AgentDock
A secure MCP runtime through which an agent operates local machines, servers and containers
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs commands and edits files on real machines and servers
- Exposes network access to the runtime with a token
Install
Manual install
{
"mcpServers": {
"agentdock": {
"url": "http://127.0.0.1:8765/mcp",
"headers": {
"Authorization": "Bearer <AGENTDOCK_AUTH_TOKEN>"
}
}
}
}First deploy the runtime via Docker or natively and take the token from its settings.
This is third-party code. Review the repository files before installing.
What it does
AgentDock is a standalone tool runtime for agents: it gives unified, controlled access to files, commands, Git, skills, MCP and a browser on the machines you choose. From one conversation in the agent you can operate several computers and servers: write code, change configuration, run commands and deploy right where the work belongs. File reads and writes are atomic with path boundaries and private-directory protection. It connects over MCP through a local HTTP address with a bearer token, installs via Docker or natively, and ships built-in skills.
Who it is for. For developers and devops who need to give an agent controlled access to machines and servers.
Good fit when
- You want to operate several machines and servers from one agent
- You need controlled agent access to files, commands and Git
- You want to deploy and configure services through the agent
Not a fit when
- You cannot give the agent access to commands and files on machines
- The agent's built-in tools in one project are enough
Example request
Connect to my server and restart the service after updating the configurationLimitations
The runtime gives the agent access to commands and files on real machines, so access and tokens must be tightly controlled. MCP connection goes over HTTP with a bearer token, and remote work needs careful network setup. It installs via Docker or natively.
How to disable. Remove the agentdock server from the MCP config and stop the runtime or container.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| AGENTDOCK_AUTH_TOKEN required, secret | Access token for the AgentDock runtime |
Security check
- Runs commands and edits files on real machines and servers
- Exposes network access to the runtime with a token
README in short
The README describes AgentDock as a standalone tool runtime for agents that gives controlled access to files, commands, Git, skills, MCP and a browser across several machines. From one conversation the agent operates computers and servers: writing code, changing configuration, running commands and deploying services. File work is atomic with path boundaries and private-directory protection. MCP connection goes through a local HTTP address with a bearer token, installed via Docker or natively. Apache-2.0 licensed.
FAQ
Is it an MCP server or a separate service?
It is a standalone tool runtime the agent connects to over MCP via HTTP with a token.
How safe is the access?
It has path boundaries, private-directory protection and atomic writes, but command access on machines needs token control.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring