Dagu
A local-first workflow engine in a single binary with a built-in MCP server so an agent can inspect and run jobs
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs arbitrary commands, containers and SSH operations
- The MCP server lets clients control runs in your environment
Install
Manual install
brew install daguInstalls the binary on macOS and Linux. Start everything with dagu start-all.
This is third-party code. Review the repository files before installing.
What it does
Dagu defines workflows in declarative YAML as directed acyclic graphs and runs them: shell commands, Docker containers, Kubernetes Jobs and remote commands over SSH. It is a single binary with a built-in web UI, no external database or message broker. It offers schedules, retries, human tasks and run history. A built-in MCP server at localhost:8080/mcp lets an agent inspect workflows and run state, maintain built-in wiki pages, preview and apply changes and control execution.
Who it is for. For devops engineers and developers who need to orchestrate scripts and jobs with agent-driven control.
Good fit when
- You want to turn scripts and runbooks into workflows with schedules, retries and history
- You need self-hosted orchestration without heavy infrastructure
- You want an agent to inspect and run workflows through MCP
Not a fit when
- A plain cron for a single job is enough
- You cannot give an agent the right to run commands in your environment
Example request
List my Dagu workflows and run the one that builds the nightly reportLimitations
Dagu runs arbitrary commands, containers and remote operations, so MCP server access must be guarded by authentication. The server and web UI listen on port 8080 by default. It is a self-hosted engine: deployment, updates and security are on you. GPL-3.0 licensed.
How to disable. Stop the dagu process, remove the binary or container and delete the server from your MCP client config.
MCP
- Transport
- http
- Authentication
- API key
Security check
- Runs arbitrary commands, containers and SSH operations
- The MCP server lets clients control runs in your environment
README in short
The README presents Dagu as a local-first workflow engine for operations and internal automation: a single binary, a web UI, no external database. It covers support for shell, Docker, Kubernetes Jobs and SSH, schedules, retries, human tasks and history. It shows install via script, Homebrew, npm and Docker, plus the built-in MCP server for inspecting and controlling runs. GPL-3.0 licensed.
FAQ
Does it need an external database?
No. Dagu runs as a single binary and stores state itself, without a separate DBMS or message broker.
What can the MCP server do?
Inspect workflows and runs, maintain built-in wiki pages, preview and apply changes to DAGs and control execution for authenticated clients.
Related
An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n
Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account
Awesome Claude Skills by Composio
Awesome Claude Skills
A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps
A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub