sandbase-harnessBLOCK
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
[](https://github.com/sandbaseai/sandbase-harness/stargazers) [](https://deepseek-plugin.org/plugins/sandbaseai/sandbase-harness) [](https://github.com/sandbaseai/sandbase-harness/releases/latest) [](https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.sandbaseai%2Fsandbase-harness) [](https://github.com/sandbaseai/sandbase-harness/discussions) [](https://github.com/sandbaseai/sandbase-harness/actions/workflows/codeql.yml) [](LICENSE)
AI-readable project metadata: llms.txt · installation guide
A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure.
Building with DeepSeek Harness? The independent DeepSeek Harness Handbook provides source-backed runtime guides, multilingual troubleshooting, and a regularly updated Agent-first resource map.
Looking for a lightweight bridge instead of a full runtime? SandBase CLI connects 25 AI client ta
2e45ae9002b2OBSERVED · 2026-09-20Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sandbase-harness-mcp:0.3.8 --env MANAGED_AGENTS_API_KEY=${MANAGED_AGENTS_API_KEY} -- docker run -i --rm ghcr.io/sandbaseai/sandbase-harness-mcp:0.3.8:NoneExposed tools (16)
13 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Local | read | Local test environment. |
Test | read | Test environment |
create_session | write | |
docker | read | |
echo | read | Echo back the provided text |
get_session | read | |
list_agents | read | |
list_artifacts | read | |
my-template | read | test |
one | read | first |
run_session | write | |
runtime-agent | read | Created through the API. |
stop_session | write | |
t | read | |
two | read | second |
valid-template | read | test |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(sql: string): void {placeholder="~/.kube/config"
apiKey: 'not-needed-for-local',
api_key: 'settings-secret-value',
api_key: 'rotated-settings-secret-value',
model: { ...failed.effective_config.model, api_key: 'repaired-model-secret' },import { postJson, putJson } from '../../api';import type { Agent, AgentToolset, ConsoleData, SkillRef, Template } from '../../types';import { postJson } from '../../api';import type { CredentialAuthType, EnvironmentHostingType } from '../../types';import { postJson } from '../../api';# open http://127.0.0.1:3000/dashboard
export MANAGED_AGENTS_URL=http://127.0.0.1:3000
Open `http://127.0.0.1:3000/dashboard`, go to **Settings > Models**, paste your
curl -X POST http://127.0.0.1:3000/v1/agents \
curl -X POST http://127.0.0.1:3000/v1/environments \
@ai-sdk/anthropic, @ai-sdk/openai, @hono/node-server, @modelcontextprotocol/sdk, ai, commander, hono, nanoid
- API gaps for templates/files/evals can start read-only, but vault credentials
| Control tool access | MCP toolsets, credential vaults, permission policies, and approvals |
- [Awesome AI Agents Security PR #107](https://github.com/ProjectRecon/awesome-ai-agents-security/pull/107): open and mergeable; added SandBase Harness to Sandboxing & Isolation Environments under a c
- [UCSB Awesome Agent Security PR #16](https://github.com/ucsb-mlsec/Awesome-Agent-Security/pull/16): open and mergeable; added SandBase Harness to System-level Runtime Defense with a concise tool ref
- [Awesome Security Agent Harnesses PR #1](https://github.com/Ed-Marcavage/awesome-security-agent-harnesses/pull/1): open; added SandBase Harness to Agent Sandboxes with sandboxed sessions, governed t
curl -X POST http://127.0.0.1:3000/v1/credential-vaults/VAULT_ID/credentials \
curl -X POST http://127.0.0.1:3000/v1/credential-vaults/VAULT_ID/credentials/CREDENTIAL_ID/rotate \
- [LobeHub Marketplace](https://github.com/lobehub/lobehub): checked the documented `@lobehub/market-cli` submission path; `plugin submit` currently requires an authenticated `lhm login`, and no LobeH
Gates applied: no_behavioural_pass.
2e45ae9002b2full audit observations/trust-audit/mcp-server/sandbaseai__sandbase-harness.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-20 | 2e45ae9002b2 | BLOCK | D | 60 | first audit |
Questions
What is the sandbase-harness MCP server?
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
What tools does sandbase-harness expose?
16 in total: 13 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is sandbase-harness safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does sandbase-harness need?
It reads MANAGED_AGENTS_API_KEY, MANAGED_AGENTS_ENVIRONMENT_KEY, MANAGED_AGENTS_SECRET_KEY, MANAGED_AGENTS_TEST_SECRET, OPENAI_API_KEY, PI_MODEL_API_KEY, SANDBASE_PI_API_KEY, SETTINGS_V2_NESTED_MODEL_API_KEY, SETTINGS_V2_PRESENT_OPENAI_KEY and UNRELATED_SERVICE_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does sandbase-harness run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as managed-agents at 0.3.8.
How current is this page?
The grade is for one exact copy of the source (2e45ae9002b2), read on 2026-09-20. The repository is watched and re-audited when it changes.