Sandbox Code Auditor MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| BASE_RPC_URL | Yes | Base L2 RPC URL used for settlement. | |
| PAYMENT_WALLET | Yes | Recipient payout wallet address for x402 micropayments on Base L2. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| python_ast_sandbox_escape_detectorA | Audits Python ASTs for dangerous builtins, |
| sql_ast_sqli_taint_analyzerA | Parses SQL query ASTs to verify parameterized binding, flagging raw string concatenations that lead to second-order SQL injection vulnerabilities. (0.040 USDC on Base L2) |
| regex_redos_exponential_scannerA | Audits regular expressions for catastrophic polynomial and exponential backtracking (ReDoS) vulnerabilities using NFA/DFA cycle decomposition. (0.035 USDC on Base L2) |
| linux_seccomp_bpf_filter_generatorA | Generates minimal Seccomp BPF syscall filter profiles for sandboxing untrusted agent processes, blocking ptrace, fork, and raw socket creation. (0.040 USDC on Base L2) |
| cors_policy_preflight_misconfig_checkerA | Audits CORS response headers for dangerous wildcards with credentials ( |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool targets a completely distinct artifact and vulnerability class (Python AST escape, SQL taint, regex ReDoS, Seccomp BPF, CORS headers). There is no realistic scenario where an agent would confuse one for another, and the descriptions reinforce the boundaries.
All five names follow a strict snake_case pattern of <domain>_<subject>_<agent-noun>, e.g. python_ast_sandbox_escape_detector, regex_redos_exponential_scanner. The convention is applied uniformly with no stylistic deviations.
Five tools is a well-scoped set for a focused security-audit server, with each tool covering a distinct check. No tool feels redundant or missing for the stated surface.
The surface covers several sandbox-relevant classes (escape, SQLi, ReDoS, seccomp, CORS) but omits common adjacent checks like shell injection, deserialization/pickle, and path traversal. Agents can work around these gaps, and notably one tool generates filters while the rest audit, a minor asymmetry.