Secure Agent Sandboxes MCP server for executing commands in isolated sandbox environments
Single tool with well-structured schema and comprehensive description. The sandbox_exec tool demonstrates good parameter documentation with types, descriptions, and validation constraints. Description is detailed and action-oriented (~320 chars), well above the 10-char minimum and within the productive 10-1024 range. Input schema is complete with all parameters typed and described. However, output schema is not documented in the visible code, and tool lacks explicit error recovery guidance. The description appropriately identifies the tool as an irreversible operation (risk=IRREVERSIBLE), meeting the critical check that state-modifying tools must declare their consequences.
Execute a shell command in a sandbox. The specific sandbox capabilities depend on the configured backend. Commands run in the configured shell. Each call is independent — no state (shell variables, working directory) persists between calls. Use the working_directory parameter or chain commands with && to control execution context. To write files or pass data without shell escaping, use the stdin parameter (e.g., command="cat > file.txt" with content in stdin). Commands time out after the configured timeout seconds by default (override with the timeout parameter for long-running operations).
Output schema not documented. The tool description does not specify what sandbox_exec returns (success/failure format, exit code, stdout/stderr structure, timeout behavior). LLMs cannot plan downstream actions without knowing the response structure.
Error recovery guidance incomplete. While the description mentions timeouts and exit codes implicitly, it lacks actionable error responses. Example: 'If command times out, increase timeout parameter' or 'Non-zero exit code indicates command failure, check stderr in response.'
No input validation constraints documented in parameters. The stdin parameter mentions '2 MiB' limit but timeout parameter only states 'minimum 1 second' without a maximum. Working_directory is documented as 'absolute path' but no validation guidance provided for invalid paths.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 64 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 41 | - | v1 |
Parameter mutual exclusivity ('command' vs 'args') documented but missing guidance on when to use each. Description states they are mutually exclusive but does not explain why an agent would choose args over command (e.g., 'Use args to avoid shell metacharacter escaping; use command for piping/redirection').