Agent Toolbox runs on your own machine — the client starts it, so there is no endpoint to ping. 39 installs a week from npm. Last commit 20 Jul 2026.
26 deterministic, offline pre-action safety gates for AI agents, each with a signed verdict.
We read the source, 20 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
const METADATA_IPV4 = new Set<string>(["169.254.169.254"]);
if (fw === "doas") {
const METADATA_IPV4 = new Set<string>(["169.254.169.254"]);
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
return finding("CMD-CRONTAB-OVERWRITE", "medium", idx, "crontab -r removes the crontab", snippet);
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Agent Toolbox and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add agent-toolbox -- npx -y agentoolbox-mcp
{
"mcpServers": {
"agent-toolbox": {
"args": [
"-y",
"agentoolbox-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.agent-toolbox]
command = "npx"
args = ["-y", "agentoolbox-mcp"]
{
"mcpServers": {
"agent-toolbox": {
"args": [
"-y",
"agentoolbox-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"agent-toolbox": {
"args": [
"-y",
"agentoolbox-mcp"
],
"command": "npx"
}
}
}
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Deterministic authorization for one proposed AI agent action, returned with a signed receipt.
Deterministic authorization and security guard for AI agent actions with signed receipts.
Deterministic prompt-injection detector; signed, offline-verifiable verdicts. Not an LLM.
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
Deterministic pre-execution safety certification for autonomous AI agents.
Deterministic market-state engine for trading agents — state, gate, coordinates, with receipts.
Answers built from our own checks of this server.