Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Box Admin Analytics MCP

PYPI · BOXADM-MCP · SCANNED SEP 20

MCP server for Box admin-log analytics — external-sharing visibility, read-only

Available components

−3 this week 73 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
  • 0 of 29 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency32
Schema Quality & AI Usability58
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4123 tokens (~458/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
  • Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage67
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 0% of tool parameters carry a description.Fail
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 9 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Box Admin Analytics MCP server?

Box Admin Analytics MCP runs locally as a PyPI package, launched with uvx boxadm-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · boxadm-mcp

# add to Claude Code
claude mcp add shigechika-boxadm-mcp -- uvx boxadm-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "shigechika-boxadm-mcp": {
      "command": "uvx",
      "args": [
        "boxadm-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "shigechika-boxadm-mcp": {
      "command": "uvx",
      "args": [
        "boxadm-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add shigechika-boxadm-mcp -- uvx boxadm-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "shigechika-boxadm-mcp": {
      "type": "local",
      "command": [
        "uvx",
        "boxadm-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add shigechika-boxadm-mcp --command uvx --arg boxadm-mcp
# ~/.hermes/config.yaml
mcp_servers:
  shigechika-boxadm-mcp:
    command: "uvx"
    args: ["boxadm-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "shigechika-boxadm-mcp": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "boxadm-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add shigechika-boxadm-mcp -t stdio -c uvx -a boxadm-mcp
// mcp.json
{
  "mcpServers": {
    "shigechika-boxadm-mcp": {
      "command": "uvx",
      "args": [
        "boxadm-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 19 Sept 26 0
    • Stability: 0.97 → pass security
    • Security disclosure: unverified → fail functional
  • 18 Sept 26 +1
    • Security disclosure: fail → unverified functional
  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Sept 26 −2
    • Stability: pass → 0.87 functional
  • 13 Sept 26 0
    • Stability: 0.97 → pass security
  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 −1
    • Stability: pass → 0.93 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed pypi/boxadm-mcp@0.9.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem pypi

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted setuptools.build_meta

Background: Why install scripts are a supply-chain risk →

Dependencies 29 packages
Packages resolved 29
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 9 exposed · ~4,123 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
daily_brief ~225

Morning DLP brief: external access (events) + external-sharing state (enumeration). One call that combines: - **access** (enterprise-wide, events): external DOWNLOAD/PREVIEW in the last ``since_hours``, with top external accessors and top externally-accessed files. - **exposure** (co-admin visible folders, enumeration): current external collaborations, open ("anyone with the link") shared links, and the owners most externally exposed. Reuses the cached folder scan, so calling this alongside the other enumeration tools doesn't re-walk. Args mirror the underlying tools; ``top`` defaults to 5 for a compact summary. Coverage/caps caveats are the same (``capped`` flags + enumeration limited to the co-admin's visible content). On failure returns ``{"error": ...}``.

NameTypeReqDescription
max_depthinteger
max_eventsinteger
max_foldersinteger
since_hoursinteger
topinteger

No output schema declared.

No examples provided.

external_access_events ~593

Surface external file access (DOWNLOAD / PREVIEW) from enterprise admin_logs. Enterprise-wide (events stream): over the window, flags each access whose actor (``created_by.login``) is outside the org domain allowlist — an external party, or an anonymous open-link visitor (no login) — and whether it came via a shared link. Aggregates to the top externally-accessed files and the top external accessors, so an admin can spot unusual outbound data pulls. Args: since_hours: Look-back window in hours (default 24). max_events: Cap on DOWNLOAD/PREVIEW events scanned (default 5000); the result's ``capped`` flag is true when more existed (never silently truncated). top: How many top files / accessors to return (default 20). created_by_logins: Comma-separated accessor logins to trace (empty = all). When set, switches to DLP-tracing mode (see below). Returns ``window_hours``, ``events_scanned``, ``capped``, ``external_access_count``, ``via_shared_link``, ``top_external_accessors`` (login + count + bytes), and ``top_externally_accessed_files`` (item id/name/ owner + external-access count). On failure returns ``{"error": ...}`` (incl. ``needs-login`` for an expired OAuth session). Notes: - ``via_shared_link`` counts ALL scanned accesses that went through a shared link (internal and external), not just external ones. - Events are scanned oldest-first from the window start. When ``capped`` is true the aggregates reflect only the scanned (earliest) slice, NOT the full window — raise ``max_events`` for a complete picture. - **DLP tracing** (``created_by_logins`` set): scans up to the wider of ``max_events`` and 50000 events (the accessor may sit anywhere in the window) but keeps only that accessor's events, so the answer to "which files did this account pull" is exact and bounded. The result reports ``events_matched`` (not ``events_scanned`` — this mode doesn't track the scanned total; judge coverage by ``capped``), ``filter…

NameTypeReqDescription
created_by_loginsstring
max_eventsinteger
since_hoursinteger
topinteger

No output schema declared.

No examples provided.

external_collaborators ~451

List external collaborators on Box folders (current state, enumeration). Walks folders the authenticating co-admin user can see (default from the root "All Files") and reports collaborations whose collaborator is outside the org domain allowlist — accepted external users or pending external invites. Useful to review who outside the organization has standing access. Args: root_folder_id: Folder to start from ("0" = the user's root). A Box folder id: decimal digits only, as shown at the end of a Box folder URL. Anything else is refused with ``{"error": ...}`` before any request is made, rather than being reported as an empty result. max_folders: Cap on folders visited (default 150); ``capped`` discloses when coverage was cut short. max_depth: Folder recursion depth (default 1 = top-level folders only). Externally-owned folders (this org is only a guest, not the owner) are out of scope and skipped — we cannot govern their collaborations, and their "external collaborators" are just the owner's own org accounts. They are reported separately under ``skipped_externally_owned`` (never silently dropped) and do not consume the ``max_folders`` budget. Coverage note: limited to content the co-admin user can access (not provably 100% of the enterprise) and to the depth/folders caps. Returns ``folders_scanned``, ``capped``, ``fetch_errors`` (count of folders whose lookup hit an API error that outlasted the client's retries, e.g. a persistent 403 or a sustained throttle — coverage is complete only when ``capped`` is false AND ``fetch_errors`` is 0), ``count``, ``external_collaborators`` (folder, owner, collaborator, role, status, expires_at), and ``skipped_externally_owned`` (folder_id, folder_name, owner). On failure returns ``{"error": ...}``.

NameTypeReqDescription
max_depthinteger
max_foldersinteger
root_folder_idstring

No output schema declared.

No examples provided.

get_user ~1,059

Look up ONE Box account by its exact login (the account's email address). Answers "what is this account's state?" — the question behind a ticket that says "my Box account is disabled". Every other tool here reads the event stream or walks folders, so an account with no recent events is invisible to them; this is one request against the user directory and the only tool that answers about an account directly. Use it when a specific account is named. It cannot list, search or enumerate accounts: it takes one login and answers about that login only. Args: login: The account's full Box login, i.e. its email address (``someone@example.com``) — not a display name, not a user id. Matched EXACTLY, case-insensitively. A partial login does not match. This server is downstream of an identity provider, not the master. Read what comes back as "what Box currently believes", and compare it against the IdP's own record (which is authoritative for who the account is). A disagreement is the finding, and is usually drift on the Box side rather than a mistyped address: - ``enterprise`` absent/null — the account is no longer in the enterprise (it has become a free personal account), so enterprise SSO no longer applies to it even though the IdP still authenticates the person. Box classes such an account as *external* and returns it only on a COMPLETE login match, which is exactly what this tool asks for — so it is reachable here, and a partial login would silently lose it. - ``status`` other than ``active`` — the IdP authenticates, Box refuses. - ``is_platform_access_only`` true — an App User, which cannot sign in interactively at all. One drift this tool cannot find for you: the same person under a second login at another domain (an alias, or a duplicate left by a migration). ``filter_term`` prefix-matches the WHOLE term, so a search for ``alice@old.example`` can never return ``alice@new.example``. Finding that would take a search on the local part a…

NameTypeReqDescription
loginstringyes

No output schema declared.

No examples provided.

health_check ~223

Report server version, Box connectivity/auth, and configuration. Call this at session start (or after a tool-call timeout) to confirm the MCP is up, see which version is running, verify the Box enterprise token can be obtained (CCG) and that the ``admin_logs`` event scope is actually granted, and view the org domain allowlist used for external detection. Lightweight: one token request plus a single-row events probe — it does not scan history. Always returns the same keys: ``status`` (healthy / degraded / error), ``service``, ``version``, ``auth_mode`` (ccg / oauth — the mode in effect, so an unrecognised ``BOX_AUTH_MODE`` reads as ``ccg``, which is what the server falls back to), ``box_api_base``, ``enterprise_id``, ``auth`` (ok / error / missing-env / needs-login), ``events_accessible`` (bool), and ``allowed_domains``. On a degraded or error result, ``detail`` carries the reason.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_folder_items ~777

