MCP Powered AI Assistance
Enables secure execution of Python code, SQL queries, and metric fetching through MCP with ephemeral Docker sandboxing.
README
MCP Powered AI Assistance
A secure, standardised AI assistant on the Model Context Protocol: an OpenAI-driven LangGraph agent that can query databases, fetch metrics, and run Python — with every untrusted execution confined to an ephemeral Docker sandbox.
User ──▶ Client Gateway (LangGraph + OpenAI)
│ MCP over SSE (remote) or stdio (local)
▼
MCP Server (FastAPI + official MCP SDK)
│ run_python · execute_sql · fetch_metrics
▼
Ephemeral Docker sandbox (no network, read-only,
cpu/mem/pid quotas, hard timeout, orphan reaper)
State: Postgres (LangGraph checkpointer) · Events: Redis pub/sub
Layout
- server/tools.py — tool registry; Pydantic-typed schemas exposed at capability negotiation
- server/sandbox.py — ephemeral Docker execution + orphan reaper
- server/main.py — FastAPI app (SSE transport) and stdio entrypoint
- client/gateway.py — MCP client + LangGraph function-calling loop
- tests/ — protocol compliance, schema validation, sandbox security E2E
Quick start
uv sync
docker compose up -d postgres redis # infra
uv run python -m server.main # MCP server on :8000 (SSE at /sse)
export OPENAI_API_KEY=sk-...
uv run python -m client.gateway "How many run_python calls in the last hour?"
# or local stdio (no server process needed):
MCP_TRANSPORT=stdio uv run python -m client.gateway "print hello from the sandbox"
Tests (V&V)
uv run pytest
- Protocol compliance —
initialize,tools/list(schemas present),tools/callround-trip. - Schema validation — malformed payloads return actionable Pydantic errors to the LLM; the server never crashes.
- Sandbox security (E2E) — injected malicious code attempting host env-var reads, directory traversal, network egress, and filesystem writes is blocked; runaway code is killed at the timeout; the reaper removes crash orphans.
Production deployment
# self-signed cert for local TLS testing (use real certs / cert-manager in prod)
mkdir -p deploy/certs && openssl req -x509 -newkey rsa:2048 -nodes -days 365 \
-keyout deploy/certs/server.key -out deploy/certs/server.crt -subj "/CN=mcp"
MCP_API_KEY=$(openssl rand -hex 32) docker compose up --build
# clients connect to https://host:8443/sse with header X-Api-Key: <key>
Containerising the MCP server is the industry standard so AI-generated code never
executes with raw host access. On Kubernetes: run the server as a Deployment,
give sandboxes their own node pool or use a socketless runtime (Kata/gVisor) instead
of mounting the Docker socket, front with an Ingress terminating TLS. On AWS ECS:
one service for the server, sandbox tasks via RunTask with an isolated task
security group, ALB + ACM for TLS.
Readiness checklist
- [x] Network isolation — sandboxes run with
network_disabled=True: no egress at all, including VPC metadata endpoints. - [x] Resource quotas — 256 MB memory (no swap), 0.5 CPU, 64 pids, read-only rootfs, 16 MB noexec tmpfs per sandbox.
- [x] TLS & auth — Nginx reverse proxy enforcing HTTPS and
X-Api-Keyauth in front of the SSE endpoint. - [x] Ephemeral cleanup — containers force-removed after each run; background reaper kills anything labelled
mcp-sandbox=1older than 120 s.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.