Atlas / MCP servers / peakmojo / Agentic Client

Agentic ClientBLOCK

mcp/peakmojo/agentic-client

A standalone agent runner that executes tasks using MCP (Model Context Protocol) tools via Anthropic Claude, AWS BedRock and OpenAI APIs. It enables AI agents to run autonomously in cloud environments and interact with various systems securely.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A standalone agent runner that executes tasks using MCP (Model Context Protocol) tools via Anthropic Claude, AWS BedRock and OpenAI APIs. It enables AI agents to run autonomously in cloud environments and interact with various systems securely.

Current Features

  • Included a basic agent dashboard
  • Run standalone agents with tasks defined in JSON configuration files
  • Support for both Anthropic Claude and OpenAI models
  • Session logging for tracking agent progress

Run Dashboard Web

cd dashboard
npm i
npm run dev

Dashboard URL: http://localhost:3000 API Documentation: http://localhost:3000/api-docs

https://github.com/user-attachments/assets/c98be6d2-0096-40f2-bd78-d3fb256fec83

Installation

  1. Clone the repository
  1. Set up dependencies:
uv sync
  1. Create an agent_worker_task.json file

Here is an example configuration file:

{
"task": "Find all image files in the current directory and tell me their sizes",
"model": "claude-3-7-sonnet-20250219",
"system_prompt": "You are a helpful assistant that completes tasks using available tools.",
"verbose": true,
"max_iterations": 10
}
  1. Run the agent:
uv run agentic_mcp_client/agent_worker/run.py

Configuration

The project requires a config.json file in the root directory to define the inference server settings and available MCP tools. Here's an example configuration:

{
"inference_server": {
"base_url": "https://api.anthropic.com/v1/",
"api_key": "YOUR_API_KEY_HERE",
"use_bedrock": true,
"aws_region": "us-east-1",
"aws_access_key_id": "YOUR_AWS_ACCESS_KEY",
"aws_secret_access_key": "YOUR_AWS_SECRET_KEY"
},
"mcp_servers": {
"mcp-remote-macos-use": {
"command": "docker",
"args": [
"run",
Read from source at commit 894939e282f2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add dashboard -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dashboard": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
ConfigurationsreadAPI endpoints for configuration files
JobsreadAPI endpoints for managing agent worker jobs
SessionsreadAPI endpoints for accessing agent worker sessions
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dashboard/app/api/jobs/route.ts:189
const childProcess = exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/app/api/jobs/[jobId]/route.ts:4
import { JobStatus } from '../../../../types/job';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/app/api/jobs/route.ts:5
import { JobStatus } from '../../../types/job';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/app/api/sessions/[id]/route.ts:2
import { getSession } from '../../../../lib/sessions';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/app/api/sessions/route.ts:2
import { getAllSessions } from '../../../lib/sessions';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/app/api/swagger/route.ts:2
import { getApiDocs } from '../../../swagger';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
dashboard/package.json
@heroicons/react, @tremor/react, date-fns, next, next-swagger-doc, react, react-dom, react-markdown
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 894939e282f2full audit observations/trust-audit/mcp-server/peakmojo__agentic-client.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08894939e282f2BLOCKD69first audit
06

Questions

What is the Agentic Client MCP server?

A standalone agent runner that executes tasks using MCP (Model Context Protocol) tools via Anthropic Claude, AWS BedRock and OpenAI APIs. It enables AI agents to run autonomously in cloud environments and interact with various systems securely.

What tools does Agentic Client expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agentic Client safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Agentic Client need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (894939e282f2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement