip daddr 169.254.169.254 tcp dport 80 drop' \
SANDBOXD_TEST_PG_URL: postgres://postgres:sbxci@localhost:5432/postgres?sslmode=disable
delete_checkpoint
.golangci.yml
.goreleaser.yml
t.Fatalf("Eval(%q,%q) = %v, want %v", tt.host, tt.method, got, tt.want)t.Errorf("Eval(%q,%q) secret = %q, want %q", tt.host, tt.method, rule.Secret, tt.secret)const fixtureDir = "../../protocol/wire/fixtures/v1"
for _, id := range []string{"../../etc", "ck_zz", "", "ck_0011223344556677x"} {for _, id := range []string{"../../etc", "ck_zz", "", "ck_00112233445566ff", "ck_deadbeefdeadbeef"} {"../../etc/passwd",
"export/../../escape",
`169.254.169.254`. The guard unit aliases that address on `lo`, so silkd
agent reads from `169.254.169.254` in the IMDSv2 shape, as cloud-init and
inert. Where an image aliases `169.254.169.254` on `lo`, silkd also serves the
curl -s -H "Authorization: Bearer $TOKEN" http://127.0.0.1:7777/v1/info | jq .
"for i in $(seq 1 200); do curl -sf -o /dev/null http://127.0.0.1:49983/health && exit 0; sleep 0.05; done; exit 1"]}
"for i in $(seq 1 1200); do curl -sf -m 1 -o /dev/null http://127.0.0.1:49983/health && curl -sf -m 1 -o /dev/null http://127.0.0.1:49999/health && exit 0; sleep 0.05; done; exit 1"]}
curl -x http://127.0.0.1:3128 https://api.github.com/user # explicit form, same path
`http://127.0.0.1:3128` when it is `relay`. `"egress": false` closes the doors, not an unlocked NIC, so
return {"type": line[9:te].decode(), "data": base64.b64decode(line[te + 10 : de], validate=True)}Gates applied: no_behavioural_pass.
9a89ec586f6afull audit observations/trust-audit/mcp-server/cocoonstack__sandbox-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9a89ec586f6a | BLOCK | F | 48 | first audit |
Questions
What is the Sandbox MCP server?
Fast cold-boot MicroVM sandboxes for AI agents on cocoon
What tools does Sandbox expose?
10 in total: 7 read-only, 2 that write, and 1 that can delete or overwrite (delete_checkpoint). Every one is listed on this page with its risk.
Is Sandbox safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (48/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Sandbox need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (9a89ec586f6a), read on 2026-10-08. The repository is watched and re-audited when it changes.