Skip to main content
Glama
alphaparkinc

genpark-agent-bash-command-sandbox-guard-skill

Official

genpark-agent-bash-command-sandbox-guard-skill

Python 3.9+ License MIT MCP Compatible GenPark AI Zero Dependencies


⚡ Overview & Architectural Significance

genpark-agent-bash-command-sandbox-guard-skill provides zero-dependency, deterministic agentic execution safety, sandboxing, and financial circuit breakers engineered strictly using Python 3.9+ standard library.

🌟 Key Architectural Capabilities

  • Zero External Dependencies: Operates exclusively via pure Python (math, re, collections, heapq, hashlib, json). Zero pip install overhead, zero C-extension compile errors.

  • Enterprise Agent Safety Invariants: Implements formal defenses against destructive shell commands, prompt injections, runaway spend loops, differential privacy data leakage, and planning deadlocks.

  • Native Anthropic MCP Protocol: Compliant with standard JSON-RPC 2.0 stdio MCP specifications for Claude Desktop, Cursor, and Windsurf.


Related MCP server: TripWire MCP Server

🏗️ Architectural Safety State Machine

flowchart TD
    UserPrompt["Incoming User Instruction / External Input"] --> InjectionGuard["Prompt Injection & Jailbreak Sentinel"]
    
    InjectionGuard -->|Malicious Injection| BlockPrompt["Reject Prompt (400 Bad Request)"]
    InjectionGuard -->|Safe Prompt| AgentPlanner["Autonomous Agent Planner / LLM Core"]
    
    AgentPlanner --> CircuitBreaker["Token Spend & Cost Circuit Breaker"]
    CircuitBreaker -->|Budget Exceeded| FreezeSpend["Freeze Execution & Alert Admin"]
    CircuitBreaker -->|Within Budget| LoopDetector["Deadlock & Liveloss Loop Detector"]
    
    LoopDetector -->|Infinite Loop Detected| BreakLoop["Inject Corrective Guidance & Reroute Plan"]
    LoopDetector -->|Healthy Trajectory| CommandSandbox["Bash / Subprocess Sandbox Guard"]
    
    CommandSandbox -->|Destructive / Traversal| BlockCmd["Block Execution (Security Violation)"]
    CommandSandbox -->|Safe Command| ToolExec["Safe Tool Execution"]
    
    ToolExec --> PrivacyGuard["Synthetic Data Differential Privacy Guard"]
    PrivacyGuard --> SanitizedOutput["Sanitized Output & Verified Return"]

🚀 Quickstart & Standalone Execution

Local Python Client Usage

from client import AgentBashCommandSandboxGuard

# Initialize engine
engine = AgentBashCommandSandboxGuard()

# Execute self-testing benchmark suite
result = engine.run_benchmark_bash_guard()
print("Execution Result:", result)

🔌 One-Click MCP Integration (Claude Desktop / Cursor)

Add to your claude_desktop_config.json or cursor.json:

{
  "mcpServers": {
    "genpark-agent-bash-command-sandbox-guard-skill": {
      "command": "python",
      "args": ["-u", "/path/to/genpark-agent-bash-command-sandbox-guard-skill/mcp_server.py"]
    }
  }
}

📦 Smithery.ai & PyPI Deployment

This skill contains pre-configured smithery.yaml and pyproject.toml manifests. Install directly via pip:

pip install git+https://github.com/alphaparkinc/genpark-agent-bash-command-sandbox-guard-skill.git

Related MCP Connectors

Related MCP Servers

  • F
    license
    C
    quality
    C
    maintenance
    Sandbox-first command safety layer for MCP-compatible coding agents, protecting commands executed through its safe_exec tool by blocking destructive operations and requiring human approval for ambiguous commands.
    2
    -
  • A
    license
    A
    quality
    D
    maintenance
    Sandboxed bash execution MCP server for AI agents, using an in-memory virtual filesystem overlay to prevent real filesystem damage, with configurable network access, timeouts, and optional Python/JS runtimes.
    9
    24 npm
    Apache 2.0
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables autonomous AI agents and MCP clients to route tool calls through a zero-trust firewall that blocks dangerous shell commands, redacts secrets and PII, restricts sensitive file access, and logs verdicts. It provides an MCP interceptor decorator to protect MCP server tools with AST-based command injection checks and allow, block, or redact decisions.
    2
    -