Sign inSign up

bawbel/sandbox

By bawbel

•Updated 4 months ago

Bawbel Stage 3 behavioral sandbox — runtime analysis harness for AI skill and MCP server files.

Image
Security
2

257

bawbel/sandbox repository overview

⁠Bawbel Sandbox

Behavioral analysis harness used by Bawbel Scanner⁠ for Stage 3 runtime scanning of AI skill files and MCP servers.

Runs inside an isolated Docker container, reads the component file mounted at /component, and outputs a structured JSON report of detected malicious behaviors.

⁠What it detects
CategoryExamples
Network egressOutbound calls to pastebin, rentry, ngrok, webhook capture sites
Credential accessReads of .env, .ssh/, private key files
PersistenceWrites to ~/.bashrc, cron directories, service installs
Code executioncurl · wget pipe-to-shell, eval $(), exec(), encoded payloads
⁠Usage

This image is pulled and managed automatically by Bawbel Scanner. You do not need to run it directly.

# Enable Stage 3 sandbox in Bawbel Scanner
BAWBEL_SANDBOX_ENABLED=true bawbel scan ./skill.md

# Force local build instead of Hub pull (air-gapped)
BAWBEL_SANDBOX_ENABLED=true BAWBEL_SANDBOX_IMAGE=local bawbel scan ./skill.md
⁠Output format
  {
    "version": "1.2.0",
    "component": "/component",
    "network":    [{"dst": "pastebin.com", "port": 443, "reason": "Known malicious paste site", "line": 7}],
    "filesystem": [{"path": ".env", "op": "read", "reason": "Env file - credential theft", "line": 26}],
    "processes":  [{"cmd": "curl pipe sh", "pid": 0, "reason": "curl pipe - arbitrary code exec", "line": 12}],
    "encoded":    []
  }

Tag summary

Content type

Image

Digest

sha256:d2b49ccab…

Size

17.2 MB

Last updated

4 months ago

docker pull bawbel/sandbox