Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
BASE_RPC_URLYesBase L2 RPC URL used for settlement.
PAYMENT_WALLETYesRecipient payout wallet address for x402 micropayments on Base L2.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
python_ast_sandbox_escape_detectorA

Audits Python ASTs for dangerous builtins, __subclasses__ gadget chains, importlib, and bytecode compilation tricks used in sandbox escapes. (0.045 USDC on Base L2)

sql_ast_sqli_taint_analyzerA

Parses SQL query ASTs to verify parameterized binding, flagging raw string concatenations that lead to second-order SQL injection vulnerabilities. (0.040 USDC on Base L2)

regex_redos_exponential_scannerA

Audits regular expressions for catastrophic polynomial and exponential backtracking (ReDoS) vulnerabilities using NFA/DFA cycle decomposition. (0.035 USDC on Base L2)

linux_seccomp_bpf_filter_generatorA

Generates minimal Seccomp BPF syscall filter profiles for sandboxing untrusted agent processes, blocking ptrace, fork, and raw socket creation. (0.040 USDC on Base L2)

cors_policy_preflight_misconfig_checkerA

Audits CORS response headers for dangerous wildcards with credentials (Access-Control-Allow-Origin: * + Credentials: true). (0.025 USDC on Base L2)

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4/5.0

Scored across 5 tools

Disambiguation5/5

Each tool targets a completely distinct artifact and vulnerability class (Python AST escape, SQL taint, regex ReDoS, Seccomp BPF, CORS headers). There is no realistic scenario where an agent would confuse one for another, and the descriptions reinforce the boundaries.

Naming Consistency5/5

All five names follow a strict snake_case pattern of <domain>_<subject>_<agent-noun>, e.g. python_ast_sandbox_escape_detector, regex_redos_exponential_scanner. The convention is applied uniformly with no stylistic deviations.

Tool Count5/5

Five tools is a well-scoped set for a focused security-audit server, with each tool covering a distinct check. No tool feels redundant or missing for the stated surface.

Completeness4/5

The surface covers several sandbox-relevant classes (escape, SQLi, ReDoS, seccomp, CORS) but omits common adjacent checks like shell injection, deserialization/pickle, and path traversal. Agents can work around these gaps, and notably one tool generates filters while the rest audit, a minor asymmetry.

Maintenance

ActivityMaintained
ResponsivenessNo issues