Sandbox Code Auditor MCP
<p align="center">
<img src="./assets/logo.png" width="130" height="130" alt="Sandbox Code Auditor MCP Logo" />
</p>
# Sandbox Code Auditor MCP
[](https://smithery.ai)
[](https://modelcontextprotocol.io)
[](https://base.org)
[](#included-tools)
[](LICENSE)
**Python sandbox escape detection, SQL injection taint analysis, Seccomp BPF filter generation, and ReDoS regex scanning.**
Built specifically for Coding agents (Claude Code, Cursor, AutoGen), CI/CD security pipelines, and automated code review bots.
---
## ⚡ Quickstart
### Smithery Install
```bash
smithery skill add whambammy/sandbox-code-auditor-mcp
```
### Claude Desktop / Cursor (`claude_desktop_config.json`)
```json
{
"mcpServers": {
"sandbox-code-auditor-mcp": {
"command": "npx",
"args": ["-y", "@whambammy/sandbox-code-auditor-mcp"],
"env": {
"PAYMENT_WALLET": "0x9793E7269b3301893318dEa8338576Ba612F39B3",
"BASE_RPC_URL": "https://mainnet.base.org"
}
}
}
}
```
---
## 🛠️ Included Tools
| Tool Name | Price (USDC) | Capability |
| :--- | :---: | :--- |
| `python_ast_sandbox_escape_detector` | $0.045 | Audits Python ASTs for dangerous builtins, `__subclasses__` gadget chains, `importlib`, and bytecode compilation tricks used in sandbox escapes. |
| `sql_ast_sqli_taint_analyzer` | $0.040 | Parses SQL query ASTs to verify parameterized binding, flagging raw string concatenations that lead to second-order SQL injection vulnerabilities. |
| `regex_redos_exponential_scanner` | $0.035 | Audits regular expressions for catastrophic polynomial and exponential backtracking (ReDoS) vulnerabilities using NFA/DFA cycle decomposition. |
| `linux_seccomp_bpf_filter_generator` | $0.040 | Generates minimal Seccomp BPF syscall filter profiles for sandboxing untrusted agent processes, blocking ptrace, fork, and raw socket creation. |
| `cors_policy_preflight_misconfig_checker` | $0.025 | Audits CORS response headers for dangerous wildcards with credentials (`Access-Control-Allow-Origin: *` + `Credentials: true`). |
---
## 🔄 End-to-End Workflow
An autonomous coding agent receives a script from an external PR -> analyzes the Python AST for sandbox escapes -> audits SQL queries for injection taint -> tests regexes for ReDoS -> outputs a Seccomp BPF filter to execute the code securely.
---
## 💰 The x402 Base L2 Micropayment Protocol
When an agent invokes a tool without payment, the server responds with a deterministic `HTTP 402 Payment Required` challenge containing:
- Target tool price in USDC
- Base Native USDC Contract: `0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`
- Recipient payout wallet address
- Single-use cryptographic nonce
Once broadcasted on Base L2, resubmitting with `paymentSignature` unlocks deterministic execution.
---
## 📄 License
MIT License. Created by [Whambammy](https://github.com/Whambammy).
TDQS
Scored across 5 tools
Each tool targets a completely distinct artifact and vulnerability class (Python AST escape, SQL taint, regex ReDoS, Seccomp BPF, CORS headers). There is no realistic scenario where an agent would confuse one for another, and the descriptions reinforce the boundaries.
All five names follow a strict snake_case pattern of <domain>_<subject>_<agent-noun>, e.g. python_ast_sandbox_escape_detector, regex_redos_exponential_scanner. The convention is applied uniformly with no stylistic deviations.
Five tools is a well-scoped set for a focused security-audit server, with each tool covering a distinct check. No tool feels redundant or missing for the stated surface.
The surface covers several sandbox-relevant classes (escape, SQLi, ReDoS, seccomp, CORS) but omits common adjacent checks like shell injection, deserialization/pickle, and path traversal. Agents can work around these gaps, and notably one tool generates filters while the rest audit, a minor asymmetry.