Bawbel Stage 3 behavioral sandbox — runtime analysis harness for AI skill and MCP server files.
257
Behavioral analysis harness used by Bawbel Scanner for Stage 3 runtime scanning of AI skill files and MCP servers.
Runs inside an isolated Docker container, reads the component file mounted at /component,
and outputs a structured JSON report of detected malicious behaviors.
| Category | Examples |
|---|---|
| Network egress | Outbound calls to pastebin, rentry, ngrok, webhook capture sites |
| Credential access | Reads of .env, .ssh/, private key files |
| Persistence | Writes to ~/.bashrc, cron directories, service installs |
| Code execution | curl · wget pipe-to-shell, eval $(), exec(), encoded payloads |
This image is pulled and managed automatically by Bawbel Scanner. You do not need to run it directly.
# Enable Stage 3 sandbox in Bawbel Scanner
BAWBEL_SANDBOX_ENABLED=true bawbel scan ./skill.md
# Force local build instead of Hub pull (air-gapped)
BAWBEL_SANDBOX_ENABLED=true BAWBEL_SANDBOX_IMAGE=local bawbel scan ./skill.md
{
"version": "1.2.0",
"component": "/component",
"network": [{"dst": "pastebin.com", "port": 443, "reason": "Known malicious paste site", "line": 7}],
"filesystem": [{"path": ".env", "op": "read", "reason": "Env file - credential theft", "line": 26}],
"processes": [{"cmd": "curl pipe sh", "pid": 0, "reason": "curl pipe - arbitrary code exec", "line": 12}],
"encoded": []
}
Content type
Image
Digest
sha256:d2b49ccab…
Size
17.2 MB
Last updated
4 months ago
docker pull bawbel/sandbox