A Model Context Protocol server for executing tools within isolated sandbox environments. Routes tool calls to sandboxes, manages client sessions, and provides sandbox lifecycle management.
The Agent Sandbox MCP server exposes only 2 tools with minimal documentation and no visible input schemas in the provided source. Tool names lack action verbs and are ambiguous. Descriptions are present but generic and lack actionable detail. No input parameter descriptions visible. No output schemas documented. The server appears to be a proxy/gateway pattern rather than implementing concrete tools, which limits its ability to follow standard tool design patterns. Code review of `pkg/handler/sbtool_handler.go` reveals tool registration but the actual schema definitions are not visible in the provided source material.
Executes a tool within a specified sandbox by proxying the call to the sandbox's MCP server
Lists all available tools within a specified sandbox
Tool names lack action verbs. 'sandbox-executor' and 'sandbox-tools' do not follow verb_noun convention (execute_sandbox, list_sandbox_tools). LLMs cannot infer intent from names alone.
Input schemas visible in declaration but parameter descriptions are minimal or absent. 'arguments' parameter for sandbox-executor has no guidance on expected structure, type, or constraints. Parameter descriptions must explain WHAT each parameter controls, not just declare it required.
No output schemas documented. Tools return unstructured responses without field definitions. LLMs cannot plan downstream tool calls or extract specific data from responses when structure is unknown.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 44 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 59 | - | v1 |
Proxy/gateway pattern conflates tool responsibilities. 'sandbox-executor' accepts arbitrary tool_name and arguments, making it impossible for LLMs to validate input or understand constraints before invocation. This is a meta-tool that delegates to unknown downstream tools.
No error handling guidance. No documentation of what errors sandbox-executor or sandbox-tools might return, what they mean, or how to recover. LLMs cannot self-correct or plan fallbacks.
Tool descriptions lack actionable detail. 'Lists all available tools within a specified sandbox' does not explain WHEN to call this vs. other discovery mechanisms, WHAT the output structure is, or HOW to use results for downstream planning.