Atlas / MCP servers / luckeyfaraday / Agentloop

AgentloopSAFE

mcp/luckeyfaraday/agentloop

MIT-licensed, backend-agnostic AI agent orchestration loop in Python: orchestrator→worker→reviewer as a deterministic harness. Drive coding-agent backends through an MCP server + CLI.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 3r · 5w · 0d
Transport
—
License
MIT
Stars
60
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE)

agentloop is a lightweight Python framework for multi-agent orchestration. It implements the orchestrator → worker → reviewer pattern (the AI agent orchestration loop) as a deterministic harness with a closed feedback loop: a goal is decomposed into subtasks, fanned out to worker subagents, aggregated, and run through a review gate that loops until the work meets its success criteria. One loop drives any LLM backend — Anthropic Claude, Claude Code, Codex, opencode, or aider — through a single Agent interface, and it ships as both an MCP server and a plain CLI so any coding agent can call it.

The design principle: the loop is a harness (deterministic code), not a skill. A prompt can describe "decompose, review, loop until done" but can't guarantee it. So the control flow lives in code, and the model-facing judgement (how to decompose, the review rubric) lives in swappable prompts. One harness drives any backend through a single Agent interface.

The tweet that started it all — Peter Steinberger (@steipete): "You shouldn't be prompting coding agents anymore. You should be designing loops that prompt your agents." agentloop is that idea as a reusable harness.
┌──────────── harness (this package) ────────────┐
goal ─▶ decompose ─▶ fan-out to subagents ─▶ aggregate ─▶ review gate ─▶ done?
▲                                                          │ no
└──────────────── feedback: refine plan ◀──────────────────┘

Quick start

python3 -m examples.run_demo        # zero-dependency MockAgent
python3 -m pytest                   # full test suite, no deps
from agentloop import Orchestr
Read from source at commit 945001dc2adeOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentloop --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env XAI_API_KEY=${XAI_API_KEY} -- uvx agentloop
claude-desktop
{
  "mcpServers": {
    "agentloop": {
      "command": "uvx",
      "args": [
        "agentloop"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "XAI_API_KEY": "${XAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

3 read · 5 write · 0 destructive.

ToolRiskDescription
doctorreadDiagnose this MCP server and worker backend availability without running agents.
list_backendsreadList worker backends this server can drive.
orchestratewriteRun an orchestrator -> worker -> reviewer loop until the success
orchestrate_listwriteList every detached run this server has started, with its status.
orchestrate_resultwriteFetch the final result of a detached run.
orchestrate_resumewriteResume a run whose intake paused with stop_reason
orchestrate_statuswriteLight status of a detached run: phase, current iteration, whether it is
orchestrate_tailreadRead what the loop has done since `cursor` — the live window into a
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
agentloop/cli.py:78
print(f"\ntoken: {result['token']}")
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:77
curl -fsSL https://x.ai/cli/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 945001dc2adefull audit observations/trust-audit/mcp-server/luckeyfaraday__agentloop.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08945001dc2adeSAFEB89first audit
06

Questions

What is the Agentloop MCP server?

MIT-licensed, backend-agnostic AI agent orchestration loop in Python: orchestrator→worker→reviewer as a deterministic harness. Drive coding-agent backends through an MCP server + CLI.

What tools does Agentloop expose?

8 in total: 3 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agentloop safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Agentloop need?

It reads ANTHROPIC_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (945001dc2ade), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement