agents-mcp-gateway

agents-mcp-gateway

Secure localhost MCP gateway that exposes project-scoped file/Git/search tools and controlled CLI agent adapters (Codex, Claude) with fixed argv for safe Windows-native agent work.

Category
Visit Server

README

agents-mcp-gateway

Secure localhost MCP gateway for Windows-native local agent work.

Only one MCP server is exposed externally: agents-mcp-gateway at http://127.0.0.1:3333/mcp. Codex and Claude are no longer used as child MCP servers. Agent work runs through ordinary non-interactive CLI subprocesses with fixed argv from local config.

Architecture

ChatGPT
  -> OpenAI Secure MCP Tunnel
  -> http://127.0.0.1:3333/mcp
      -> native bounded file/Git/search/check tools
      -> codex CLI subprocess adapter
      -> claude CLI subprocess adapter

Configuration

config/projects.yaml has two registries:

projects:
  agents-mcp-gateway:
    description: Gateway source tree
    path: D:\Projects\agents-mcp-gateway

agents:
  codex-readonly:
    description: Codex CLI non-interactive read-only agent
    adapter: codex
    args: ["exec", "--json", "-s", "read-only", "-c", "approval_policy='never'"]

  claude-readonly:
    description: Claude Code non-interactive JSON agent
    adapter: claude
    args: ["-p", "--output-format", "json", "--permission-mode", "dontAsk"]

Remote MCP callers cannot pass command, args, env, model, cwd, or arbitrary filesystem paths for an agent. They can only choose a configured agent, provide a configured project_id, and send a prompt.

Public Agent Tools

  • list_projects()
  • list_agents()
  • create_task(project_id, agent, prompt) -> task_id, thread_id
  • resume_thread(thread_id, prompt) -> task_id
  • get_task(task_id)
  • await_task(task_id, timeout_ms?) — wait up to 60 seconds for a terminal task state, defaulting to 30 seconds; if the timeout elapses, returns the latest task with wait_timed_out: true
  • cancel_task(task_id)
  • list_tasks(status?, limit?)
  • get_thread(thread_id)
  • list_threads(status?, limit?)
  • close_thread(thread_id)

A task is one CLI subprocess execution. A thread stores the gateway thread ID, provider session ID, adapter, agent, and canonical cwd so later tasks can resume the provider conversation without accepting project_id or agent again.

Native Tools

Native file/Git/search tools remain project-scoped:

  • list_files(project_id, relative_path, depth)
  • read_file(project_id, relative_path, start_line, end_line)
  • search_code(project_id, query, glob, max_results)
  • git_status(project_id)
  • git_diff(project_id, base, max_chars)
  • git_log(project_id, limit)
  • run_check(project_id, check_id)

run_check does not accept arbitrary commands. It only runs detected package scripts named test, lint, typecheck/check, or build.

CLI Probe Findings

Codex 0.146.0-alpha.3.1:

  • new session: codex exec --json -C <cwd> ... <prompt>
  • JSONL event thread.started.thread_id is the provider session ID
  • resume: codex exec resume --json <thread_id> <prompt>
  • resume command must run with process cwd set to the original cwd; resume has no -C
  • fixture probe confirmed new session, remembered context, and cwd continuity

Claude Code 2.1.220:

  • new session: claude -p --output-format json ... with prompt on stdin
  • JSON result has session_id
  • resume help exposes --resume <session_id>
  • current provider probe returned a quota 429, so command shape and session_id parsing are implemented, while semantic resume could not be completed in this run

Run

cd D:\Projects\agents-mcp-gateway
pnpm install
pnpm build
pnpm start

Doctor:

pnpm doctor

Tests:

pnpm test

Automatic Start

powershell -ExecutionPolicy Bypass -File scripts\install-task-scheduler.ps1

Remove:

powershell -ExecutionPolicy Bypass -File scripts\uninstall-task-scheduler.ps1

Security Notes

  • Server binds only to 127.0.0.1.
  • No router port forwarding, 0.0.0.0, or public tunnel URL is used.
  • External access should go through OpenAI Secure MCP Tunnel only.
  • Agent argv is fixed in local config.
  • Environment is allowlisted.
  • Sensitive files, credential folders, .git, node_modules, browser session stores, symlink/junction escapes, UNC paths, URL paths, and project traversal are blocked.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured