Sandcastle — security grade SAFE, quality 62/100

Security audit verdict: SAFE · quality 62/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by gizmax · MCP Server · ★ 83

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Sandcastle safe to install? View the security audit →

About Sandcastle

Sandcastle Your box. Your brains. Your data. Sandcastle is sovereign agent infrastructure: an open-source, production-ready workflow orchestrator that runs AI agents entirely on hardware you control - local models at $0/run, hard data-residency enforcement, and a tamper-evident audit trail. When you want the cloud, it's there too: 7 AI providers with auto-failover, 22 step types including Claude Managed Agents, 15 agent templates, 4 OCR engines, EU AI Act compliance features, and a full-featured dashboard. Define workflows in YAML or let AI design them for you. European-built. v0.33.0 — "Your Box, Your Brains" The cloud was always someone el

aiai-agentsaudit-trailcompliancecost-trackingdagdashboardeu-ai-actfastapillm

Quick Facts

Stars83
Forks7
LanguagePython
CategoryMCP Server
Quality Score61.6062711142895/100
Open Issues3
Last Updated2026-08-26
Created2026-02-15
Platformsmcp, python
Est. Tokens~25k

Compatible Skills

These tools work well together with Sandcastle for enhanced workflows:

  • clawmetry — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • hivemind — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • Claude-Skills — semantic(0.20)+complementary+rare_topics+same_lang+similar_pop+shared_platform (56%)
  • vnx-orchestration — semantic(0.18)+complementary+rare_topics+same_lang+similar_pop+shared_platform (56%)

Sandcastle alternative? Top 6 similar tools

Looking for a Sandcastle alternative? If you're comparing Sandcastle with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • fim-agent by fim-ai · ⭐ 93

    LLM-powered Agent Runtime with Dynamic DAG Planning & Concurrent Execution

  • mate by antiv · ⭐ 92

    Production-ready multi-agent orchestration engine built on Google ADK. Database-driven agent config, 50+ LLM p

  • mcp-server by strands-agents · ⭐ 293

    This MCP server provides documentation about Strands Agents to your GenAI tools, so you can use your favorite

  • orchestkit by yonatangross · ⭐ 283

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • omnicoreagent by omnirexflora-labs · ⭐ 246

    Open Python agent harness for production AI apps: tools, MCP, memory, workspace, telemetry, subagents, backgro

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is Sandcastle?

Sandcastle is Describe what you want. Go home. Sandcastle ships it. 6 AI providers, EU data residency, smart failover, cost intelligence, 20 step types, 236 templates. European-built, open source. pip install sandc. It is categorized as a MCP Server with 83 GitHub stars.

What programming language is Sandcastle written in?

Sandcastle is primarily written in Python. It covers topics such as ai, ai-agents, audit-trail.

How do I install or use Sandcastle?

You can find installation instructions and usage details in the Sandcastle GitHub repository at github.com/gizmax/Sandcastle. The project has 83 stars and 7 forks, indicating an active community.

What are the best alternatives to Sandcastle?

The top alternatives to Sandcastle on Agent Skills Hub include fim-agent, mate, mcp-server. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools