{"_id":"@brycepelletier/agent-env-mcp","_rev":"7-153221d016e3ee7ce734bfeb2dbcb48f","name":"@brycepelletier/agent-env-mcp","dist-tags":{"latest":"1.1.0"},"versions":{"0.4.0":{"name":"@brycepelletier/agent-env-mcp","version":"0.4.0","license":"MIT","_id":"@brycepelletier/agent-env-mcp@0.4.0","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"9a0bc08bb1adc60cbafd98b3832e888957944470","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-0.4.0.tgz","fileCount":8,"integrity":"sha512-dO3yLJG+0pe0lhxEvZ6HmumHxmoYDGuKwbpCWHTKfz/gEh6pfQC6P6lZmopIP9dH+1cKhQX5Fu2b9w0CDNNuJQ==","signatures":[{"sig":"MEYCIQD0e2gvUMCylpdRJWM+8gFt9CuQsytxgYBcoxZGTuV3igIhAOnXwkYbIzDz00zV2xUNuiIpIwHdEJhpSjkWI9qOlRiM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":43694},"type":"module","engines":{"node":">=20.10"},"gitHead":"fc1ce0423c630c4406684ab472d0243dba460fbf","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_0.4.0_1787516208765_0.8180008799428646","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@brycepelletier/agent-env-mcp","version":"0.4.1","license":"MIT","_id":"@brycepelletier/agent-env-mcp@0.4.1","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"c592d64ce86b054ddcc59411008a2973a112efb8","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-0.4.1.tgz","fileCount":8,"integrity":"sha512-0AgD8kWJjPYbbM8SMpsxvTQbRVUH8aAdl+0UcEOAGk3lGfCboWiaGJCkktv/cp0lVY2IsCaIMJD85W+XQklFZg==","signatures":[{"sig":"MEYCIQDF8U2KKxIiUasxVgTQ704d55d/xPAgGXx3UC0jKRrHIgIhAIzhO+ytVxafepNV6EDrieNlhvmDy/7NLNB9tohTR9D7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":44615},"type":"module","engines":{"node":">=20.10"},"gitHead":"56948cef920f1a97d2c3f8ac9dcc495b74f75de9","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_0.4.1_1787535178428_0.3845224076697973","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@brycepelletier/agent-env-mcp","version":"0.4.2","license":"MIT","_id":"@brycepelletier/agent-env-mcp@0.4.2","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"c9e81632380ac7f12cdb08d418a376753b8a48a6","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-0.4.2.tgz","fileCount":8,"integrity":"sha512-AujqD+fJVnI84FLFq3u71RbzHp2dUXL2JD8NZmGKZ32pNe/rs7tJmzi+44RvIK9jhCiPk3tUf1EutS//N2ov3g==","signatures":[{"sig":"MEYCIQDAZvJqdm094vYvTvJoPnMx5AvuSsRnztGHaZtLjbmIWAIhAMqqMdsjnqGETi2ab4qlEWhQr982Fx1+Owdt1jKj9swL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47485},"type":"module","engines":{"node":">=20.10"},"gitHead":"85eebcd1e7e93782cb0d615ac11179af7ab982bd","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_0.4.2_1787624559737_0.5182264325757062","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"@brycepelletier/agent-env-mcp","version":"0.4.3","license":"MIT","_id":"@brycepelletier/agent-env-mcp@0.4.3","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"c806eb0eb9e8fb869dbb220478768a02b79ca133","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-0.4.3.tgz","fileCount":8,"integrity":"sha512-6IHaFJhwThOfovdpjcLxQZC3PSJdaoYS1GP2TyTzM+0gRnW6XGzjOF5g/FodRbWKImZA9JDGb4AYASylCcTtGQ==","signatures":[{"sig":"MEQCICrIgZVWwR/0QgbiuuMgcrummTC5O2uE5EkUqS2bTMh2AiBPmGD+3WVrd48e/ribB7f8kFP0vqfTYbcmibUnFVyFoQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48645},"type":"module","engines":{"node":">=20.10"},"gitHead":"85eebcd1e7e93782cb0d615ac11179af7ab982bd","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_0.4.3_1787698924342_0.8376615922908359","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@brycepelletier/agent-env-mcp","version":"0.5.0","license":"MIT","_id":"@brycepelletier/agent-env-mcp@0.5.0","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"efe528d30e3b7e72db66abb82aec1c789d32c01c","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-0.5.0.tgz","fileCount":8,"integrity":"sha512-ppm/EwX3sVB++DiOUmtm8gxIUM8rUXtj+hOsORt4crZmKjG1AGVF2+WFqN/Ah1SzaY5G7n/oWzL4W9sT6727gA==","signatures":[{"sig":"MEUCIQDQwScYsyBsN1lq+CP/ehTnquD5yrWMrOOx2yA+K0p1KwIgXlalqhodTBiCvmnR26YAKdHiEj02gt79pEflZaGvW1k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":51591},"type":"module","engines":{"node":">=20.10"},"gitHead":"984b2d14f3e8dcb450bb8ed1794cffc4e342c88e","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_0.5.0_1787767490219_0.739846523070822","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@brycepelletier/agent-env-mcp","version":"1.0.0","license":"MIT","_id":"@brycepelletier/agent-env-mcp@1.0.0","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"bin":{"agent-env-mcp":"index.mjs"},"dist":{"shasum":"fb6b69b899f6a688aa44a53a44b3cdb90d3c3016","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-1.0.0.tgz","fileCount":9,"integrity":"sha512-gq2AYoxU7Z04BNyfD8DdvXhyirdcoyZpEBnXobwVGc6L32qXOKSsNzSobqiUXrpTwAfl10ZI1khG6YlCmXll/g==","signatures":[{"sig":"MEUCIFQLLEWRMXM6XyKICdkRi6v79pss2jx5CW47b2u/5L7NAiEAl+bqqI062Aav2PQ0Sn0Whl4tYcCOTjHXy4JI4wVqBes=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58454},"type":"module","engines":{"node":">=20.10"},"gitHead":"543b2fb77cd9c7a575df37f79f966912fc53196a","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && node --check ./runtime/agent-system.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && node --check ./runtime/agent-system.mjs && npm test && npm pack --dry-run"},"_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-env-mcp_1.0.0_1787966914418_0.3795339337997188","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"_id":"@brycepelletier/agent-env-mcp@1.1.0","bin":{"agent-env-mcp":"index.mjs"},"bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"dist":{"shasum":"dea803144918f153521ba1b6ea691b767efd04bd","tarball":"https://registry.npmjs.org/@brycepelletier/agent-env-mcp/-/agent-env-mcp-1.1.0.tgz","fileCount":10,"integrity":"sha512-u+0TKfoZTb3m8xjgHmZS79lwc7o7/mKKJHZI817G5tnYGwTjGtcfFDtjUOWjkUNFY+jGxlmmhP1d6ud8N3aHPw==","signatures":[{"sig":"MEUCIQCYuZNVgb1rwcY+hkN5KPMGcQ9UyWOXvzfIwihqQXOaMAIgJaiwayZCJBVRElxamF+bhtjmXxi9f1KjXH+eBcEVF8M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGUHB+xF9B1b879sGQ7M3hn8Z+kUF0OG8miQWDYd7OO6AiAeihyd0s8gmj2ML9JRSkTA5b3eytms8zcp2b6+YP4CcQ=="}],"unpackedSize":63194},"name":"@brycepelletier/agent-env-mcp","type":"module","engines":{"node":">=20.10"},"gitHead":"ac0819ca5dab052cc6eb5a2edb73d12923cd535b","license":"MIT","scripts":{"link":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && node --check ./runtime/agent-system.mjs && npm install && npm link","test":"node --test","unlink":"npm uninstall --global @brycepelletier/agent-env-mcp","validate":"node --check ./index.mjs && node --check ./runtime/helper.mjs && node --check ./runtime/lifecycle.mjs && node --check ./runtime/agent-system.mjs && npm test && npm pack --dry-run"},"version":"1.1.0","_npmUser":{"name":"brycepelletier","email":"brycepelletier@gmail.com"},"homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"_npmVersion":"11.17.0","description":"Hardened MCP gateway for reusable containerized software-engineering environments.","directories":{},"maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.22.0","@modelcontextprotocol/sdk":"^1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-env-mcp_1.1.0_1789752809976_0.40018967491373747"}}},"time":{"created":"2026-08-23T20:16:48.505Z","modified":"2026-09-18T17:33:30.211Z","0.4.0":"2026-08-23T20:16:48.909Z","0.4.1":"2026-08-24T01:32:58.577Z","0.4.2":"2026-08-25T02:22:39.868Z","0.4.3":"2026-08-25T23:02:04.510Z","0.5.0":"2026-08-26T18:04:50.496Z","1.0.0":"2026-08-29T01:28:34.569Z","1.1.0":"2026-09-18T17:33:30.070Z"},"bugs":{"url":"https://github.com/brycepelletier/agent-env-mcp/issues"},"license":"MIT","homepage":"https://github.com/brycepelletier/agent-env-mcp#readme","repository":{"url":"git+https://github.com/brycepelletier/agent-env-mcp.git","type":"git"},"description":"Hardened MCP gateway for reusable containerized software-engineering environments.","maintainers":[{"name":"brycepelletier","email":"brycepelletier@gmail.com"}],"readme":"# @brycepelletier/agent-env-mcp\r\n\r\nReusable host-side MCP controller for a hardened Linux software-engineering\r\nruntime.\r\n\r\n## 0.4.0 trust boundary\r\n\r\n`agent-env-mcp` is software-engineering only. Its single `agent` service can\r\ninspect, edit, build, test, lint, and debug the active workspace. The real\r\n`.git` directory is physically masked by a root-owned tmpfs mount, and the\r\ncontainer receives no GitHub credentials or Docker socket.\r\n\r\n```text\r\nSoftware Engineer\r\n       |\r\nagent-env-mcp\r\n       |\r\nLinux engineering runtime\r\n       |-- source tree visible\r\n       |-- .git masked\r\n       |-- no GitHub credentials\r\n       `-- no Docker socket\r\n\r\nGitHub Operator\r\n       |\r\ngithub-app-mcp\r\n       `-- all Git and GitHub operations\r\n```\r\n\r\nVersion 0.4.0 removes the former `git` service and public `git_command`. That is\r\nan intentional breaking change: all local and remote Git operations belong to\r\n`@brycepelletier/github-app-mcp` and the GitHub Operator trust domain.\r\n\r\n## Tools\r\n\r\n### `describe_agent_system`\r\n\r\nReads the installed `~/.agents/*.agent.md` frontmatter and returns the current orchestrator identity, direct capability categories, permitted specialists, their ownership categories, exact `runSubagent` calls, and source filename/hash. It accepts no path or other arguments, does not start the container environment, and never returns specialist tool inventories or schemas. Invalid, duplicate, or missing definitions fail closed.\r\n\r\n- `ensure_environment`\r\n- `list_directory`\r\n- `read_file`\r\n- `search_workspace`\r\n- `workspace_edit`\r\n- `run_command`\r\n\r\nRecursive workspace listing and search omit `.git`, `.ssh`, and `.gnupg`\r\ndirectory nodes and their descendants at every depth. Direct read or edit\r\nrequests containing those path segments are rejected before filesystem access.\r\nThe `.git` mount remains physically masked from programs launched through\r\n`run_command`; programs that deliberately access it may receive a permission\r\nerror without gaining repository metadata.\r\n\r\nThe MCP discovers the active VS Code workspace lazily through MCP Roots,\r\nrequires exactly one local `file:` root, and does not accept a model-supplied\r\nhost workspace path.\r\n\r\n`read_file` returns only the path, truncation state, and verbatim source text.\r\nSource lines and response fields are never decorated with generated line\r\nnumbers. This makes returned content safe to reuse as `workspace_edit.old_text`\r\nwithout accidentally searching for presentation-only prefixes or normalized\r\nline endings. `search_workspace` likewise returns file paths and matching text\r\nwithout generated line or column numbers. Other MCP modules must not decorate\r\neditable source content with synthetic numbering.\r\n\r\nFor full-file changes, use `workspace_edit` with `operation: \"overwrite\"`, the\r\ncomplete `new_text`, and the `expected_sha256` returned by `read_file`. This\r\navoids sending a second escaped copy of the old file while still preventing a\r\nstale agent from overwriting concurrent work. Use `operation: \"replace\"` only\r\nfor small, unique, exact snippets.\r\n\r\n```json\r\n{\r\n  \"operation\": \"overwrite\",\r\n  \"path\": \"src/example.cpp\",\r\n  \"expected_sha256\": \"<sha256 returned by read_file>\",\r\n  \"new_text\": \"<complete desired file>\"\r\n}\r\n```\r\n\r\n### Command path semantics\r\n\r\nThe `workspace` reported by `ensure_environment` is already the authorized\r\nproject root. `run_command` resolves `cwd` and any executable path containing a\r\nslash relative to that root. Use `cwd: \".\"` for repository-root commands or a\r\nrelative subdirectory such as `scripts`; do not pass an absolute path or repeat\r\nthe project directory name. In the Linux runtime, prefer `python3` unless the\r\nrepository defines another interpreter.\r\n\r\nExamples:\r\n\r\n```json\r\n{\"program\":\"python3\",\"args\":[\"verify_pr_validation.py\"],\"cwd\":\".\"}\r\n{\"program\":\"python3\",\"args\":[\"scripts/verify_pr_validation.py\"],\"cwd\":\".\"}\r\n{\"program\":\"python3\",\"args\":[\"verify_pr_validation.py\"],\"cwd\":\"scripts\"}\r\n```\r\n\r\nInvalid paths, missing executables, and permission failures return concrete\r\nsanitized errors. A program that starts and exits unsuccessfully returns its\r\n`exit_code`, `signal`, bounded `stdout`, and bounded `stderr`, including script,\r\ndependency/import, and network diagnostics emitted by that program. These\r\ndetails improve recovery without expanding the authorized filesystem boundary.\r\n\r\n## Host prerequisites\r\n\r\n- Node.js 20.10 or newer\r\n- Docker with Linux-container support\r\n- Exactly one local VS Code workspace root\r\n\r\n## Docker behavior and lifecycle\r\n\r\nThe trusted host facade starts one deterministic Docker Compose project for the\r\nactive workspace. The only runtime service is `agent`; it runs as the unprivileged\r\n`vscode` user with all Linux capabilities dropped and `no-new-privileges` set.\r\nThe workspace is bind-mounted, while its `.git` directory is over-mounted with\r\nan inaccessible tmpfs. No Docker socket or credential path is mounted.\r\n\r\nMCP stdin EOF/close, SIGINT, SIGTERM, SIGHUP, or a fatal process error starts an\r\nidempotent shutdown. Shutdown waits for in-flight preparation, runs\r\n`docker compose down --remove-orphans`, closes the MCP server, and exits. The\r\n15-minute idle timeout is a secondary cleanup path. New calls fail once shutdown\r\nbegins.\r\n\r\n## Local development and validation\r\n\r\nFrom Git Bash:\r\n\r\n```bash\r\nnpm run link\r\nnpm test\r\nnpm run validate\r\nnpm run unlink\r\n```\r\n\r\n`npm run validate` performs syntax checks, policy and lifecycle tests, and an\r\nnpm package dry run. Docker Compose rendering and image builds are separate host\r\nintegration checks because they require a running Docker daemon.\r\n\r\n## VS Code configuration\r\n\r\nPublished-package configuration:\r\n\r\n```json\r\n{\r\n  \"servers\": {\r\n    \"agent-env\": {\r\n      \"type\": \"stdio\",\r\n      \"command\": \"npx\",\r\n      \"args\": [\"--yes\", \"@brycepelletier/agent-env-mcp@0.4.1\"]\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nWhile locally linked, replace `npx` and its arguments with:\r\n\r\n```json\r\n\"command\": \"agent-env-mcp\"\r\n```\r\n\r\n## Acceptance checks\r\n\r\nBefore relying on the boundary:\r\n\r\n1. `ensure_environment` reports the expected project workspace.\r\n2. `run_command` can build and test the project.\r\n3. Direct `git` is rejected by policy.\r\n4. Invoking the real Git binary indirectly through Python or Node reports that\r\n   the workspace is not a Git repository because `.git` is physically hidden.\r\n5. `.git`, `.ssh`, and `.gnupg` paths are inaccessible through workspace tools.\r\n6. No GitHub credential variables, PEM, or Docker socket are visible.\r\n7. The MCP tool inventory contains no `git_command` or GitHub API tools.\r\n8. Closing the MCP connection removes its Compose containers.\r\n\r\nThe `.git` masking assumes a standard checkout where `.git` is a directory.\r\nGit worktrees and submodules that use a `.git` file must be rejected or handled\r\nby a future mount strategy before treating those repository forms as hardened.\r\n\r\n## License\r\n\r\nMIT. See `LICENSE`.\r\n\r\n## Command diagnostics and Python\r\n\r\nensure_environment defines the repository root. run_command.cwd is `.` or a relative POSIX subdirectory; absolute/Windows/traversing paths remain denied. Executable paths are relative to cwd. Operational failures return MCP isError with a stable code and message instead of an opaque protocol exception. Nonzero subprocess results retain exit_code, signal, stdout, stderr, and truncation information; dependency/import/script/network errors therefore remain diagnosable.\r\n\r\nUse the repository-defined Linux interpreter or `python3`. The image places the installed PlatformIO venv first in PATH so repository tools have its dependencies (including pyserial). Relative repository venv `bin/python*` symlinks may target only the runtime-owned /usr/bin/python3 family outside the workspace; executable parent directories must remain inside the workspace. Other external executable symlinks remain denied. Git/Docker commands and protected metadata remain outside Software Engineer authority.\r\n","readmeFilename":"README.md"}