Read-only MCP server that surfaces external file sharing risks from Box enterprise event logs, enabling early-warning leakage detection without modifying any data.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.BOX_CLIENT_ID— ✓ App Client IDBOX_CLIENT_SECRET— ✓ App Client SecretBOX_OAUTH_REDIRECT_URI— oauth redirect. Default http://localhost:8787/callbackBOX_TOKEN_CACHE— oauth token cache path. Default ~/.config/boxadm-mcp/token.jsonBOX_ALLOWED_DOMAINS— ✓ Internal email domains (comma-separated). No default — every address counts as external until you set thisBOX_AUTH_MODE— Two modes, selected via :BOX_API_BASE— Default https://api.box.comBOX_ENTERPRISE_ID— ccg mode Enterprise ID (CCG subject; not needed for oauth)[](https://m8ven.ai/mcp/shigechika-boxadm-mcp-6dchb1)