
Dmcps
io.github.thealidevv1.0.0更新於 Oct 6, 2026
DMCPS: Highly secure, isolated MCP server environment giving AI agents sandboxed shell access.
概覽
讓 AI 助理在白名單目錄內進行沙箱化的檔案讀寫、目錄列舉與 shell 指令執行。
- 功能
- DMCPS 執行一個本機 Node.js/Express 常駐程式,對外提供四個 MCP 工具:read_file、write_file、list_directory 與 run_shell_command。存取範圍僅限於透過網頁儀表板明確加入白名單的目錄,shell 執行也會依指令白名單進行驗證。儀表板還負責管理 API 金鑰、對外防火牆目標與連線監控。
- 適用情境
- 當你希望助理在自己的機器或已部署的容器中處理程式碼與檔案,並且需要目錄沙箱與指令過濾,而不是不受限制的主機存取時,可以使用它。它適合需要執行安裝套件等 shell 指令的本機開發流程。
- 執行需求
- 建議的本機部署需要 Docker 或 Docker Compose,常駐程式也可用 Node.js 執行。儀表板需要 ADMIN_PASSWORD 環境變數;連接代理時需在 Authorization 標頭中傳入自動產生的 Bearer API 金鑰。可選的 NGROK_AUTHTOKEN 用於對外暴露。儀表板網址為 localhost:3000。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Dmcps,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
🛡️ DMCPS (Docker Model Context Protocol Secured)
[CI Tests] [License: MIT] [MCP Registry]
🔥 OFFICIALLY PUBLISHED ON THE GLOBAL MCP REGISTRY!
A true revolution in AI security. DMCPS seamlessly bypasses PaaS hypervisor limitations (like Render's no-new-privileges) via application-layer interceptors while retaining a military-grade directory sandbox.
[Deploy to Render] [Deploy on Railway] [Deploy with Vercel]
[DMCPS - Secure Docker sandbox for AI agent filesystem & shell access | Product Hunt]
A highly secure, isolated Model Context Protocol (MCP) server environment designed to give AI agents access to a sandboxed filesystem and shell execution, without compromising the host machine.
This is built as a robust Node.js/Express backend daemon, featuring a "military-grade" secured dashboard to strictly manage which directories the AI is allowed to touch.
🛡️ Key Security Features
- PaaS Hypervisor Bypass via Node: Runs natively as root within the container, but uses JS interceptors to filter commands, allowing package installs (
apk add) seamlessly on Render without triggeringno-new-privilegescrashes. - Strict Whitelisting: The AI cannot read, write, or execute commands outside of directories explicitly whitelisted via the web dashboard. (Directory traversal attempts like
../are mathematically blocked). - Hardened Dashboard:
- Protected by a single environment password (
ADMIN_PASSWORD). - Implements Rate Limiting to prevent brute-force login attacks.
- Hardened with Helmet (CSP, HSTS, XSS protection, anti-sniffing).
- Protected by a single environment password (
- Auto-Generated API Keys: Connect to your MCP server using a dynamically generated Bearer token to ensure only authorized agents can execute tools on your server.
- Application-Layer Sudo Whitelist:
sudois unlocked to allow the AI to install packages, but execution is strictly validated against a dashboard whitelist before reaching the shell. (apk addis whitelisted by default). - Firewall (iptables) Whitelist: Manage specific outbound network destinations dynamically from the dashboard.
- Pre-installed AI Toolkit: Foundational tools (
git,python3,curl,bash,make,jq) are pre-baked into the image so the AI is immediately ready to work.
🚀 Getting Started Locally
1. Configure Environment
Copy the example environment file:
Open .env and set your ADMIN_PASSWORD. (Optional: Add an NGROK_AUTHTOKEN to expose the server to the internet).
2. Run with Docker Compose
The safest way to run this is via the provided docker-compose.yml:
This will mount your local ./projects folder into the sandbox, but the AI won't be able to touch it until you approve the path in the dashboard.
3. Configure the Sandbox & Get Your API Key
Navigate to the mobile-friendly dashboard:
👉 http://localhost:3000/
Log in with username admin and your ADMIN_PASSWORD.
From the dashboard, you can:
- Whitelist directories (e.g.,
/projects/my-app) that the AI can interact with. - Whitelist root commands for controlled package management (Note:
apk addis already allowed by default). - Configure Firewall by opening specific outgoing destinations via
iptables. - Copy your API Key needed for the AI agent to securely connect.
- Monitor Active Connections in real-time.
- Copy the exact JSON Config for Cursor or Claude Desktop.
4. Connect your AI Agent
Point your MCP-compatible AI agent (like Cursor, Claude Desktop, Gemini, Spark, or custom tools) to the Server-Sent Events (SSE) endpoint securely.
Raw agents and clients can connect to standard endpoints: 👉 http://localhost:3000/sse OR http://localhost:3000/mcp
You must pass the auto-generated API Key (found in your dashboard) in the request headers:
(You can also pass it in the URL for raw browser connections: /mcp?key=mcp_your_random_key_here)
🌍 Cloud Deployments (Backend)
This is a persistent backend service, not a static frontend. It is pre-configured for 1-click deployments on modern PaaS providers.
Render
Clicking deploy or pushing to Render will automatically read render.yaml. It spins up a persistent Node.js web service and auto-generates an ADMIN_PASSWORD for you.
Railway
Push to Railway and it will automatically detect the railway.toml config, building the backend via Nixpacks and keeping the daemon alive automatically.
Vercel (Testing Only)
Vercel is supported via vercel.json for UI testing. Note: Because Vercel is a stateless serverless platform, whitelist configurations and API keys will be saved to /tmp and will reset when the function goes to sleep. For production, use Render, Railway, or Docker.
🧪 Running Automated Tests
The security rules (Path checking, Directory Traversal prevention, Suffix attacks) are proven via an automated Jest test suite. To run the tests without starting the server:
🛠️ MCP Tools Exposed to the AI
Once authenticated and restricted to a whitelisted folder, the AI has access to:
read_file- Read text from a file.write_file- Write content to a file.list_directory- List all files in a folder.run_shell_command- Execute terminal commands strictly within the isolated workspace.
🚀 The Revolution: "Cursor on your Phone" (Gemini Mobile)
This server features a custom Streamable HTTP Transport Adapter designed specifically to bypass Google's aggressive caching and seamlessly hook into the Gemini mobile app (and web app).
You can now turn your phone into a full-fledged cloud coding environment, giving Gemini arbitrary filesystem and shell execution access on your machine!
How to Connect to Gemini
- Open the Gemini App (or gemini.google.com).
- Go to Settings > Connected Apps.
- Scroll to the bottom and click Add a custom app under "Custom apps for Spark".
- When prompted for the MCP Server URL, enter your server's endpoint:
👉
https://YOUR-APP-URL.onrender.com/gemini - (If prompted for a Client ID or Secret, just leave them blank or enter dummy text — our custom OAuth bypass handles it automatically).
- Click Connect!
Once connected, you can open a chat with Gemini on your phone and ask it to list files in my project directory or run a shell command to start the server. Enjoy the power of Cursor right in your pocket! 🎉
來源:README.md,提交 21239e9
工具
0版本歷史
1- v1.0.0最新Oct 6, 2026


