Dmcps

io.github.thealidevv1.0.0Updated Oct 6, 2026

DMCPS: Highly secure, isolated MCP server environment giving AI agents sandboxed shell access.

Overview

AI-generated overview

Gives an AI assistant sandboxed file read/write, directory listing, and shell command execution inside whitelisted folders.

What it does
DMCPS runs a local Node.js/Express daemon that exposes four MCP tools: read_file, write_file, list_directory, and run_shell_command. Access is limited to directories explicitly whitelisted through a web dashboard, and shell execution is validated against a command whitelist. The dashboard also manages an API key, outbound firewall destinations, and connection monitoring.
When to use it
Use it when you want an assistant to work on code or files on your own machine, or on a deployed container, with a directory sandbox and command filtering rather than unrestricted host access. It suits local development workflows where shell commands such as package installs are expected.
Requirements
Docker or Docker Compose for the recommended local setup, or a Node.js runtime for the daemon. An ADMIN_PASSWORD environment variable for the dashboard, and the auto-generated Bearer API key passed in the Authorization header when connecting an agent. Optional NGROK_AUTHTOKEN for internet exposure. The dashboard is reached at localhost:3000.
Before you install
The server grants shell execution and file writes, so a misconfigured whitelist or command list can affect real files. It runs as root inside its container and deliberately bypasses PaaS hypervisor restrictions, and sudo is unlocked for whitelisted commands. The dashboard is protected only by ADMIN_PASSWORD, and the API key can also be passed in a URL query parameter, which may leak it into logs. Exposing the endpoint publicly, for example via NGROK_AUTHTOKEN, widens the attack surface.

Installation

In SourceWeft

  1. Open Dmcps in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

🛡️ DMCPS (Docker Model Context Protocol Secured)

[CI Tests] [License: MIT] [MCP Registry]

🔥 OFFICIALLY PUBLISHED ON THE GLOBAL MCP REGISTRY! A true revolution in AI security. DMCPS seamlessly bypasses PaaS hypervisor limitations (like Render's no-new-privileges) via application-layer interceptors while retaining a military-grade directory sandbox.

[Deploy to Render]    [Deploy on Railway]    [Deploy with Vercel]

[DMCPS - Secure Docker sandbox for AI agent filesystem & shell access | Product Hunt]

A highly secure, isolated Model Context Protocol (MCP) server environment designed to give AI agents access to a sandboxed filesystem and shell execution, without compromising the host machine.

This is built as a robust Node.js/Express backend daemon, featuring a "military-grade" secured dashboard to strictly manage which directories the AI is allowed to touch.

🛡️ Key Security Features

  • PaaS Hypervisor Bypass via Node: Runs natively as root within the container, but uses JS interceptors to filter commands, allowing package installs (apk add) seamlessly on Render without triggering no-new-privileges crashes.
  • Strict Whitelisting: The AI cannot read, write, or execute commands outside of directories explicitly whitelisted via the web dashboard. (Directory traversal attempts like ../ are mathematically blocked).
  • Hardened Dashboard:
    • Protected by a single environment password (ADMIN_PASSWORD).
    • Implements Rate Limiting to prevent brute-force login attacks.
    • Hardened with Helmet (CSP, HSTS, XSS protection, anti-sniffing).
  • Auto-Generated API Keys: Connect to your MCP server using a dynamically generated Bearer token to ensure only authorized agents can execute tools on your server.
  • Application-Layer Sudo Whitelist: sudo is unlocked to allow the AI to install packages, but execution is strictly validated against a dashboard whitelist before reaching the shell. (apk add is whitelisted by default).
  • Firewall (iptables) Whitelist: Manage specific outbound network destinations dynamically from the dashboard.
  • Pre-installed AI Toolkit: Foundational tools (git, python3, curl, bash, make, jq) are pre-baked into the image so the AI is immediately ready to work.

