Open-source evaluation artifact · Authority boundaries
Public dataset · Experimental characterization profile
MCP Sandbox Authority Boundary Profile
Execution containment is not proof of bounded authority.
Abstract
A profile for making an authority boundary observable.
The MCP Sandbox Authority Boundary Profile is a vendor-neutral, synthetic-only evaluation artifact for characterizing whether an MCP-connected execution sandbox preserves its declared authority boundary. It covers repository and storage scope, workload credentials, revocation timing, network and DNS egress, session isolation, cross-interface consistency, independently reviewable evidence, and cross-module composition. Its purpose is to produce bounded, reviewable observations of a named target in one authorized configuration, not to certify a platform or make a provider finding.
Control question
What authority does the environment actually exercise?
A sandbox can appear contained while its effective authority extends beyond the boundary an operator intended. The profile requires an evaluator to state the declared boundary, run both positive and negative synthetic controls, record the observed effective authority, and bind the result to an evidence record. It treats a result as a characterization only: a pass means the observed behavior matched declared policy under that configuration and observation window.
A sandbox may correctly restrict access to one attached repository while still possessing a broadly scoped credential and unrestricted network egress. Each local control can behave as configured while the composed environment exercises authority beyond the operator’s declared boundary.
Profile coverage
Nine questions that a sandbox boundary must answer.
| ID | Boundary question |
|---|---|
| RS-01 | Attached repository scope |
| RS-02 | Attached storage scope |
| CS-01 | Workload credential scope |
| LC-01 | Credential revocation timing |
| ES-01 | Network and DNS egress scope |
| SI-01 | Session isolation |
| CS-02 | Cross-interface policy consistency |
| EV-01 | Independently reviewable observation |
| CM-01 | Cross-module authority composition |
Each observation records the profile and case versions, target-configuration digest, declared and observed authority, action, expected and actual outcomes, timestamps, evidence digest and producer, control outcomes, redactions, reviewer, limitations, and untested dimensions.
How to use it
Run only against an authorized, isolated target.
- Declare the boundary. Name the permitted repositories, storage, credentials, egress, interfaces, and observation window.
- Use disposable identities and synthetic data. Do not introduce production credentials, customer data, or unrestricted egress.
- Exercise positive and negative controls. Demonstrate an authorized path and a deliberately out-of-policy synthetic path before interpreting a denial.
- Publish a bounded observation. Record what the named configuration demonstrated, the evidence supporting it, and what remains untested.
Evidence and limitations
An experimental profile with a self-contained synthetic example.
- The public release contains a machine-readable profile, a self-contained observation schema, a synthetic characterization example, coverage matrix, changelog, and dependency-free validator.
- The current corrective release is pinned by Git tag
v0.1.1and Hugging Face dataset revisiond6046c561ba25ef29e1b7c410fb88531a4d061f4. - Its synthetic example demonstrates profile structure and evidence requirements. It is not an audit of a named provider or a production environment.
- Consumers should pin profile and schema versions. Future minor releases may add optional fields; breaking semantic changes require a new major version.
Source record
Use the versioned dataset for implementation.
Dataset and source
Hugging Face dataset: msaleme/mcp-sandbox-authority-boundary-profile
Open the pinned v0.1.1 release
Cite this PubPoint archive record
Saleme, Michael K. (2026). MCP Sandbox Authority Boundary Profile [PubPoint archive record]. PubPoint. https://pubpoint.com/publications/mcp-sandbox-authority-boundary-profile/
Cite the versioned profile artifact
Saleme, Michael K. (2026). MCP Sandbox Authority Boundary Profile: v0.1.0 Experimental Characterization Profile [Dataset], corrective release v0.1.1, revision d6046c561ba25ef29e1b7c410fb88531a4d061f4. Hugging Face.
Dataset released July 23, 2026. Corrective release v0.1.1 published August 1, 2026. This PubPoint archive record was published August 1, 2026. Material revisions are recorded here.
Related research