Add bounded read-only Athena terminal MCP

This commit is contained in:
Mikei386 committed 2026-08-23 19:38:57 +02:00
1 parent c3e44b18f8
commit 91d36a98e3
15 files changed
+806 -7

No files matched your search

@@ -1,7 +1,7 @@
"""
title: MikeAI Auto Tool Selector
author: MikeAI
version: 1.0.0
version: 1.1.0
description: Selects a small, relevant set of MCP servers for each user request.
"""
@@ -27,6 +27,7 @@ class Filter:
"unraid": "server:mcp:unraid-readonly-local",
"navidrome": "server:mcp:navidrome-local",
"platform": "server:mcp:athena-platform",
"terminal": "server:mcp:athena-terminal-local",
}
LABELS = {
@@ -37,6 +38,7 @@ class Filter:
"unraid": "Unraid-Diagnose",
"navidrome": "Navidrome",
"platform": "Athena-Plattformwissen",
"terminal": "Athena-Terminal (begrenzt, nur lesend)",
}
def __init__(self):
@@ -94,6 +96,15 @@ class Filter:
selected: list[str] = []
terminal = self._matches(
text,
(
r"\bathena[- ]terminal\b",
r"\b(?:athena|ki[- ]host)\b.*\b(?:terminal|shell|kommando|befehl)\b",
r"\b(?:terminal|shell)\b.*\b(?:athena|ki[- ]host)\b",
r"\b(?:ls|tail|grep|rg|cat)\b.*\b(?:athena|ki[- ]host)\b",
),
)
platform = self._matches(
text,
(
@@ -103,6 +114,8 @@ class Filter:
r"\b(?:disaster|bare metal)[- ]recovery\b",
r"\b(?:installations?|reinstall|setup)[- ]skript\b",
r"\bplattform(?:wissen|dokumentation)?\b",
r"\bmcp\b.*\b(?:bau\w*|implementier\w*|entwickel\w*|integrier\w*)\b",
r"\b(?:bau\w*|implementier\w*|entwickel\w*|integrier\w*)\b.*\bmcp\b",
),
)
homeassistant = self._matches(
@@ -155,7 +168,9 @@ class Filter:
# A specialist source is more precise than public web search. Platform
# wins over a generic Docker mention when Athena is explicitly named.
if platform:
if terminal:
selected.append("terminal")
elif platform:
selected.append("platform")
elif homeassistant:
selected.append("homeassistant")
+37
View File
@@ -212,6 +212,13 @@ with con:
"Quellcode dieses Werkzeug statt allgemeiner Websuche verwenden. Keine Issues, "
"Pull Requests, Actions oder Schreibzugriffe.",
),
"athena-terminal-local": (
"Athena Terminal (begrenzt, nur lesend)",
"Nur für gezielte Beweissuche in Athenas versioniertem Stack und einem "
"begrenzten Laufzeitsnapshot. Unterstützt ausschließlich fest erlaubte "
"Lesebefehle und Syntaxprüfung. Kein SSH, Docker, Netzwerk, Schreibzugriff, "
"Reboot, Shutdown, systemctl, Interpreter oder Zugriff auf Secrets.",
),
}
changed = False
for connection in connections:
@@ -237,6 +244,8 @@ with con:
match = "navidrome-local"
elif "mike-ai-mcp-github" in url:
match = "github-local"
elif "mike-ai-mcp-athena-terminal" in url:
match = "athena-terminal-local"
elif "mike-ai-mcp-unraid-official" in url:
match = "unraid-readonly-local"
else:
@@ -274,6 +283,34 @@ with con:
}
)
changed = True
if not any(
isinstance(connection, dict)
and (
str(connection.get("url", "")).lower()
== "http://mike-ai-mcp-athena-terminal:8000/mcp"
or str((connection.get("info") or {}).get("id", "")).lower()
== "athena-terminal-local"
)
for connection in connections
):
name, description = descriptions["athena-terminal-local"]
connections.append(
{
"url": "http://mike-ai-mcp-athena-terminal:8000/mcp",
"path": "",
"type": "mcp",
"auth_type": "none",
"headers": None,
"key": "",
"config": {"enable": True, "access_grants": []},
"info": {
"id": "athena-terminal-local",
"name": name,
"description": description,
},
}
)
changed = True
if github_enabled and not any(
isinstance(connection, dict)
and (