No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by jegly · MCP Server · ★ 844
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Box safe to install? View the security audit →
[]() []() [, vision models (VLM), image generation (Stable Diffusion)
Local RAG MCP server for Claude Code — hybrid search (semantic + BM25), cross-encoder reranking, 13 MCP tools,
Explore other popular mcp server tools:
Box is The most advanced, fully offline client-side AI suite on Android today.. It is categorized as a MCP Server with 844 GitHub stars.
Box is primarily written in Kotlin. It covers topics such as android, android-ai-app, artificial-intelligence.
You can find installation instructions and usage details in the Box GitHub repository at github.com/jegly/Box. The project has 844 stars and 53 forks, indicating an active community.
The top alternatives to Box on Agent Skills Hub include OGAM, Atomic-Chat, nocturne_memory. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: