Kujolang.ai MCP

io.github.kujolangv0.1.0更新于 Sep 30, 2026

Discover Kujo projects, tools, skills, workflows, and installation guidance with read-only tools.

已验证Streamable HTTP可网页运行Developer ToolsKnowledge & Memory

概览

AI 生成的概览

通过托管或本地 MCP 端点,以只读方式发现 Kujo 项目、技能、工作流和安装指南。

功能
提供七个只读工具来探索 Kujo 生态:Kujo 概览与目录计数、生态列表与目录搜索、带来源链接和版本的精确条目检索、小型确定性技术栈推荐、安装配置档查看,以及 WebOps 能力搜索。六个资源和三个提示词覆盖概览、项目、技能、工作流、安装和安全数据。所有工具均为确定性、幂等且只读。
适用场景
适合助手回答关于 Kujo 项目、原语、工具、展示、技能或工作流的问题,或为某项任务建议技术栈和安装配置档。它用于发现和指导,而非执行。
运行要求
使用 mcp.kujolang.ai 的远程 Streamable HTTP 端点,或本地 Kujo 运行时在 127.0.0.1:8941 运行服务器。未声明任何凭据、API 密钥或环境变量;公共目录不需要用户身份验证。
安装前请注意
该服务器为只读,没有写入、安装、部署、文件系统、shell 或读取密钥的能力,也不会执行其返回的安装命令。目录内容是经过审核的快照;README 指出其修订号可检测意外损坏,但不能替代签名发布或人工审核。本地非回环启动需明确确认可信入口限制。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Kujolang.ai MCP,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "kujolang-mcp": {
      "type": "http",
      "url": "https://mcp.kujolang.ai/mcp"
    }
  }
}

README

Kujolang.ai MCP Server

kujolang-mcp is a read-only Model Context Protocol server for discovering Kujo projects, primitives, tooling, showcases, agent skills, workflows, and reviewed installation guidance. The complete runtime and every custom utility are written in Kujo.

This repository is the Kujolang.ai catalog server, not the reusable kujolang/mcp framework. It follows that framework's conventions while remaining independently deployable and product-specific.

Readiness

The repository contains the native reference server and a generated Cloudflare Worker target. The public service is bounded, stateless, deterministic, and read-only. The Worker is generated from Kujo definitions and the reviewed catalog; Cloudflare executes the generated JavaScript artifact, not Kujo source directly. This is not a claim of formal enterprise certification.

The public URL is https://mcp.kujolang.ai/mcp and health is https://mcp.kujolang.ai/health once deployment verification passes. Local use is always available.

What agents can do

  • Understand Kujo and the current public catalog.
  • List and search projects, primitives, tooling, showcases, skills, and workflows.
  • Retrieve exact records with source links, install text, versions, and scope notes.
  • Receive small deterministic stack recommendations for concrete work.
  • Inspect default, grouped, and complete installer profiles without executing them.
  • Discover WebOps capabilities without unrelated search results consuming the result limit.

All seven tools are read-only, deterministic, and idempotent. There is no write tool, arbitrary URL fetcher, filesystem-path input, shell input, package installer, deployment action, or secret-reading capability.

Quick start

Use a Kujo runtime with run, test, and the HTTP standard library:

bash
cd /path/to/kujolang-mcpkujo run server.kujo --interpreter --self-checkkujo run server.kujo --interpreter

The local endpoint is http://127.0.0.1:8941/mcp; /mcp/v1 is a compatibility alias and /health is the health endpoint.

For a local Streamable HTTP client:

json
{  "mcpServers": {    "kujolang": {      "type": "http",      "url": "http://127.0.0.1:8941/mcp"    }  }}

The server advertises MCP 2026-07-28 and handshake-era 2025-06-18. Production configuration enables strict Mcp-Method and Mcp-Name binding for 2026 requests.

MCP surface

ToolPurpose
get_kujo_overviewExplain Kujo, catalog counts, discovery flow, and the trust boundary
list_ecosystemFilter projects, skills, and workflows by kind or category
search_kujo_catalogSearch released public catalog metadata
get_catalog_itemRetrieve one exact item and its source-backed guidance
recommend_kujo_stackReturn a compact deterministic match set for a task
get_installationReturn default, core, AI, quality, showcase, operating, or complete install guidance
list_webops_capabilitiesSearch only the WebOps capability collection

Six resources expose overview, project, skill, workflow, installation, and safety data. Three prompts guide stack selection, adoption planning, and WebOps discovery.

Repository layout

text
server.kujo                         Thin stable launchersrc/runtime.kujo                    Configuration, modes, and HTTP routingsrc/http_security.kujo              Transport guards and security headerssrc/protocol.kujo                   JSON-RPC and MCP dispatchsrc/registry.kujo                   Tools, resources, and promptssrc/catalog.kujo                    Catalog validation, indexing, and searchdata/catalog.json                   Reviewed deterministic catalog snapshotscripts/sync_catalog.kujo           Kujo-only catalog synchronizationscripts/generate_worker.kujo        Kujo-only Worker generationdist/worker.js                      Reviewed generated Cloudflare Workerwrangler.jsonc                      Free-tier Worker deployment configurationbenchmarks/search_benchmark.kujo    Kujo-only search benchmarktests/                              Kujo test suites and snapshots

Root-level manifests, policy, configuration, license, documentation, and the thin launcher remain at the root because package managers, operators, and repository hosts discover them there. Application implementation lives under src/.

