github Shell re-analysis due

psyb0t/docker-claudebox

github

Claude Code in Docker. Drop-in OpenAI-compatible API, MCP server, Telegram bot, and CLI — five interfaces, one image. Persistent sessions, file ops, always-on skill injection, and a full dev toolchain (Go, Python, Node, K8s, Terraform, databases) or a minimal image with just the basics.

maintainer
psyb0t
license
WTFPL
first seen
2026-07-27
last seen
2026-09-06
releases · 30d
3
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities 0 tools
transport stdio · streamable-http · http verified reported listed in the official MCP registry counts 0 tools · 0 res · 0 prompts permission surface via code analysis

No tools enumerated yet for this server.

skills & danger signals github-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed commit e4c67d3 · analyzer v33 · 2d ago

skills & prompt files 1

code evidence vv2.3.9 · github-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 31

shell / exec 1

  • shell psyb0t-docker-claudebox-e4c67d3/.agents/plugins/claudebox/bin/cli.js :9 import { spawnSync } from "node:child_process";

secrets 1

  • secrets psyb0t-docker-claudebox-e4c67d3/.agents/plugins/claudebox/bin/cli.js :32 const token = process.env.CLAUDEBOX_MCP_MODE_TOKEN;

declared dependencies 1

  • mcp-remote@0.1.38