Install
$ agentstack add mcp-areebahmeddd-superbox-ai Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
β Flagged1 finding(s); flagged for manual review. Β· v0.1.0 How review works β
- β’ Prompt-injection patterns
- β’ Secret / credential exfiltration
- β’ Dangerous shell & filesystem operations
- β’ Untrusted network calls
- β’ Known-malicious package signatures
- high Dangerous shell/eval execution.
What it can access
- β Network access No
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets No
- β Dynamic code execution Used
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work βAbout
_ _
| | (_)
___ _ _ _ __ ___ _ __| |__ _____ __ __ _ _
/ __| | | | '_ \ / _ \ '__| '_ \ / _ \ \/ / / _` | |
\__ \ |_| | |_) | __/ | | |_) | (_) >
[](https://github.com/areebahmeddd/superbox.ai/actions/workflows/ci.yaml)
[](https://pypi.org/project/superbox)
[](https://pypi.org/project/superbox)
[](https://pypi.org/project/superbox)
[](https://go.dev)
[](LICENSE)
# π§° SuperBox
**SuperBox** (inspired by [Docker Hub](https://hub.docker.com)) helps you discover, deploy, and test MCPs in isolated sandboxes ( [Demo Video]() ). It includes:
- A Python (Click) CLI to initialize metadata, run security scans, push to a registry (R2), search, and configure popular AI clients (VS Code, Cursor, Windsurf, Claude, ChatGPT)
- A Golang (Gin) backend to list/get/create MCP servers with optional pricing and security reports
- A Cloudflare Worker + Durable Object executor that runs MCP servers on demand directly from their Git repositories using a lightweight TypeScript interpreter (Cloudflare Workers blocks `eval()` and exceeds the WASM bundle size limit, making Pyodide unusable)
Why this project:
- There's no centralized MCP registry to discover all MCPs, and many lack clear usage docs.
- MCPs on our platform pass a 5-step security/quality check (SonarQube, Bandit, GitGuardian) to reduce vulnerabilities and promote best practices.
- Unlike MCPs that run locally on your machine, MCP servers here execute in sandboxed environments and return responses securely.
## Key Features
- **Central MCP Registry**: R2-backed registry with per-server JSON for easy discovery and portability.
- **Sandboxed Execution**: MCP servers run in Cloudflare Durable Objects and return responses securely. The executor supports `requests`-based HTTP tools; see `cloudflare/README.md` for the full scope.
- **Security Pipeline (5-step)**: SonarQube, Bandit, and GitGuardian checks with a unified report.
- **One-Command Publish**: `superbox push` scans, discovers tools, and uploads a unified record to R2.
- **Client Auto-Config**: `superbox pull --client cursor|vscode|...` writes correct MCP config pointing to the Cloudflare Worker.
- **Terminal Runner**: `superbox run --name ` starts an interactive prompt against the Cloudflare executor.
- **Live Logs**: `superbox logs --name ` shows instructions for streaming logs via `wrangler tail`.
- **Tool Discovery**: Regex-based discovery across Python code and optional Node `package.json` definitions.
## π Documentation
**For complete documentation, setup guides, API references, and CLI usage:**
π **[https://superbox.1mindlabs.org/docs](https://superbox.1mindlabs.org/docs)**
## π Research Paper
The IEEE research paper for SuperBox is available in the [`ieee/`](ieee/) directory:
- [`paper.pdf`](ieee/paper.pdf) β compiled paper
- [`paper.tex`](ieee/paper.tex) β LaTeX source
## ποΈ Project Structure
```text
.
βββ docs/ # Documentation (INSTALL.md, SETUP.md)
βββ ieee/ # IEEE research paper (paper.pdf, paper.tex)
βββ src/
β βββ superbox/
β βββ cli/ # CLI: init, auth, push, pull, run, search, inspect, test, logs
β β βββ commands/ # CLI subcommands
β β βββ scanners/ # SonarCloud, Bandit, ggshield, tool-discovery
β βββ server/ # Golang (Gin) app + handlers
β β βββ handlers/ # servers, payment, auth, health
β β βββ models/ # Request/response types
β β βββ helpers/ # Python R2 helper
β β βββ templates/ # Landing page
β βββ shared/ # Config, models, R2/S3-compat utils
βββ pyproject.toml # Project metadata & dependencies
βββ Dockerfile # Server container
βββ docker-compose.yaml # Optional local stack
βββ tests/ # pytest suite - see tests/README.md
π API Reference
The HTTP API provides endpoints for server management, authentication, and payments.
For complete API documentation, see: https://superbox.1mindlabs.org/docs/api
π§ CLI Overview
The SuperBox CLI provides commands for authentication, server management, and testing:
Authentication:
superbox auth registerβ Register a new accountsuperbox auth loginβ Log in (email/Google/GitHub)superbox auth logoutβ Log outsuperbox auth statusβ Check authentication statussuperbox auth refreshβ Refresh authentication token
Server Management:
superbox initβ Initialize a new MCP server projectsuperbox pushβ Publish server to registrysuperbox pullβ Download and configure server for AI clientssuperbox searchβ Search for servers in registrysuperbox inspectβ View server details and security reportsuperbox testβ Test server directly from repository (without registry)
Execution & Monitoring:
superbox runβ Run server in interactive modesuperbox logsβ View server execution logs
For detailed CLI documentation and usage examples, see: https://superbox.1mindlabs.org/docs/cli
π¦ Installation
pip install superbox
- PyPI: https://pypi.org/project/superbox
- npm: coming soon
See [docs/INSTALL.md](docs/INSTALL.md) for complete installation instructions.
π License
This project is licensed under the [MIT License](LICENSE).
π₯ Authors
Core Contributors:
Acknowledgments:
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source β we do not rehost the code.
- Author: areebahmeddd
- Source: areebahmeddd/superbox.ai
- License: MIT
- Homepage: https://superbox.1mindlabs.org
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.