agent-env-mcp

agent-env-mcp

Provides a restricted Docker-based sandbox for LLM agents, enabling file operations, command execution, and local Git within an isolated runtime.

Category
Visit Server

README

@brycepelletier/agent-env-mcp

Reusable, host-side MCP controller for a hardened Linux software-engineering runtime.

0.3.1 trust split

The Compose runtime has two execution domains over the same working tree:

  • agent: used by Software Engineer tools. The real .git directory is masked with a root-owned tmpfs mount.
  • git: used only by git_command. It sees the real .git directory and has network_mode: none.

Remote Git/GitHub operations do not belong in this package; they are intended for the separate GitHub MCP trust domain.

Tools

  • ensure_environment
  • list_directory
  • read_file
  • search_workspace
  • workspace_edit
  • run_command
  • git_command

The MCP discovers the active VS Code workspace lazily through MCP Roots when a tool is first used. No ${workspaceFolder} launch-time variable is required.

Local development

npm run link

User-level VS Code MCP configuration while linked:

"agent-env": {
  "type": "stdio",
  "command": "agent-env-mcp"
}

To remove the global development link:

npm run unlink

0.3.1 acceptance checks

Before removing a project's old .devcontainer:

  1. ensure_environment succeeds and reports /agent-env/environment/<project>.
  2. run_command can build the project.
  3. run_command cannot obtain the real Git branch/history even if it invokes Git indirectly through Python/Node.
  4. git_command ["status", "--short", "--branch"] succeeds.
  5. The Git service has no network access.

The current .git masking implementation assumes a standard checkout where .git is a directory. Git worktrees/submodules that use a .git file should be rejected or handled by a future mount strategy before treating this runtime as hardened for those repository forms.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured
E2B

E2B

Using MCP to run code via e2b.

Official
Featured