Atlas / MCP servers / cocoonstack / Sandbox

SandboxBLOCK

mcp/cocoonstack/sandbox-6

Fast cold-boot MicroVM sandboxes for AI agents on cocoon

Verdict
BLOCK
Grade
F
Trust score
48 /100
Exposed tools
10 7r · 2w · 1d
Transport
—
License
AGPL-3.0
Stars
83
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MicroVM sandboxes for AI agents, built on cocoon: a fast-boot guest stack, an in-guest product daemon, a per-node control plane with warm pools, and SDKs for Go and Python. Warm claims are sub-millisecond; a pool miss clones from a golden snapshot in tens of milliseconds; cold boot is ~0.2–0.4 s on bare metal.

SDK (Go/Python)         sandboxd (per node)              guest microVM
client.New/new ─ HTTP ─► claim: warm pool / golden clone   Cloud Hypervisor
exec/files/... ─ HTTP upgrade (kept) ─► byte relay ─ vsock ─► silkd :2048
memberlist mesh: warm-count gossip,
MOVED-style redirect to the owning node

Cloud Hypervisor serves both network lanes. net=none has no NIC and uses vsock-only I/O (hardened default); net=egress attaches a bridge/CNI NIC.

Documentation: cocoonstack.github.io/sandbox (deployment, clusters, HTTP API, Go + Python SDK references, the MCP server, the OpenAI Agents SDK and LangChain adapters, silkd protocol, performance) — source in docs/.

Layout

  • silkd/ — in-guest product daemon (Rust, tokio): exec with context,

persistent shell sessions, streaming fs, tar-stream tree push/pull, find/replace, watch (ready-acked), pty, structured git, guest port relay (port_forward), and an LSP broker for flavor-shipped language servers — newline-JSON frames over vsock 2048, RPCs back to back on one connection; baked into the base image

  • sandboxd/ — per-node control plane (Go): warm pools refilled from golden

snapshot exports (online-retunable), claim/release/renew/hibernate/fork/ promote/checkpoint HTTP API, operator-catalog dataset volumes (read-only or writable), signed preview URLs, the HTTP-upgrade byte relays to silkd and to any guest port, claim env with host-side credential injection and per-claim upstream proxies, runtime tenants, config reload (SIGHUP),

Read from source at commit 9a89ec586f6aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cocoonstack-sandbox -- uvx cocoonstack-sandbox
claude-desktop
{
  "mcpServers": {
    "cocoonstack-sandbox": {
      "command": "uvx",
      "args": [
        "cocoonstack-sandbox"
      ]
    }
  }
}
03

Exposed tools (10)

7 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
branch_checkpointread
checkpointread
delete_checkpointdestructive
execwrite
forkread
hibernateread
list_dirread
read_fileread
releaseread
write_filewrite
04

Trust audit

BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (4 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
sandboxd/egress/policy.go:139
func (p Policy) Eval(host, method string, port uint16) (Rule, Decision) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
sandboxd/egress/policy.go:199
Eval(host, method string, port uint16) (Rule, Decision)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
sandboxd/egress/policy.go:215
func (c composite) Eval(host, method string, port uint16) (Rule, Decision) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
os-image/base/24.04/Dockerfile:74
'Environment=no_proxy=localhost,127.0.0.1,::1,169.254.169.254' \
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
os-image/e2b-ci/24.04/Dockerfile:48
'    iif != "lo" ip daddr 169.254.169.254 tcp dport 80 drop' \
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/sandboxd.yml:74
SANDBOXD_TEST_PG_URL: postgres://postgres:sbxci@localhost:5432/postgres?sslmode=disable
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_checkpoint
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yml
.goreleaser.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
sandboxd/egress/policy_test.go:33
t.Fatalf("Eval(%q,%q) = %v, want %v", tt.host, tt.method, got, tt.want)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
sandboxd/egress/policy_test.go:36
t.Errorf("Eval(%q,%q) secret = %q, want %q", tt.host, tt.method, rule.Secret, tt.secret)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sandboxd/engine/portconn_test.go:76
const fixtureDir = "../../protocol/wire/fixtures/v1"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sandboxd/pool/checkpoint_test.go:151
for _, id := range []string{"../../etc", "ck_zz", "", "ck_0011223344556677x"} {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sandboxd/pool/checkpoint_test.go:340
for _, id := range []string{"../../etc", "ck_zz", "", "ck_00112233445566ff", "ck_deadbeefdeadbeef"} {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sandboxd/store/peer/transport_test.go:59
"../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sandboxd/store/peer/transport_test.go:60
"export/../../escape",
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
docs/e2b.md:63
`169.254.169.254`. The guard unit aliases that address on `lo`, so silkd
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
docs/sandboxd-api.md:766
agent reads from `169.254.169.254` in the IMDSv2 shape, as cloud-init and
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
docs/silkd.md:84
inert. Where an image aliases `169.254.169.254` on `lo`, silkd also serves the
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/deploy.md:668
curl -s -H "Authorization: Bearer $TOKEN" http://127.0.0.1:7777/v1/info | jq .
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/e2b.md:47
"for i in $(seq 1 200); do curl -sf -o /dev/null http://127.0.0.1:49983/health && exit 0; sleep 0.05; done; exit 1"]}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/e2b.md:101
"for i in $(seq 1 1200); do curl -sf -m 1 -o /dev/null http://127.0.0.1:49983/health && curl -sf -m 1 -o /dev/null http://127.0.0.1:49999/health && exit 0; sleep 0.05; done; exit 1"]}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/egress.md:33
curl -x http://127.0.0.1:3128 https://api.github.com/user   # explicit form, same path
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/sandboxd-api.md:119
`http://127.0.0.1:3128` when it is `relay`. `"egress": false` closes the doors, not an unlocked NIC, so
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
sdk/python/cocoonsandbox/frames.py:46
return {"type": line[9:te].decode(), "data": base64.b64decode(line[te + 10 : de], validate=True)}

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 9a89ec586f6afull audit observations/trust-audit/mcp-server/cocoonstack__sandbox-6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-089a89ec586f6aBLOCKF48first audit
06

Questions

What is the Sandbox MCP server?

Fast cold-boot MicroVM sandboxes for AI agents on cocoon

What tools does Sandbox expose?

10 in total: 7 read-only, 2 that write, and 1 that can delete or overwrite (delete_checkpoint). Every one is listed on this page with its risk.

Is Sandbox safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (48/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Sandbox need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (9a89ec586f6a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement