Agent OrchestratorBLOCK
A modular Python framework implementing the Model Context Protocol (MCP). It features a standardized client-server architecture over StdIO, integrating LLMs with external tools, real-time weather data fetching, and an advanced RAG (Retrieval-Augmented Generation) system.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/haohao-end-mcp-agent)
The MCP Agent Orchestrator is a professional-grade Python implementation of the Model Context Protocol (MCP). It provides a structured environment for Large Language Models (LLMs) to interact with external tools and knowledge bases through a standardized communication layer. The project utilizes FastMCP for server-side tool definitions and an asynchronous client-side bridge to OpenAI-compatible interfaces.
System Architecture
The project follows a decoupled client-server architecture:
- MCP Client: Acts as the orchestrator. It manages the lifecycle of the MCP server, performs tool discovery, handles LLM completions, and executes tool calls returned by the model.
- MCP Servers: Independent services (Weather, RAG) that expose specific functions to the client via the Model Context Protocol.
- Transport Layer: Uses Standard Input/Output (StdIO) for high-performance, local inter-process communication.
Core Components
1. Intelligent Client Bridge
The client implementation (rag_agent.py, client.py) facilitates:
- Asynchronous lifecycle management using
AsyncExitStack. - Automatic tool schema conversion for OpenAI-compatible function calling.
- Persistent conversation state and multi-turn reasoning loops.
2. Weather Service Server
The weather server (server.py) demonstrates real-time API integration:
- Integration with external REST APIs (WeatherAPI).
- Data normalization and formatting for LLM consumption.
- Asynchronous request handling using
httpx.
3. RAG Knowledge Server
The RAG server (rag_server.py) provides advanced document intelligence:
- Data Ingestion: Support for PDF and TXT formats using
LangChain. - Vector Database: Persistent storage via
ChromaDB. - Search Optimization: Implements Maximal Marginal Relevance (MMR) for
e65a84a45a8eOBSERVED · 2026-10-07Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
local_asearch | read | xxx |
query_weather | read | |
rag_query | read | response = rag.query(query) |
search_web | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
http_client=httpx.Client(verify=False)
create_final_communities.parquet
create_final_community_reports.parquet
create_final_documents.parquet
create_final_entities.parquet
create_final_nodes.parquet
print("api_key----------:",api_key)Gates applied: no_behavioural_pass, no_license.
e65a84a45a8efull audit observations/trust-audit/mcp-server/haohao-end__agent-orchestrator-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e65a84a45a8e | BLOCK | D | 69 | first audit |
Questions
What is the Agent Orchestrator MCP server?
A modular Python framework implementing the Model Context Protocol (MCP). It features a standardized client-server architecture over StdIO, integrating LLMs with external tools, real-time weather data fetching, and an advanced RAG (Retrieval-Augmented Generation) system.
What tools does Agent Orchestrator expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Agent Orchestrator safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Agent Orchestrator need?
It reads API_KEY and YDC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Agent Orchestrator run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (e65a84a45a8e), read on 2026-10-07. The repository is watched and re-audited when it changes.