Toolbox Langchain SDKSAFE
Python SDK for interacting with the MCP Toolbox for Databases.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/Apache-2.0) [](https://pypi.org/project/toolbox-core/)
This repository contains Python SDKs designed to seamlessly integrate the functionalities of the MCP Toolbox into your Gen AI applications. These SDKs allow you to load tools defined in Toolbox and use them as standard Python functions or objects within popular orchestration frameworks or your custom code.
For comprehensive guides and advanced configuration, visit the Main Documentation Site.
- Available Packages
- Quickstart
- Contributing
- License
- Support
Available Packages
This repository hosts the following Python packages. See the package-specific READMEs or the docsite for detailed usage:
3c2223c0c4dbOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add toolbox-llamaindex --env GEMINI_API_KEY=${GEMINI_API_KEY} -- uvx toolbox-llamaindex{
"mcpServers": {
"toolbox-llamaindex": {
"command": "uvx",
"args": [
"toolbox-llamaindex"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_weather | read | Gets the weather. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (7)
credentials=HttpCredentials(token="fake-integration-token"),
.release-please-manifest.json
.trampolinerc
async with ToolboxClient("http://127.0.0.1:5000") as toolbox:async with ToolboxClient("http://127.0.0.1:5000") as toolbox:async with ToolboxClient("http://127.0.0.1:5000") as toolbox:autoprefixer, postcss, postcss-cli
Gates applied: no_behavioural_pass.
3c2223c0c4dbfull audit observations/trust-audit/mcp-server/googleapis__toolbox-langchain-sdk.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 3c2223c0c4db | SAFE | B | 89 | first audit |
Questions
What is the Toolbox Langchain SDK MCP server?
Python SDK for interacting with the MCP Toolbox for Databases.
What tools does Toolbox Langchain SDK expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Toolbox Langchain SDK safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Toolbox Langchain SDK need?
It reads GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (3c2223c0c4db), read on 2026-10-06. The repository is watched and re-audited when it changes.