Skip to content

MCP provider · promptkit codegen

The agent thinks.The sandbox has the hands.

Safe, structured, containerised tools that let a PromptKit agent read, edit, and verify code — separated from the agent's runtime by an MCP wire.

brain / hands · one mcp wire

A PromptKit agent sends tool calls over an MCP wire to filesystem, shell and verification tools, which act on a shared workspace. agent · brain mcp wire filesystem shell verification workspace

The codegen sandbox is the hands of a PromptKit codegen agent. The agent (the brain) runs the model and holds context; the sandbox executes everything that touches a filesystem, spawns a process, or makes a network call. They talk over MCP (HTTP+SSE). Prompt injection or model error can corrupt the sandbox; it cannot corrupt the agent runtime or the host.

Filesystem

Read, Write, Edit operate on a single workspace root. Every path is resolved and checked for containment before any I/O. Edit returns post-edit lint findings inline.

Search

Glob (mtime-sorted, gitignore-aware) and Grep (ripgrep-backed) for fast navigation. Structured file:line:rule: message output on lint results.

Shell

Bash foreground + background (via BashOutput / KillShell). Per-call timeouts kill the whole process group; a small denylist catches footguns.

Verification

run_tests, run_lint, run_typecheck use project-type detection (Go today; more languages behind the Detector interface) to run the right command.

Vendor MCP for the web

The sandbox deliberately doesn’t ship WebFetch/WebSearch — wire vendor MCP servers (Brave, Exa, Tavily, official fetch) alongside it instead. See non-sandbox tools.

Safe by default

Path containment, command denylist, secret scrubbing — layered defence-in-depth. The Docker container is the real trust boundary.

One container, one flag, one workspace mount. The sandbox is a provider behind PromptKit’s agent — PromptKit asks for a sandbox, the provider returns an MCP endpoint.

codegen-sandbox · local
❯ docker run -p 8080:8080 -v $PWD:/workspace ghcr.io/altairalabs/codegen-sandbox
# mcp over http+sse · workspace mounted read-write
✓ codegen-sandbox listening on :8080 (workspace=/workspace)
32 tools registered · scrubbing on · denylist on
❯

The codegen sandbox is one provider behind PromptKit’s agent — the piece that actually runs tool calls. PromptKit asks for “a sandbox”; the provider returns an MCP endpoint. The agent then calls tools over MCP; the sandbox executes them inside a container. The star chart at the top of this page is that path end to end.

flowchart TB
subgraph Agent["PromptKit agent"]
direction LR
M[Model] --- C[Context]
end
subgraph Wire["MCP wire"]
direction LR
MW[scrubbing middleware]
end
subgraph Sandbox["Sandbox container"]
direction TB
W[workspace.Resolve<br/>path containment]
D[Bash denylist]
S[secrets interface<br/>+ scrub registry]
W --- D --- S
end
Agent -- tool call --> Wire
Wire -- structured args --> Sandbox
Sandbox -- structured output --> Wire
Wire -- scrubbed text --> Agent