Repository navigation
Mvp - #4
Merged
Merged
Mvp#4
Conversation
- Updated the main heading to focus on agent decision-making and execution. - Revised supporting text to clearly outline the security and operational aspects of agent actions. - Adjusted animation delays for a more cohesive visual experience.
- Increased tmpfs size for /root/.npm to 256m in both executeMcpToolCall and probeMcpServer functions, enhancing npm cache performance. - Removed tmpfs settings for /home/node/.npm to streamline container resource allocation. - Updated Dockerfile comments to clarify container security measures and user context.
…ssions The npx runtime installs inside read-only Docker containers fail with "Permission denied" because npx-created bin files lack the execute bit on tmpfs. This fix: - executor.js now resolves server commands in 3 steps: 1. Check if binary exists globally in PATH (pre-installed) 2. npm-install to /tmp and run entry point via `node` (no x-bit needed) 3. Fall back to chmod + direct .bin/ execution - Dockerfile: remove silent error suppression (2>/dev/null || true) from global npm install so build failures are visible in CI - Dockerfile: add verification step for global binary availability - Diagnostic logging (uid, resolved command) aids debugging Co-authored-by: Cursor <cursoragent@cursor.com>
Removed all hardcoded MCP server packages from the Dockerfile. The executor now handles ANY npm-based MCP server at runtime: 1. npm install --prefix /tmp/mcp-pkg <package> 2. Read package.json bin field to find entry point 3. Run via node (no execute-bit needed on tmpfs) Locally verified end-to-end: server-github (26 tools) and server-filesystem (14 tools) both start, connect, list tools, and close cleanly using this approach. Co-authored-by: Cursor <cursoragent@cursor.com>
- Removed global pre-installation of MCP server binaries from Dockerfile to simplify the build process and avoid CI errors. - Updated executor.js to directly install packages to /tmp and resolve entry points without relying on global binaries, enhancing compatibility with read-only environments. - Improved logging for better visibility during package installation and command resolution. This change enhances the flexibility of the MCP executor by eliminating the need for pre-installed binaries and ensuring smoother execution in constrained environments.
MCP security was L1 (policy) + L3 (execution) with no L2. This adds the missing layer: L2 Pre-Execution (BLOCKS before credentials leave vault): - AI analyzes: server command + tool name + credential env vars - Catches: malicious packages stealing creds, credential-server mismatch, suspicious tool names - Rule-based fallback when AI unavailable (official MCP packages, credential type matching) - Fail-closed: errors block execution L2 Post-Execution (flags after L3): - AI verifies result matches expected tool behaviour - Catches: exfiltration in output, anomalous payloads - Creates audit flags on mismatch Execution recording: - MCP L3 results now create Execution records - Activity page shows "executed" status with exit code, duration Admin dashboard (/admin): - Password-protected (ADMIN_PASSWORD env var, default: admin1) - Shows L3 executions, L2 verifications, audit flags - Real-time refresh (5s polling) Full MCP flow: L1 → L2 pre-exec → L3 → L2 post-exec → result Co-authored-by: Cursor <cursoragent@cursor.com>
- Fix toolCall lookup for execution recording: search by contains (proxy stores prefixed name, structured-execute sends bare name) - Post-exec L2 verification now skippable with MCP_POST_VERIFY=false to halve AI cost per MCP tool call (pre-exec L2 still always runs) Co-authored-by: Cursor <cursoragent@cursor.com>
- Expanded the 'secure_exec.completed' event to include additional data: serverCommand, image, exitCode, credentialEnvVars, and containerSecurity details. - Updated the admin dashboard to reflect these changes, providing deeper insights into L3 executions and security events. - Removed the post-execution verification from the event structure, streamlining the data flow for better performance and clarity. Co-authored-by: Cursor <cursoragent@cursor.com>
- Added logic to classify risk based on MCP tool names, distinguishing between read-only, destructive, and write operations. - Implemented regex patterns to identify tool behavior, improving risk assessment accuracy for tools prefixed with "mcp:". This change enhances the security framework by providing more granular risk classifications for MCP tools.
- Integrated organization policy settings to determine visibility of webhook events based on platform mode. - Updated the event filtering logic to ensure only relevant events are displayed for users in different platform modes. - Adjusted the webhook creation mutation to respect the filtered event list. This change improves user experience by tailoring notifications to the specific organizational context.
- Added .cursor/mcp.json to .gitignore to prevent sensitive configuration files from being tracked. - Improved message handling in mcp-proxy.ts to rewrite endpoint paths for client POST requests, ensuring correct routing and preventing 404 errors. These changes enhance security and improve the functionality of the MCP proxy tool.
- Added a new POST route for `/mcp/:instanceId/sse` that responds with a 405 error, instructing users to use GET for SSE connections. - Improved message handling in the MCP proxy to rewrite endpoint paths for messages, ensuring correct routing and preventing 404 errors. - Updated tests to reflect changes in message endpoint handling. These enhancements improve the functionality and user experience of the MCP proxy tool.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.