sandbase-harness — security grade SAFE, quality 76/100

Security audit verdict: SAFE · quality 76/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by sandbaseai · MCP Server · ★ 648

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is sandbase-harness safe to install? View the security audit →

About sandbase-harness

managed-agents A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure. Why Agent SDKs handle the model loop. Production agents need more: persistent sessions, tool governance, sandbox boundaries, credential handling, memory, auditability, and a UI for humans to inspect what happened. is that runtime layer — not a visual workflow builder and not another model SDK. Features Claude Managed Agents-style API and local Console SQLite-backed agents, sessions, environments, credential vaults, memory stores, files, skills, and API keys — SQLite metadata by default local file/skill bytes stored in the workspace state directory Resumable Server-Sent Events for session replay and debugging One active model provider boundary configured through Settings V2 Sandbox backends: local process, Docker (per-session containers), Kubernetes (kubectl exec/cp), self-hosted worker queue Settings V2: one workspace model vendor, loop engine, storage, memory, sandbox — with validation, form/JSON modes, and restart flow MC

agent-harnessagent-observabilityagent-pluginagent-runtimeagent-sandboxai-agentsai-infrastructureaudit-loggingdeepseek-harnessdevops

Quick Facts

Stars648
Forks69
LanguageTypeScript
CategoryMCP Server
LicenseApache-2.0
Quality Score76.0138638780136/100
Open Issues19
Last Updated2026-09-20
Created2026-07-11
Platformsdocker, k8s, mcp, node
Est. Tokens~16k

Compatible Skills

These tools work well together with sandbase-harness for enhanced workflows:

  • dsh-cc-tui — semantic(0.46)+complementary+rare_topics+same_lang+similar_pop+shared_platform (71%)
  • cetus — semantic(0.39)+complementary+rare_topics+same_lang+similar_pop+shared_platform (68%)
  • dsh-TUI — semantic(0.36)+complementary+rare_topics+same_lang+similar_pop+shared_platform (67%)
  • modsearch — semantic(0.36)+complementary+rare_topics+same_lang+similar_pop+shared_platform (67%)
  • modlens — semantic(0.34)+complementary+rare_topics+same_lang+similar_pop+shared_platform (66%)

sandbase-harness alternative? Top 6 similar tools

Looking for a sandbase-harness alternative? If you're comparing sandbase-harness with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcpproxy-go by smart-mcp-proxy · ⭐ 377

    Supercharge AI Agents, Safely

  • Containarium by FootprintAI · ⭐ 281

    Open-source agent runtime — SSH-native isolation, eBPF egress policy, Kubernetes + LXC backends, GPU passthrou

  • anythingmcp by HelpCode-ai · ⭐ 250

    #1 MCP Gateway on GitHub 🔌 200+ ready connectors + any REST/SOAP/GraphQL/SQL system as custom connectors for

  • MCPJungle by mcpjungle · ⭐ 1.2k

    One place to manage & connect to all your MCP servers

  • memtrace-public by syncable-dev · ⭐ 472

    Structural memory for AI coding agents. Bi-temporal graph, MCP-native, zero LLM calls. Cursor · Claude Code ·

  • DashClaw by ucsandman · ⭐ 306

    Remote approvals, policy checks, and execution evidence for unattended AI agents.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is sandbase-harness?

sandbase-harness is Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.. It is categorized as a MCP Server with 648 GitHub stars.

What programming language is sandbase-harness written in?

sandbase-harness is primarily written in TypeScript. It covers topics such as agent-harness, agent-observability, agent-plugin.

How do I install or use sandbase-harness?

You can find installation instructions and usage details in the sandbase-harness GitHub repository at github.com/sandbaseai/sandbase-harness. The project has 648 stars and 69 forks, indicating an active community.

What license does sandbase-harness use?

sandbase-harness is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to sandbase-harness?

The top alternatives to sandbase-harness on Agent Skills Hub include mcpproxy-go, Containarium, anythingmcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools