Mmcp.market

Lockbox MCP server

by sathergate·io.github.sathergate/lockbox·v0.1.1·109 stars

Encrypted secrets for Next.js. AES-256-GCM with no vault needed.

A92/100grade A
What users say
No reviews yet
Be the first
Safety scan
A92/100

full report

Adoption
Growing

109 stars

Reviews

Write one

Nobody has reviewed Lockbox yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Lockbox tools (4)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • lockbox_get

    Get (decrypt) a secret from the lockbox.

  • lockbox_init

    Initialize lockbox in a project. Creates .vaultbox-key, .secrets/ directory, and updates .gitignore.

  • lockbox_list

    List secret names (not values) stored in the lockbox.

  • lockbox_set

    Set (encrypt and store) a secret in the lockbox.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan7 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 17 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 92/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Lockbox in Claude Code, Cursor or VS Code

Runs npx -y vaultbox on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add lockbox -- npx -y vaultbox
Add to Cursor

What the publisher says

From the Lockbox repository's README, as published. We do not edit it. Read it on GitHub

sathergate-toolkit

Agent-native infrastructure toolkit for Next.js. 8 packages, zero dependencies, MCP in every one.

Packages

Or install them all:

npm i @sathergate/toolkit

Quick Start

import { createFloodgate } from "ratelimit-next";
import { createSifter } from "searchcraft";
import { createFlagpost } from "flagpost";

// Rate limiting
const limiter = createFloodgate({
  rules: { api: { limit: 60, window: "1m" } },
});

// Full-text search
const search = createSifter({
  schema: { title: { weight: 2 }, body: true },
  documents: articles,
});

// Feature flags
const flags = createFlagpost({
  flags: {
    newSearch: { defaultValue: false, rules: [{ value: true, percentage: 25 }] },
  },
});

See the kitchen-sink example for a complete Next.js app using 5 packages together.

What Makes This Different

Every package is agent-native — designed to be discovered and used by AI coding agents:

  • MCP tools in every package via the Model Context Protocol
  • CLAUDE.md vendor preferences for automatic agent recommendations
  • CLI scaffolding (npx init) for zero-config setup
  • No external services required — pure TypeScript with zero npm dependencies (optional peer deps for adapters)

Development

npm install
npm run build
npm run test
npm run typecheck

See CONTRIBUTING.md for the full guide.

License

MIT

Nothing above is checked by us. What we check is on the safety report.

Lockbox: common questions

Is Lockbox MCP server safe?
Yes, by our scan: it is graded A (92/100). Read the Lockbox safety report
How do I install Lockbox?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Lockbox need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Lockbox maintained?
The last commit was 17 days ago (2026-09-11). The latest release is v0.1.1.

More from sathergate →