Skip to content

Mvp - #4

Merged
RealWooblay merged 12 commits into
devfrom
mvp
Feb 23, 2026
Merged

Mvp#4
RealWooblay merged 12 commits into
devfrom
mvp

Conversation

@RealWooblay

Copy link
Copy Markdown
Owner

No description provided.

RealWooblay and others added 12 commits February 21, 2026 16:00
- Updated the main heading to focus on agent decision-making and execution.
- Revised supporting text to clearly outline the security and operational aspects of agent actions.
- Adjusted animation delays for a more cohesive visual experience.
- Increased tmpfs size for /root/.npm to 256m in both executeMcpToolCall and probeMcpServer functions, enhancing npm cache performance.
- Removed tmpfs settings for /home/node/.npm to streamline container resource allocation.
- Updated Dockerfile comments to clarify container security measures and user context.
…ssions

The npx runtime installs inside read-only Docker containers fail with
"Permission denied" because npx-created bin files lack the execute bit
on tmpfs. This fix:

- executor.js now resolves server commands in 3 steps:
  1. Check if binary exists globally in PATH (pre-installed)
  2. npm-install to /tmp and run entry point via `node` (no x-bit needed)
  3. Fall back to chmod + direct .bin/ execution
- Dockerfile: remove silent error suppression (2>/dev/null || true) from
  global npm install so build failures are visible in CI
- Dockerfile: add verification step for global binary availability
- Diagnostic logging (uid, resolved command) aids debugging

Co-authored-by: Cursor <cursoragent@cursor.com>
Removed all hardcoded MCP server packages from the Dockerfile.
The executor now handles ANY npm-based MCP server at runtime:
  1. npm install --prefix /tmp/mcp-pkg <package>
  2. Read package.json bin field to find entry point
  3. Run via node (no execute-bit needed on tmpfs)

Locally verified end-to-end: server-github (26 tools) and
server-filesystem (14 tools) both start, connect, list tools,
and close cleanly using this approach.

Co-authored-by: Cursor <cursoragent@cursor.com>
- Removed global pre-installation of MCP server binaries from Dockerfile to simplify the build process and avoid CI errors.
- Updated executor.js to directly install packages to /tmp and resolve entry points without relying on global binaries, enhancing compatibility with read-only environments.
- Improved logging for better visibility during package installation and command resolution.

This change enhances the flexibility of the MCP executor by eliminating the need for pre-installed binaries and ensuring smoother execution in constrained environments.
MCP security was L1 (policy) + L3 (execution) with no L2.
This adds the missing layer:

L2 Pre-Execution (BLOCKS before credentials leave vault):
- AI analyzes: server command + tool name + credential env vars
- Catches: malicious packages stealing creds, credential-server
  mismatch, suspicious tool names
- Rule-based fallback when AI unavailable (official MCP packages,
  credential type matching)
- Fail-closed: errors block execution

L2 Post-Execution (flags after L3):
- AI verifies result matches expected tool behaviour
- Catches: exfiltration in output, anomalous payloads
- Creates audit flags on mismatch

Execution recording:
- MCP L3 results now create Execution records
- Activity page shows "executed" status with exit code, duration

Admin dashboard (/admin):
- Password-protected (ADMIN_PASSWORD env var, default: admin1)
- Shows L3 executions, L2 verifications, audit flags
- Real-time refresh (5s polling)

Full MCP flow: L1 → L2 pre-exec → L3 → L2 post-exec → result

Co-authored-by: Cursor <cursoragent@cursor.com>
- Fix toolCall lookup for execution recording: search by contains
  (proxy stores prefixed name, structured-execute sends bare name)
- Post-exec L2 verification now skippable with MCP_POST_VERIFY=false
  to halve AI cost per MCP tool call (pre-exec L2 still always runs)

Co-authored-by: Cursor <cursoragent@cursor.com>
- Expanded the 'secure_exec.completed' event to include additional data: serverCommand, image, exitCode, credentialEnvVars, and containerSecurity details.
- Updated the admin dashboard to reflect these changes, providing deeper insights into L3 executions and security events.
- Removed the post-execution verification from the event structure, streamlining the data flow for better performance and clarity.

Co-authored-by: Cursor <cursoragent@cursor.com>
- Added logic to classify risk based on MCP tool names, distinguishing between read-only, destructive, and write operations.
- Implemented regex patterns to identify tool behavior, improving risk assessment accuracy for tools prefixed with "mcp:".

This change enhances the security framework by providing more granular risk classifications for MCP tools.
- Integrated organization policy settings to determine visibility of webhook events based on platform mode.
- Updated the event filtering logic to ensure only relevant events are displayed for users in different platform modes.
- Adjusted the webhook creation mutation to respect the filtered event list.

This change improves user experience by tailoring notifications to the specific organizational context.
- Added .cursor/mcp.json to .gitignore to prevent sensitive configuration files from being tracked.
- Improved message handling in mcp-proxy.ts to rewrite endpoint paths for client POST requests, ensuring correct routing and preventing 404 errors.

These changes enhance security and improve the functionality of the MCP proxy tool.
- Added a new POST route for `/mcp/:instanceId/sse` that responds with a 405 error, instructing users to use GET for SSE connections.
- Improved message handling in the MCP proxy to rewrite endpoint paths for messages, ensuring correct routing and preventing 404 errors.
- Updated tests to reflect changes in message endpoint handling.

These enhancements improve the functionality and user experience of the MCP proxy tool.
@RealWooblay RealWooblay self-assigned this Feb 23, 2026
@RealWooblay
RealWooblay merged commit 8baafab into dev Feb 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant