No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by sandbaseai · MCP Server · ★ 648
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is sandbase-harness safe to install? View the security audit →
managed-agents A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure. Why Agent SDKs handle the model loop. Production agents need more: persistent sessions, tool governance, sandbox boundaries, credential handling, memory, auditability, and a UI for humans to inspect what happened. is that runtime layer — not a visual workflow builder and not another model SDK. Features Claude Managed Agents-style API and local Console SQLite-backed agents, sessions, environments, credential vaults, memory stores, files, skills, and API keys — SQLite metadata by default local file/skill bytes stored in the workspace state directory Resumable Server-Sent Events for session replay and debugging One active model provider boundary configured through Settings V2 Sandbox backends: local process, Docker (per-session containers), Kubernetes (kubectl exec/cp), self-hosted worker queue Settings V2: one workspace model vendor, loop engine, storage, memory, sandbox — with validation, form/JSON modes, and restart flow MC
| Stars | 648 |
| Forks | 69 |
| Language | TypeScript |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 76.0138638780136/100 |
| Open Issues | 19 |
| Last Updated | 2026-09-20 |
| Created | 2026-07-11 |
| Platforms | docker, k8s, mcp, node |
| Est. Tokens | ~16k |
These tools work well together with sandbase-harness for enhanced workflows:
Looking for a sandbase-harness alternative? If you're comparing sandbase-harness with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Supercharge AI Agents, Safely
Open-source agent runtime — SSH-native isolation, eBPF egress policy, Kubernetes + LXC backends, GPU passthrou
#1 MCP Gateway on GitHub 🔌 200+ ready connectors + any REST/SOAP/GraphQL/SQL system as custom connectors for
One place to manage & connect to all your MCP servers
Structural memory for AI coding agents. Bi-temporal graph, MCP-native, zero LLM calls. Cursor · Claude Code ·
Remote approvals, policy checks, and execution evidence for unattended AI agents.
Explore other popular mcp server tools:
sandbase-harness is Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.. It is categorized as a MCP Server with 648 GitHub stars.
sandbase-harness is primarily written in TypeScript. It covers topics such as agent-harness, agent-observability, agent-plugin.
You can find installation instructions and usage details in the sandbase-harness GitHub repository at github.com/sandbaseai/sandbase-harness. The project has 648 stars and 69 forks, indicating an active community.
sandbase-harness is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to sandbase-harness on Agent Skills Hub include mcpproxy-go, Containarium, anythingmcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: