sandbox-studio-mcp
npm
v1.0.3
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
A local MCP server for the Sandbox Studio API
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "update_cleanup_hook" appears to run shell commands or evaluate code (parameter "script"). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool update_cleanup_hook
Untrusted-input tools ([list_accounts, list_unregistered_accounts, get_account_lease_history, list_approvals, list_events, list_leases, list_public_templates, list_managed_templates, get_template_leases, list_users, list_groups]) co-exist with external-action tools ([update_cleanup_hook]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [list_accounts, list_unregistered_accounts, get_account_lease_history, list_approvals, list_events, list_leases, list_public_templates, list_managed_t
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow list_accounts → update_cleanup_hook
Tool "update_cleanup_hook" takes a command-shaped parameter "script" with no enum/pattern constraint. Free-form, model- or attacker-controlled arguments reaching a shell is the command-injection precondition.
Fix: Constrain the parameter (enum/pattern), or build the command from a fixed template with escaped args.
Location: tool update_cleanup_hook · inputSchema.properties.script
Tool "update_cleanup_hook" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool update_cleanup_hook
Each tool and what it can reach — statically extracted from the published source.
get_account_lease_historyingests untrusted inputget_template_leasesingests untrusted inputlist_accountsingests untrusted inputlist_approvalsingests untrusted inputlist_eventsingests untrusted inputlist_groupsingests untrusted inputlist_leasesingests untrusted inputlist_managed_templatesingests untrusted inputlist_public_templatesingests untrusted inputlist_unregistered_accountsingests untrusted inputlist_usersingests untrusted inputupdate_cleanup_hookruns code / shelladd_event_teamsno sensitive capabilityassign_event_team_ownerno sensitive capabilitycreate_eventno sensitive capabilitycreate_oauth_clientno sensitive capabilitycreate_templateno sensitive capabilitydelete_oauth_clientno sensitive capabilitydelete_templateno sensitive capabilityeject_accountsno sensitive capabilityget_accountno sensitive capabilityget_account_cleanup_logsno sensitive capabilityget_account_failed_resourcesno sensitive capabilityget_cleanup_hookno sensitive capabilityget_cleanup_settingsno sensitive capabilityget_email_settingsno sensitive capabilityget_eventno sensitive capabilityget_event_teamsno sensitive capabilityget_global_configno sensitive capabilityget_leaseno sensitive capabilityget_lease_costsno sensitive capabilityget_lease_logsno sensitive capabilityget_lease_secretsno sensitive capabilityget_lease_team_membersno sensitive capabilityget_runtime_configno sensitive capabilityget_smtp_settingsno sensitive capabilityget_tagsno sensitive capabilityget_templateno sensitive capabilityget_template_infono sensitive capabilityget_template_launch_settingsno sensitive capabilityget_template_permissionsno sensitive capabilityget_terms_of_serviceno sensitive capabilityget_terms_versionno sensitive capabilityimport_accountsno sensitive capabilitylist_all_oauth_clientsno sensitive capabilitylist_my_oauth_clientsno sensitive capabilitylist_terms_versionsno sensitive capabilityprovision_eventno sensitive capabilitypublish_terms_of_serviceno sensitive capabilityrequest_leaseno sensitive capabilityresume_leaseno sensitive capabilityretry_account_cleanupno sensitive capabilityreview_leaseno sensitive capabilitysend_test_emailno sensitive capabilityshare_leaseno sensitive capabilitystart_eventno sensitive capabilitysuspend_leaseno sensitive capabilityterminate_eventno sensitive capabilityterminate_leaseno sensitive capabilitytrigger_drift_detectionno sensitive capabilitytrigger_lease_monitoringno sensitive capabilityunshare_leaseno sensitive capabilityupdate_cleanup_settingsno sensitive capabilityupdate_email_settingsno sensitive capabilityupdate_eventno sensitive capabilityupdate_global_configno sensitive capabilityupdate_leaseno sensitive capabilityupdate_oauth_clientno sensitive capabilityupdate_preferencesno sensitive capabilityupdate_smtp_settingsno sensitive capabilityupdate_template_budgetno sensitive capabilityupdate_template_durationno sensitive capabilityupdate_template_infono sensitive capabilityupdate_template_launch_settingsno sensitive capabilityupdate_template_managersno sensitive capabilityupdate_template_permissionsno sensitive capabilityupdate_template_sharingno sensitive capabilityupdate_template_tagsno sensitive capabilityvalidate_s3_pathno sensitive capabilityvalidate_usersno sensitive capabilitywithdraw_leaseno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.3 latest |
A 92/100 | 4 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan sandbox-studio-mcp --online
Operator control CLI for AdGuard Home with an MCP adapter
interacting with Aliyun (Alibaba Cloud) services through This MCP server provides tools.
MCP server for the Aspro.Cloud REST API
MCP server for Atlassian Confluence and Jira Cloud APIs
AuroraCloud-first MCP server that exposes AuroraDocs workspace data to Claude Desktop and other AI agents
The official AWS Knowledge Base retrieval server using Bedrock Agent Runtime.