Dmcps

io.github.thealidevv1.0.0更新于 Oct 6, 2026

DMCPS: Highly secure, isolated MCP server environment giving AI agents sandboxed shell access.

概览

AI 生成的概览

让 AI 助手在白名单目录内进行沙箱化的文件读写、目录列举和 shell 命令执行。

功能
DMCPS 运行一个本地 Node.js/Express 守护进程,对外提供四个 MCP 工具:read_file、write_file、list_directory 和 run_shell_command。访问范围仅限于通过网页控制台显式加入白名单的目录,shell 执行也会按命令白名单进行校验。控制台还负责管理 API 密钥、出站防火墙目标和连接监控。
适用场景
当你希望助手在本机或已部署的容器中处理代码和文件,并且需要目录沙箱与命令过滤,而不是不受限制的主机访问时,可以使用它。它适合需要执行安装软件包等 shell 命令的本地开发流程。
运行要求
推荐的本地部署需要 Docker 或 Docker Compose,守护进程也可用 Node.js 运行。控制台需要 ADMIN_PASSWORD 环境变量;连接代理时需在 Authorization 请求头中传入自动生成的 Bearer API 密钥。可选 NGROK_AUTHTOKEN 用于对外暴露。控制台地址为 localhost:3000。
安装前请注意
该服务器提供 shell 执行和文件写入能力,白名单或命令列表配置不当可能影响真实文件。它在容器内以 root 运行,并刻意绕过 PaaS 的 hypervisor 限制,sudo 对白名单命令是解锁的。控制台仅由 ADMIN_PASSWORD 保护,API 密钥还可通过 URL 查询参数传递,可能被日志记录。通过 NGROK_AUTHTOKEN 等方式公开暴露端点会扩大攻击面。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Dmcps,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

🛡️ DMCPS (Docker Model Context Protocol Secured)

[CI Tests] [License: MIT] [MCP Registry]

🔥 OFFICIALLY PUBLISHED ON THE GLOBAL MCP REGISTRY! A true revolution in AI security. DMCPS seamlessly bypasses PaaS hypervisor limitations (like Render's no-new-privileges) via application-layer interceptors while retaining a military-grade directory sandbox.

[Deploy to Render]    [Deploy on Railway]    [Deploy with Vercel]

[DMCPS - Secure Docker sandbox for AI agent filesystem & shell access | Product Hunt]

A highly secure, isolated Model Context Protocol (MCP) server environment designed to give AI agents access to a sandboxed filesystem and shell execution, without compromising the host machine.

This is built as a robust Node.js/Express backend daemon, featuring a "military-grade" secured dashboard to strictly manage which directories the AI is allowed to touch.

🛡️ Key Security Features

  • PaaS Hypervisor Bypass via Node: Runs natively as root within the container, but uses JS interceptors to filter commands, allowing package installs (apk add) seamlessly on Render without triggering no-new-privileges crashes.
  • Strict Whitelisting: The AI cannot read, write, or execute commands outside of directories explicitly whitelisted via the web dashboard. (Directory traversal attempts like ../ are mathematically blocked).
  • Hardened Dashboard:
    • Protected by a single environment password (ADMIN_PASSWORD).
    • Implements Rate Limiting to prevent brute-force login attacks.
    • Hardened with Helmet (CSP, HSTS, XSS protection, anti-sniffing).
  • Auto-Generated API Keys: Connect to your MCP server using a dynamically generated Bearer token to ensure only authorized agents can execute tools on your server.
  • Application-Layer Sudo Whitelist: sudo is unlocked to allow the AI to install packages, but execution is strictly validated against a dashboard whitelist before reaching the shell. (apk add is whitelisted by default).
  • Firewall (iptables) Whitelist: Manage specific outbound network destinations dynamically from the dashboard.
  • Pre-installed AI Toolkit: Foundational tools (git, python3, curl, bash, make, jq) are pre-baked into the image so the AI is immediately ready to work.

🚀 Getting Started Locally

1. Configure Environment

Copy the example environment file:

bash
cp .env.example .env

Open .env and set your ADMIN_PASSWORD. (Optional: Add an NGROK_AUTHTOKEN to expose the server to the internet).

2. Run with Docker Compose

The safest way to run this is via the provided docker-compose.yml:

bash
docker-compose up -d --build

This will mount your local ./projects folder into the sandbox, but the AI won't be able to touch it until you approve the path in the dashboard.

3. Configure the Sandbox & Get Your API Key

Navigate to the mobile-friendly dashboard: 👉 http://localhost:3000/ Log in with username admin and your ADMIN_PASSWORD.

From the dashboard, you can:

  1. Whitelist directories (e.g., /projects/my-app) that the AI can interact with.
  2. Whitelist root commands for controlled package management (Note: apk add is already allowed by default).
  3. Configure Firewall by opening specific outgoing destinations via iptables.
  4. Copy your API Key needed for the AI agent to securely connect.
  5. Monitor Active Connections in real-time.
  6. Copy the exact JSON Config for Cursor or Claude Desktop.

4. Connect your AI Agent

Point your MCP-compatible AI agent (like Cursor, Claude Desktop, Gemini, Spark, or custom tools) to the Server-Sent Events (SSE) endpoint securely.

Raw agents and clients can connect to standard endpoints: 👉 http://localhost:3000/sse OR http://localhost:3000/mcp

You must pass the auto-generated API Key (found in your dashboard) in the request headers:

Authorization: Bearer mcp_your_random_key_here

(You can also pass it in the URL for raw browser connections: /mcp?key=mcp_your_random_key_here)


🌍 Cloud Deployments (Backend)

This is a persistent backend service, not a static frontend. It is pre-configured for 1-click deployments on modern PaaS providers.

Render

Clicking deploy or pushing to Render will automatically read render.yaml. It spins up a persistent Node.js web service and auto-generates an ADMIN_PASSWORD for you.

Railway

Push to Railway and it will automatically detect the railway.toml config, building the backend via Nixpacks and keeping the daemon alive automatically.

Vercel (Testing Only)

Vercel is supported via vercel.json for UI testing. Note: Because Vercel is a stateless serverless platform, whitelist configurations and API keys will be saved to /tmp and will reset when the function goes to sleep. For production, use Render, Railway, or Docker.


🧪 Running Automated Tests

The security rules (Path checking, Directory Traversal prevention, Suffix attacks) are proven via an automated Jest test suite. To run the tests without starting the server:

bash
npm installnpm test

🛠️ MCP Tools Exposed to the AI

Once authenticated and restricted to a whitelisted folder, the AI has access to:

  1. read_file - Read text from a file.
  2. write_file - Write content to a file.
  3. list_directory - List all files in a folder.
  4. run_shell_command - Execute terminal commands strictly within the isolated workspace.

🚀 The Revolution: "Cursor on your Phone" (Gemini Mobile)

This server features a custom Streamable HTTP Transport Adapter designed specifically to bypass Google's aggressive caching and seamlessly hook into the Gemini mobile app (and web app).

You can now turn your phone into a full-fledged cloud coding environment, giving Gemini arbitrary filesystem and shell execution access on your machine!

How to Connect to Gemini

  1. Open the Gemini App (or gemini.google.com).
  2. Go to Settings > Connected Apps.
  3. Scroll to the bottom and click Add a custom app under "Custom apps for Spark".
  4. When prompted for the MCP Server URL, enter your server's endpoint: 👉 https://YOUR-APP-URL.onrender.com/gemini
  5. (If prompted for a Client ID or Secret, just leave them blank or enter dummy text — our custom OAuth bypass handles it automatically).
  6. Click Connect!

Once connected, you can open a chat with Gemini on your phone and ask it to list files in my project directory or run a shell command to start the server. Enjoy the power of Cursor right in your pocket! 🎉

来源:README.md,提交 21239e9

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 6, 2026