whatbox-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| WHATBOX_MUTATIONS_ENABLED | No | Set to true to enable mutation tools. Mutations are off by default. | false |
Capabilities
Features and capabilities supported by this server
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| whatbox_list_toolsA | Return the full tool catalog grouped by category and risk, plus whether remote mutations are currently enabled. Back the /tools command with this. |
| server_infoA | Return non-sensitive metadata about this local Whatbox MCP server. |
| list_capabilitiesA | List implemented capabilities, planned Whatbox integrations, and safety boundaries. |
| whatbox_website_readinessA | Inspect fixed website-hosting readiness facts without reading Nginx configuration contents, process arguments, or private connection values. |
| whatbox_website_diagnosticsA | Test fixed userland Nginx configuration syntax, optionally probe a configured loopback port without a response body, and summarize recent error severities without returning configuration or log contents. |
| whatbox_website_deployment_planA | Validate an explicitly allowlisted local static-site source and create a redacted, signed deployment plan. This tool never uploads files or changes Whatbox state. |
| whatbox_operational_snapshotA | Return one sanitized read-only assessment covering storage pressure, allowlisted services, website readiness, recommendations, and mutation safety state. |
| whatbox_configuration_statusA | Check whether local Whatbox configuration is complete without returning configuration values or secrets. |
| whatbox_connection_statusA | Test a verified read-only SSH connection using local credentials without returning their values. |
| whatbox_configuration_reviewA | Return conservative advisory findings from service metadata and storage capacity without reading configuration contents or making changes. |
| whatbox_services_statusA | Report conservative configured and running states for an allowlisted Whatbox service catalog without reading configuration contents or process arguments. |
| whatbox_structure_mapA | Create a bounded directory-only map and Mermaid diagram below an allowed root without reading file contents or traversing sensitive directories or symlinks. |
| whatbox_torrent_clients_statusA | Report whether allowlisted Whatbox torrent clients are running without returning torrent or unrelated process details. |
| whatbox_storage_statusA | Report capacity and usage for configured Whatbox storage roots using a fixed read-only query. |
| whatbox_list_directoryA | List a directory below an explicitly allowed Whatbox storage root. Absolute paths and path escapes are rejected. |
| whatbox_upload_pathA | Upload an allowlisted local file or directory into an allowed remote root without overwriting. Reversible; checks remote free space first. |
| whatbox_download_pathA | Download a remote file or directory into the configured local download directory. Skips symlinks; checks local free space first. |
| whatbox_move_pathA | Move or rename a path between allowed roots without overwriting an existing destination. Reversible. |
| whatbox_make_directoryA | Create a directory (and missing parents) below an allowed root. Reversible. |
| whatbox_quarantine_pathA | Move a path into a dated quarantine directory instead of deleting it. Requires explicit human approval. Reversible; reports storage headroom (quarantine does not free space). |
| whatbox_list_quarantineA | List items currently in the quarantine directory, so a human can choose what to restore (move) or purge. |
| whatbox_purge_quarantineA | Permanently delete an item that already lives in the quarantine directory. This is the irreversible second step and requires its own explicit human approval. |
| whatbox_backup_configurationA | Download allowlisted service configuration directories to the local download directory as a timestamped backup. Returns counts only; checks local free space first. |
| whatbox_service_controlA | Control an allowlisted userland service using fixed start scripts and bounded process signals. Stop/restart require explicit human approval. |
| whatbox_website_deploy_executeA | Stage a validated local static site into a new release, verify the remote manifest by checksum, atomically activate it via the current-release pointer, and health-check. Reversible via rollback. Checks remote free space first. |
| whatbox_website_rollbackA | Atomically repoint the current-release pointer to an existing prior release and health-check it. Requires explicit human approval. |
| whatbox_torrents_statusA | Report bounded torrent status (name, state, progress, ratio, label, totals) through an SSH loopback tunnel to the configured client RPC. Read-only. |
| whatbox_torrent_addA | Add a torrent from a bounded magnet or HTTP(S) URL through the configured client RPC. Reversible. |
| whatbox_torrent_controlA | Pause, resume, set the label/category, or set the seed-ratio limit of one torrent. Reversible. |
| whatbox_torrent_removeA | Remove a torrent from the client, optionally deleting its downloaded data. Requires explicit human approval; deleting data is irreversible. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| whatbox_safe_audit | Guide an agent through a sanitized read-only Whatbox assessment without requesting secrets or implying mutation authority. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| whatbox-agent-guide | Safe operating sequence, secret policy, mutation boundary, and external-provider boundaries for AI agents. |
| whatbox-tools-catalog | The full catalog of tools grouped by category and risk, and the current mutation-enabled state. |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/SNSEIxAUGMNTD/whatbox-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server