MCP DEVBOX

checking · runtime

00 · WHAT IT SOLVES

A general shell gives the model more authority than most tasks require.

ChatGPT working on real infrastructure without receiving a free shell.

MCP Devbox lets an agent read, change, test, publish and deploy projects through narrow tools, immutable policy, denied secrets and verifiable operations.

The owner chooses between read-only access, explicit review or autonomy within preconfigured limits.

PRODUCT STATUS

IMPLEMENTED

Repository operations, GitHub pull requests and diagnostics, Coolify deployment, Brain memory, bounded results, authenticated console and outbound Edge workcells.

EXPERIMENTAL

Broader execution profiles and advanced local workcells remain evidence-driven rather than assumed universal.

PLANNED

Multi-tenant operation and universal isolation are not claimed. Any future expansion must preserve the same authority boundary.

01 · AUTHORITY COMPARISON

SAME GOAL. RADICALLY DIFFERENT AUTHORITY.

The difference is not whether the agent can produce a change. It is how much authority it receives to attempt it and how each effect is constrained.

BROAD AMBIENT AUTHORITY

Agent with a general shell

  1. The model receives a general shell.
  2. The shell inherits credentials and environmental access.
  3. The model composes arbitrary commands.
  4. The effect can reach resources the task did not require.
  5. Consequences are difficult to bound before execution.

OUTCOME: available authority depends on the environment.

EXPLICIT BOUNDED AUTHORITY

MCP Devbox

  1. The model sees only tools with closed schemas.
  2. Repositories, branches, applications and targets are authorized in advance.
  3. Paths and secrets are denied; commands and parameters are validated.
  4. The read-only, ask or allow mode defines how authorized work proceeds.
  5. Bound plans revalidate state before a consequential effect.
  6. The result remains bounded, redacted and audited.

OUTCOME: the effect stays inside configured authority.

CHOOSE HOW THE AGENT PROCEEDS

The mode changes the workflow; it does not remove server boundaries.

MODE ≠ PLAN ≠ HUMAN GRANT

Observe and diagnose without changing files or executing commands.

The path jail, secret denial, redaction, input and output bounds, and audit remain active.

CAUTIONMCP Devbox reduces the authority available. It does not make generated code or every allowed operation inherently safe.

ABSENT BY CONSTRUCTION

Force push, arbitrary host paths, public plan approval and unauthenticated tool execution are not hidden switches. They are not part of this surface.

02 · READ-ONLY GUIDED DEMO

FROM REQUEST TO PRODUCTION COMMIT

This story is generated from Pixelgrama's public, versioned manifest. It does not query GitHub during page load and grants no authority over MCP Devbox.

DEMO BOUNDARY

Public, unauthenticated and read-only. It cannot invoke tools, open the console, approve plans, request grants, read credentials or access repositories.

Loading the embedded public manifest...

  1. REQUEST

    Awaiting evidence...

    The canonical summary is shown verbatim from the public manifest.

  2. PERIMETER

    repository
    view manifest
    base branch
    historical mode
    exact tools
    Not published in the historical evidence.

    Includes

    • Awaiting evidence...

    Excludes

    • Awaiting evidence...
  3. CHANGE

    Purposes and SHAs come from the manifest. Each PR's public Files changed view keeps the file-level detail without duplicating it here.

    1. Awaiting evidence...
  4. VALIDATION

    • Awaiting evidence...
  5. EXTERNAL OPERATIONS

    Direct and plan-protected operation classes are documented publicly; plan IDs, approvals and audit remain private.

    Documented direct operations

    • Awaiting evidence...

    Plan-protected operations

    • Awaiting evidence...

    In ask, a reviewable effect waits for approval. In allow, an authorized operation may continue without that pause. In both cases, the plan remains exact, temporary, revalidated and single-use. Pixelgrama's exact historical mode is not publicly proven.

  6. RESULT

    production
    public wall
    identity
    observed commit
    source main
    verified
    infrastructure

    Awaiting comparison...

    Earlier PR SHAs are historical evidence. The observed commit above is the production state verified on the stated date.

03 · POLICY EXPLORER

ASK THE AGENT TO MISBEHAVE

Choose a request. This is a local simulation of documented policy outcomes. It sends no request to MCP Devbox and grants no authority.

SELECT A REQUEST

policy> awaiting local input

Every verdict names the invariant that produces it.

04 · REQUEST PATH

HOW A REQUEST TRAVELS

Request path with a direct policy route for reads and allowlisted commands, and an approval route for consequential actions.
The public landing is outside this path. It cannot submit a request, approve a plan or reach a private adapter.

05 · HOST & ADMISSION

A MICRO VPS, MEASURED INSTEAD OF GUESSED

The control plane runs on a 2 vCPU, 3.805 GiB KVM guest. The dated 2026-07-22 baseline measured idle and a real no-cache deployment. CPU, not memory, was the demonstrated binding resource.

MEASURERESULTINTERPRETATION
idle CPU p9541.10%control-plane baseline
intensive build CPU p9593.20%serialized heavy work
host memory peak2.33 GiBno OOM observed
CPU stealnegligibleguest workload contention

P16 TARGET-VPS ACCEPTANCE · CLOSED

Both preflights returned 0. All six calibration runs completed with exit status 0 and zero OOM. The deterministic selector chose 65%; 50% was rejected by duration regression.

CPU quota
650 ms per second
MemoryHigh
1280 MiB
MemoryMax
1792 MiB
TasksMax
512
service
active and enabled

06 · EVIDENCE

REAL GATES, INCLUDING THE FAILURES

FAIL five High container findings and one reachable Go vulnerability blocked closure.

FIXED affected packages were upgraded or removed; the final image gate proved zero High/Critical findings.

CLOSED CodeQL path and cookie findings were remediated at source with adversarial regression tests.

SEALED PR #57 made the catalog discoverable and passed 16 exact-head checks.

SEALED PR #58 normalized documentary whitespace without weakening literal contracts; 16 checks passed.

ACCEPTED P16 target-VPS calibration selected 65% after two preflights and six successful runs.

A threshold is not edited to obtain green. A failure is diagnosed, a bounded change is made, and the full exact-head gate set runs again.

07 · VULNERABILITY LEDGER

DETECTED, REMEDIATED, REGRESSION-TESTED

REACHABLE GO TLS FINDING CLOSED

GO-2026-5856 was reachable through repository call paths.

detected
Govulncheck blocking job
fixed
Go advanced to the patched release across builds and workflows

GNU WGET FINDINGS CLOSED

Three High findings existed in the final runtime image.

detected
SBOM plus Grype gate
fixed
standalone Wget removed; BusyBox applet used for health checks

NPM BUNDLED TREE CLOSED

Affected sigstore and picomatch copies remained after the first attempted upgrade.

detected
second image scan
fixed
patched npm installed and the vulnerable bootstrap tree removed entirely

PATH INJECTION FLOW CLOSED

Remote repository input previously participated in validation-runner paths.

detected
CodeQL
fixed
server-owned registry entries and Linux descriptor revalidation before execution

SESSION COOKIE POSTURE CLOSED

Dynamic cookie security could not be proven on every path.

detected
CodeQL
fixed
creation and deletion always use Secure, HttpOnly and SameSite Strict

08 · LIVE RUNTIME IDENTITY

VERIFY THE DEPLOYED PROCESS

This panel reads the same safe public identity exposed by /version. No credential is sent and no private state is requested.

status
checking
version
commit
built at
protocol
tool count
catalog hash

Loading public runtime identity.

Independent checks: liveness JSON identity authenticated operator console.

09 · HONEST LIMITS

WHAT THIS IS NOT

  • Not a public control panel. This landing cannot call tools, approve plans or inspect private state.
  • Not multi-tenant. The system is single-owner by design.
  • Not a universal terminal. Arbitrary shell access is deliberately absent.
  • Not universal OS isolation. Hard local containment is Linux-oriented; Windows use runs through WSL.
  • Not proof against stolen owner credentials. Narrow authority reduces blast radius but cannot remove trust.
  • Not a claim that every planned profile or orchestrator is implemented.

Any agent. Any stack. Explicit guardrails. Auditable delivery.

Public source and documentation