Catalog integrity and synchronization

The bundled catalog is validated at startup for schema, item shape, unique slugs, counts, and a SHA-256 content digest. Production requests never read a sibling website checkout or fetch remote URLs.

Regenerate or verify it from a reviewed Kujolang.ai checkout:

bash
kujo run scripts/sync_catalog.kujo --interpreter -- --site /path/to/kujolang.aikujo run scripts/sync_catalog.kujo --interpreter -- --site /path/to/kujolang.ai --check

The synchronizer rejects duplicate or malformed slugs and unexpected source URL schemes. Installer profile membership is parsed from the website's public installer instead of duplicated by hand. The catalog revision covers both records and installation profiles; it detects accidental snapshot corruption but is not a substitute for signed releases or human review.

The current snapshot contains 50 projects, 135 skills, and 45 workflow records (230 records total; 44 kits plus the Publishing House Operator). There is no authoritative standalone agent catalog in the source; agent-related projects, SDKs, skills, and workflows remain discoverable under their actual source kinds rather than being presented as invented agent records.

For the autonomous weekly agent prompt that reviews source accuracy, updates GitHub, deploys through the configured hosting workflow, and verifies the live catalog, see docs/WEEKLY_REFRESH.md.

Security and performance controls

  • Search fields are length-bounded and normalized query terms are deduplicated and capped before catalog work.
  • Search text and identity fields are indexed once when the catalog loads.
  • Host is mandatory and allowlisted; browser Origin is exact-allowlisted when present.
  • JSON requests require application/json, bounded body configuration, validated envelopes, object parameters, and deterministic errors.
  • Responses include defensive no-store, no-sniff, frame, referrer, resource, and content security headers.
  • Local rate limiting uses isolated request buckets when the runtime supplies a peer address; health checks do not consume the quota.
  • Non-loopback startup fails unless trusted ingress limits are explicitly acknowledged, and public listeners refuse the application-local limiter because the current runtime cannot reliably identify anonymous socket peers.

The application body check happens after the current Kujo HTTP runtime buffers the request. Production ingress must reject oversized bodies and enforce connection/read timeouts before forwarding.

Verification

bash
kujo run scripts/sync_catalog.kujo --interpreter -- --site /path/to/kujolang.ai --checkkujo run server.kujo --interpreter --self-checkkujo run tests/run_all.kujo --interpreterkujo run benchmarks/search_benchmark.kujo --interpreterkujo run scripts/generate_worker.kujo --interpreter -- --framework /path/to/mcpnode --check dist/worker.js

Production deployment contract

Select the production configuration explicitly:

bash
KUJOLANG_MCP_CONFIG=mcp-server.production.example.json \  kujo run server.kujo --interpreter

The trusted ingress must:

  • terminate TLS and be the only network peer allowed to reach the Kujo listener;
  • enforce body bytes, connection/read timeouts, per-client throttling, and a global overload ceiling before proxying;
  • overwrite or discard spoofable client identity headers;
  • forward only /mcp and /health with the exact public Host;
  • provide access/error metrics, alerting, capacity limits, and incident-response routing.

The public catalog intentionally requires no user credentials. If private or tenant data, remote fetching, writes, or execution are ever introduced, this authority model must be redesigned and authentication becomes mandatory.

See SECURITY.md for the complete boundary and docs/NEXT_SESSION_REVIEW.md for the next production-readiness work list.

License

MIT

Release freshness

The catalog's version and latest_release_url identify a published component release when one exists. scope_note distinguishes later default-branch work, preview support, and operator requirements. The catalog's source_version is the website version, not the Kujo runtime version; the kujo item records the current runtime. Private projects retain empty public source/install fields.

The September 9 review covers all 86 public organization repositories, the 135 released skill records, and all 44 workflows in the 0.6.0 distribution. Its source inventory is in evidence/ecosystem-refresh-2026-09-09/.

Use Kujo 1.6.0 for native catalog generation and assertion tests. Node verifies the generated JavaScript Worker and its parity with the native implementation; it is not a runtime dependency of the hosted read-only catalog. Neither server installs or executes commands returned in catalog content.

After deploying, run node tests/production_catalog_test.mjs to compare all public catalog records and installer profiles with the reviewed generated Worker. Set RECEIPT_PATH to retain a JSON receipt. This sends read-only MCP queries and never executes installation commands.

The Kujo runtime entry now identifies the published 1.6.0 release across Linux x64/arm64, macOS x64/arm64 and Windows x64, including runtime npm packages. Wave C beta and Wave D alpha remain experimental; participant SDK packages remain private/unpublished. The catalog remains read-only and grants no replay authority.

The September 29 companion refresh identifies Workcell, Ability and MCP 1.2.0. Preservation, controlled application/STDIO execution and Git correlation retain their documented experimental boundaries. Dispatch publication is separate.

The September 29 SSG refresh records SSG 1.1.0, default-on experimental public WebMCP, and the independently versioned local Ability pack 1.0.0. It also synchronizes the website's reviewed Kennel install guidance. The catalog remains read-only; it does not execute SSG builds or deploy sites.

来源:README.md,提交 72d60f4

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Sep 30, 2026