🚀 Getting Started Locally

1. Configure Environment

Copy the example environment file:

bash
cp .env.example .env

Open .env and set your ADMIN_PASSWORD. (Optional: Add an NGROK_AUTHTOKEN to expose the server to the internet).

2. Run with Docker Compose

The safest way to run this is via the provided docker-compose.yml:

bash
docker-compose up -d --build

This will mount your local ./projects folder into the sandbox, but the AI won't be able to touch it until you approve the path in the dashboard.

3. Configure the Sandbox & Get Your API Key

Navigate to the mobile-friendly dashboard: 👉 http://localhost:3000/ Log in with username admin and your ADMIN_PASSWORD.

From the dashboard, you can:

  1. Whitelist directories (e.g., /projects/my-app) that the AI can interact with.
  2. Whitelist root commands for controlled package management (Note: apk add is already allowed by default).
  3. Configure Firewall by opening specific outgoing destinations via iptables.
  4. Copy your API Key needed for the AI agent to securely connect.
  5. Monitor Active Connections in real-time.
  6. Copy the exact JSON Config for Cursor or Claude Desktop.

4. Connect your AI Agent

Point your MCP-compatible AI agent (like Cursor, Claude Desktop, Gemini, Spark, or custom tools) to the Server-Sent Events (SSE) endpoint securely.

Raw agents and clients can connect to standard endpoints: 👉 http://localhost:3000/sse OR http://localhost:3000/mcp

You must pass the auto-generated API Key (found in your dashboard) in the request headers:

Authorization: Bearer mcp_your_random_key_here

(You can also pass it in the URL for raw browser connections: /mcp?key=mcp_your_random_key_here)


🌍 Cloud Deployments (Backend)

This is a persistent backend service, not a static frontend. It is pre-configured for 1-click deployments on modern PaaS providers.

Render

Clicking deploy or pushing to Render will automatically read render.yaml. It spins up a persistent Node.js web service and auto-generates an ADMIN_PASSWORD for you.

Railway

Push to Railway and it will automatically detect the railway.toml config, building the backend via Nixpacks and keeping the daemon alive automatically.

Vercel (Testing Only)

Vercel is supported via vercel.json for UI testing. Note: Because Vercel is a stateless serverless platform, whitelist configurations and API keys will be saved to /tmp and will reset when the function goes to sleep. For production, use Render, Railway, or Docker.


🧪 Running Automated Tests

The security rules (Path checking, Directory Traversal prevention, Suffix attacks) are proven via an automated Jest test suite. To run the tests without starting the server:

bash
npm installnpm test

🛠️ MCP Tools Exposed to the AI

Once authenticated and restricted to a whitelisted folder, the AI has access to:

  1. read_file - Read text from a file.
  2. write_file - Write content to a file.
  3. list_directory - List all files in a folder.
  4. run_shell_command - Execute terminal commands strictly within the isolated workspace.

🚀 The Revolution: "Cursor on your Phone" (Gemini Mobile)

This server features a custom Streamable HTTP Transport Adapter designed specifically to bypass Google's aggressive caching and seamlessly hook into the Gemini mobile app (and web app).

You can now turn your phone into a full-fledged cloud coding environment, giving Gemini arbitrary filesystem and shell execution access on your machine!

How to Connect to Gemini

  1. Open the Gemini App (or gemini.google.com).
  2. Go to Settings > Connected Apps.
  3. Scroll to the bottom and click Add a custom app under "Custom apps for Spark".
  4. When prompted for the MCP Server URL, enter your server's endpoint: 👉 https://YOUR-APP-URL.onrender.com/gemini
  5. (If prompted for a Client ID or Secret, just leave them blank or enter dummy text — our custom OAuth bypass handles it automatically).
  6. Click Connect!

Once connected, you can open a chat with Gemini on your phone and ask it to list files in my project directory or run a shell command to start the server. Enjoy the power of Cursor right in your pocket! 🎉

Source: README.md at commit 21239e9

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 6, 2026