_ _
| | (_)
___ _ _ _ __ ___ _ __| |__ _____ __ __ _ _
/ __| | | | '_ \ / _ \ '__| '_ \ / _ \ \/ / / _` | |
\__ \ |_| | |_) | __/ | | |_) | (_) > < | (_| | |
|___/\__,_| .__/ \___|_| |_.__/ \___/_/\_(_)__,_|_|
| |
|_|
🧰 SuperBox
SuperBox (inspired by Docker Hub) helps you discover, deploy, and test MCPs in isolated sandboxes ( Demo Video ). It includes:
- A Python (Click) CLI to initialize metadata, run security scans, push to a registry (R2), search, and configure popular AI clients (VS Code, Cursor, Windsurf, Claude, ChatGPT)
- A Golang (Gin) backend to list/get/create MCP servers with optional pricing and security reports
- A Cloudflare Worker + Durable Object executor that runs MCP servers on demand directly from their Git repositories using a lightweight TypeScript interpreter (Cloudflare Workers blocks
eval()and exceeds the WASM bundle size limit, making Pyodide unusable)
Why this project:
- There's no centralized MCP registry to discover all MCPs, and many lack clear usage docs.
- MCPs on our platform pass a 5-step security/quality check (SonarQube, Bandit, GitGuardian) to reduce vulnerabilities and promote best practices.
- Unlike MCPs that run locally on your machine, MCP servers here execute in sandboxed environments and return responses securely.
Key Features
- Central MCP Registry: R2-backed registry with per-server JSON for easy discovery and portability.
- Sandboxed Execution: MCP servers run in Cloudflare Durable Objects and return responses securely. The executor supports
requests-based HTTP tools; seecloudflare/README.mdfor the full scope. - Security Pipeline (5-step): SonarQube, Bandit, and GitGuardian checks with a unified report.
- One-Command Publish:
superbox pushscans, discovers tools, and uploads a unified record to R2. - Client Auto-Config:
superbox pull --client cursor|vscode|...writes correct MCP config pointing to the Cloudflare Worker. - Terminal Runner:
superbox run --name <server>starts an interactive prompt against the Cloudflare executor. - Live Logs:
superbox logs --name <server>shows instructions for streaming logs viawrangler tail. - Tool Discovery: Regex-based discovery across Python code and optional Node
package.jsondefinitions.
📚 Documentation
For complete documentation, setup guides, API references, and CLI usage:
🔗 https://superbox.1mindlabs.org/docs
📄 Research Paper
The IEEE research paper for SuperBox is available in the ieee/ directory:
🗂️ Project Structure
.
├── docs/ # Documentation (INSTALL.md, SETUP.md)
├── ieee/ # IEEE research paper (paper.pdf, paper.tex)
├── src/
│ └── superbox/
│ ├── cli/ # CLI: init, auth, push, pull, run, search, inspect, test, logs
│ │ ├── commands/ # CLI subcommands
│ │ └── scanners/ # SonarCloud, Bandit, ggshield, tool-discovery
│ ├── server/ # Golang (Gin) app + handlers
│ │ ├── handlers/ # servers, payment, auth, health
│ │ ├── models/ # Request/response types
│ │ ├── helpers/ # Python R2 helper
│ │ └── templates/ # Landing page
│ └── shared/ # Config, models, R2/S3-compat utils
├── pyproject.toml # Project metadata & dependencies
├── Dockerfile # Server container
├── docker-compose.yaml # Optional local stack
└── tests/ # pytest suite - see tests/README.md
🌐 API Reference
The HTTP API provides endpoints for server management, authentication, and payments.
For complete API documentation, see: https://superbox.1mindlabs.org/docs/api
🔧 CLI Overview
The SuperBox CLI provides commands for authentication, server management, and testing:
Authentication:
superbox auth register– Register a new accountsuperbox auth login– Log in (email/Google/GitHub)superbox auth logout– Log outsuperbox auth status– Check authentication statussuperbox auth refresh– Refresh authentication token
Server Management:
superbox init– Initialize a new MCP server projectsuperbox push– Publish server to registrysuperbox pull– Download and configure server for AI clientssuperbox search– Search for servers in registrysuperbox inspect– View server details and security reportsuperbox test– Test server directly from repository (without registry)
Execution & Monitoring:
superbox run– Run server in interactive modesuperbox logs– View server execution logs
For detailed CLI documentation and usage examples, see: https://superbox.1mindlabs.org/docs/cli
📦 Installation
pip install superbox
- PyPI: https://pypi.org/project/superbox
- npm: coming soon
See docs/INSTALL.md for complete installation instructions.
📄 License
This project is licensed under the MIT License.
👥 Authors
Core Contributors:
Acknowledgments:
Metadata
Release files for superbox 0.6.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| superbox-0.6.0.tar.gz | 29.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| superbox-0.6.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 66.0 kB
Release files / superbox-0.6.0.tar.gz
| Download URL | superbox-0.6.0.tar.gz |
|---|---|
| Size | 29.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8413170bbd8e670db51533ff8629cc860cd785e4dec09176d22756ab316f16cd
|
|
BLAKE2b-256 checksum How to use checksums |
542d14f1bb094d68d882a5fa23710af533b2c107c4a8d14d962ac581849d7433
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 15, 2026.
Transparency logRelease files / superbox-0.6.0-py3-none-any.whl
| Download URL | superbox-0.6.0-py3-none-any.whl |
|---|---|
| Size | 36.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d7980bb20754ec3a4ad7d39de0b47e1ba2148ee6828317453ce8415dd4f35619
|
|
BLAKE2b-256 checksum How to use checksums |
d0f9e6ea4872c824f34d2298bae7c3bdde06cec566dd9a39924ca0a9a92d37ec
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 15, 2026.
Transparency log