List ONE Box folder's contents, newest first, with who uploaded each item. An ``ls``, not a ``cat``: names, timestamps, sizes, uploader and a direct link per item. File CONTENT is not read and no shared link is ever created. Written for a help desk answering a submitted enquiry whose attachments land in a Box folder. Instead of a human going to find that folder, the answer can name the attachments and link straight to them. Args: folder_id: The folder's Box id — decimal digits, the number at the end of a Box folder URL. ``"0"`` is the caller's own root ("All Files"), the same convention the enumeration tools use. Anything else — a name, a label, a whole URL — is refused before any request is made. uploaded_by: Optional. Return only items uploaded by this person, matched EXACTLY and case-insensitively against ``uploaded_by`` below. Use it when the enquiry names its submitter. since: Optional lower bound on upload time (``created_at``), inclusive. until: Optional upper bound on upload time (``created_at``), inclusive. Both MUST carry a UTC offset (``2026-08-14T00:00:00+09:00``): a bare date names a different instant in every timezone, and this server has no basis for choosing one. Compared as instants, not as text. limit: How many rows to RETURN after filtering (default 100). It does not bound what is searched — a full page is always fetched first, so a match for ``uploaded_by`` is found even when it is not among the newest items. On ``uploaded_by``: Box populates ``uploader_display_name`` for an upload made through a File Request, where no Box user is involved — ``created_by`` and ``modified_by`` both read "Anonymous User" and the owner is the application's service account, so neither identifies anybody. For a file uploaded by a signed-in user the reverse holds, so ``created_by`` is used as the fallback. Despite its name the value observed here was an emai…

NameTypeReqDescription
folder_idstringyes
limitinteger
sincestring
untilstring
uploaded_bystring

No output schema declared.

No examples provided.

public_shared_links ~316

List items with an open ("anyone with the link") shared link (enumeration). Walks folders the authenticating co-admin user can see and reports files and folders whose shared link access is ``open`` — reachable by anyone with the URL, the highest-exposure sharing mode. Args: root_folder_id: Folder to start from ("0" = the user's root). A Box folder id: decimal digits only, as shown at the end of a Box folder URL. Anything else is refused with ``{"error": ...}`` before any request is made, rather than being reported as an empty result. max_folders: Cap on folders visited (default 150); ``capped`` discloses truncation. max_depth: Folder recursion depth (default 1 = top-level only; raise to reach file links inside folders). Coverage note: limited to content the co-admin user can access and to the caps. Returns ``folders_scanned``, ``capped``, ``fetch_errors`` (count of folders whose lookup hit an API error; coverage is complete only when ``capped`` is false AND ``fetch_errors`` is 0), ``count``, and ``public_shared_links`` (item type/id/name, owner, access, can_download). On failure returns ``{"error": ...}``.

NameTypeReqDescription
max_depthinteger
max_foldersinteger
root_folder_idstring

No output schema declared.

No examples provided.

recent_admin_events ~238

Fetch recent enterprise ``admin_logs`` events (raw passthrough). Diagnostic/starter tool: returns Box events verbatim so the real event types and field shapes can be confirmed before analytics tools are layered on. For external-sharing work the event types of interest are typically COLLABORATION_INVITE / COLLAB_ADD_COLLABORATOR, SHARED_LINK_CREATED / ITEM_SHARED_CREATE, and DOWNLOAD / PREVIEW. Args: event_types: Comma-separated Box event_type filter (empty = all types). since_hours: Look-back window in hours (default 24). limit: Max events to return in this page (default 100). stream_position: Continue a previous page by passing back the ``next_stream_position`` from the prior call (empty = first page). Box caps a single page at 500, so manual paging is needed to walk a busy window — or use ``external_access_events`` which pages for you.

NameTypeReqDescription
event_typesstring
limitinteger
since_hoursinteger
stream_positionstring

No output schema declared.

No examples provided.

top_external_sharers ~241

Rank internal owners by their external exposure (enumeration). One traversal (same as external_collaborators / public_shared_links), then ranks internal file/folder owners by how much external exposure they hold: external collaborations + open shared links on content they own. Surfaces the people whose content is most exposed outside the organization. Args: root_folder_id / max_folders / max_depth: traversal bounds (see external_collaborators). top: How many owners to return (default 20). Coverage note: limited to the co-admin user's visible content and the caps. Returns ``folders_scanned``, ``capped``, ``fetch_errors`` (count of folders whose lookup hit an API error; coverage is complete only when ``capped`` is false AND ``fetch_errors`` is 0), and ``top_external_sharers`` (owner, external_collaborations, public_links, total). On failure ``{"error": ...}``.

NameTypeReqDescription
max_depthinteger
max_foldersinteger
root_folder_idstring
topinteger

No output schema declared.

No examples provided.

Common questions

What is the Box Admin Analytics MCP server?

Box Admin Analytics MCP is listed in the public MCP registry as io.github.shigechika/boxadm-mcp. MCP server for Box admin-log analytics, external-sharing visibility, read-only. This page covers its PyPI package (boxadm-mcp).

Is the Box Admin Analytics MCP server safe to use?

Box Admin Analytics MCP scores 73 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Box Admin Analytics MCP server expose?

Box Admin Analytics MCP exposes 9 tools: health_check, recent_admin_events, external_access_events, external_collaborators, public_shared_links, and 4 more. Their descriptions and schemas cost roughly 4,123 tokens of context every time the server is loaded.

Is the Box Admin Analytics MCP server still maintained?

Box Admin Analytics MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.