Atlas / MCP servers / sandbaseai / sandbase-harness

sandbase-harnessBLOCK

mcp/sandbaseai/sandbase-harness

Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
16 13r · 3w · 0d
Transport
stdio
License
Apache-2.0
Stars
647
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

[](https://github.com/sandbaseai/sandbase-harness/stargazers) [](https://deepseek-plugin.org/plugins/sandbaseai/sandbase-harness) [](https://github.com/sandbaseai/sandbase-harness/releases/latest) [](https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.sandbaseai%2Fsandbase-harness) [](https://github.com/sandbaseai/sandbase-harness/discussions) [](https://github.com/sandbaseai/sandbase-harness/actions/workflows/codeql.yml) [](LICENSE)

AI-readable project metadata: llms.txt · installation guide

A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure.

Building with DeepSeek Harness? The independent DeepSeek Harness Handbook provides source-backed runtime guides, multilingual troubleshooting, and a regularly updated Agent-first resource map.

Looking for a lightweight bridge instead of a full runtime? SandBase CLI connects 25 AI client ta
Read from source at commit 2e45ae9002b2OBSERVED · 2026-09-20
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add sandbase-harness-mcp:0.3.8 --env MANAGED_AGENTS_API_KEY=${MANAGED_AGENTS_API_KEY} -- docker run -i --rm ghcr.io/sandbaseai/sandbase-harness-mcp:0.3.8:None
03

Exposed tools (16)

13 read · 3 write · 0 destructive.

ToolRiskDescription
LocalreadLocal test environment.
TestreadTest environment
create_sessionwrite
dockerread
echoreadEcho back the provided text
get_sessionread
list_agentsread
list_artifactsread
my-templatereadtest
onereadfirst
run_sessionwrite
runtime-agentreadCreated through the API.
stop_sessionwrite
tread
tworeadsecond
valid-templatereadtest
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/core/db/database.ts:39
exec(sql: string): void {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
apps/console/src/components/pages/settings/RuntimeSettingsSandboxForm.tsx:87
placeholder="~/.kube/config"
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
examples/basic/README.md:47
apiKey: 'not-needed-for-local',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/api.test.ts:1262
api_key: 'settings-secret-value',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/api.test.ts:1333
api_key: 'rotated-settings-secret-value',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/settings.test.ts:524
model: { ...failed.effective_config.model, api_key: 'repaired-model-secret' },
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/console/src/components/modals/AgentModals.tsx:4
import { postJson, putJson } from '../../api';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/console/src/components/modals/AgentModals.tsx:7
import type { Agent, AgentToolset, ConsoleData, SkillRef, Template } from '../../types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/console/src/components/modals/ResourceModals.tsx:3
import { postJson } from '../../api';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/console/src/components/modals/ResourceModals.tsx:7
import type { CredentialAuthType, EnvironmentHostingType } from '../../types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/console/src/components/modals/SessionModals.tsx:3
import { postJson } from '../../api';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:40
# open http://127.0.0.1:3000/dashboard
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:462
export MANAGED_AGENTS_URL=http://127.0.0.1:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:557
Open `http://127.0.0.1:3000/dashboard`, go to **Settings > Models**, paste your
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:671
curl -X POST http://127.0.0.1:3000/v1/agents \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:684
curl -X POST http://127.0.0.1:3000/v1/environments \
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ai-sdk/anthropic, @ai-sdk/openai, @hono/node-server, @modelcontextprotocol/sdk, ai, commander, hono, nanoid
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.kiro/specs/local-agent-platform/dashboard-console-implementation-plan.md:621
- API gaps for templates/files/evals can start read-only, but vault credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:49
| Control tool access | MCP toolsets, credential vaults, permission policies, and approvals |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/promotion.md:474
- [Awesome AI Agents Security PR #107](https://github.com/ProjectRecon/awesome-ai-agents-security/pull/107): open and mergeable; added SandBase Harness to Sandboxing & Isolation Environments under a c
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/promotion.md:475
- [UCSB Awesome Agent Security PR #16](https://github.com/ucsb-mlsec/Awesome-Agent-Security/pull/16): open and mergeable; added SandBase Harness to System-level Runtime Defense with a concise tool ref
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/promotion.md:494
- [Awesome Security Agent Harnesses PR #1](https://github.com/Ed-Marcavage/awesome-security-agent-harnesses/pull/1): open; added SandBase Harness to Agent Sandboxes with sandboxed sessions, governed t
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/api.md:590
curl -X POST http://127.0.0.1:3000/v1/credential-vaults/VAULT_ID/credentials \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/api.md:611
curl -X POST http://127.0.0.1:3000/v1/credential-vaults/VAULT_ID/credentials/CREDENTIAL_ID/rotate \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/promotion.md:455
- [LobeHub Marketplace](https://github.com/lobehub/lobehub): checked the documented `@lobehub/market-cli` submission path; `plugin submit` currently requires an authenticated `lhm login`, and no LobeH
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-20 · audit v0.4.1 · source sha 2e45ae9002b2full audit observations/trust-audit/mcp-server/sandbaseai__sandbase-harness.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-202e45ae9002b2BLOCKD60first audit
06

Questions

What is the sandbase-harness MCP server?

Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.

What tools does sandbase-harness expose?

16 in total: 13 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is sandbase-harness safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does sandbase-harness need?

It reads MANAGED_AGENTS_API_KEY, MANAGED_AGENTS_ENVIRONMENT_KEY, MANAGED_AGENTS_SECRET_KEY, MANAGED_AGENTS_TEST_SECRET, OPENAI_API_KEY, PI_MODEL_API_KEY, SANDBASE_PI_API_KEY, SETTINGS_V2_NESTED_MODEL_API_KEY, SETTINGS_V2_PRESENT_OPENAI_KEY and UNRELATED_SERVICE_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does sandbase-harness run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as managed-agents at 0.3.8.

How current is this page?

The grade is for one exact copy of the source (2e45ae9002b2), read on 2026-09-20. The repository is watched and re-audited when it changes.

Advertisement