Atlas / MCP servers / zkzkgamal / Agentic AI Engineering

Agentic AI EngineeringCAUTION

mcp/zkzkgamal/agentic-ai-engineering

Agentic AI Engineering is a production-grade engineering resource for building modern agentic AI systems with LangChain, LangGraph, RAG, MCP, local models, and deployable Python services.

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
7 5r · 2w · 0d
Transport
sse
License
MIT
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/) [](https://langchain.com/) [](https://langchain-ai.github.io/langgraph/) [](LICENSE)

Agentic AI Engineering is a production-grade engineering resource for building modern agentic AI systems with LangChain, LangGraph, RAG, MCP, local models, and deployable Python services.

The repository leads toward the architecture implemented in Chapter 5: a multi-node LangGraph assistant connected to a standalone MCP server, with intent routing, tool execution, response summarization, email tooling, math tools, automated tests, and GitHub Actions CI. Earlier chapters build the required layers underneath it: provider abstraction, LCEL orchestration, vector retrieval, memory, ReAct agents, router graphs, sequential workflows, multi-agent collaboration, and human-in-the-loop control.

This is not a beginner chatbot walkthrough. It is a structured engineering path for developers building systems that need state, tools, routing, retrieval, observability, modularity, and model-provider flexibility.

What You'll Build

  • Multi-node LangGraph assistant with router, execution, summarization, and conversation nodes.
  • MCP tool server exposing isolated math and email tools over a decoupled server boundary.
  • Tool-using ReAct workflows that call external capabilities through typed tool contracts.
  • RAG pipelines using vector stores, embeddings, retrieval chains, and local document context.
  • Provider-flexible LLM interfaces across OpenAI, Gemini, and Ollama.
  • Agent routing systems for sequential, router-based, ReAct, and multi-agent workflows.
  • **Human-in-the-loop executio
Read from source at commit d259ded0a236OBSERVED · 2026-10-08
02

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
addwriteAdd any number of arguments.
check_inboxreadFetch recent emails from inbox. Returns list of dicts with subject, from, body snippet.
draft_replyreadGenerate a draft email reply (uses LLM internally if needed, but simple here).
multiplyreadMultiply any number of arguments.
read_emailreadRead a specific email by its ID.
reply_to_emailreadReply to a specific email by its ID.
send_emailwrite
03

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Chapter2/chapter2-code.ipynb:258
"    base_url=\"http://127.0.0.1:11434\",\n",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Chapter2/chapter2-code.ipynb:679
"    base_url=\"http://127.0.0.1:11434\",\n",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Chapter4/chapter4-code.ipynb:261
"    base_url=\"http://127.0.0.1:11434\",\n",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Chapter4/chapter4-code.ipynb:455
"    base_url=\"http://127.0.0.1:11434\",\n",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Chapter4/chapter4-code.ipynb:1339
"    base_url=\"http://127.0.0.1:11434\",\n",
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
Chapter1/requirements.txt
openai, google-genai, ollama, python-dotenv, pydantic, tiktoken
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
Chapter2/requirements.txt
openai, google-genai, ollama, python-dotenv, pydantic, tiktoken, langchain, langchain-openai
Why it matters. 12 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
Chapter3/requirements.txt
openai, google-genai, ollama, python-dotenv, pydantic, tiktoken, langchain, langchain-openai
Why it matters. 14 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
Chapter4/requirements.txt
openai, google-genai, ollama, python-dotenv, pydantic, tiktoken, langchain, langchain-openai
Why it matters. 17 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
Chapter5/SimpleChatAgent/AganticAssistant/requirements.txt
mcp, ollama, httpx, openai, google-genai, ollama, python-dotenv, pydantic
Why it matters. 22 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
Chapter5/SimpleChatAgent/README.md:75
1. **Security & Isolation**: The LLM agent (the "brain") never has direct access to your email passwords or file system. It only communicates with the MCP server via strict HTTP Server-Sent Events (SS
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
Chapter5/SimpleChatAgent/demo/githubCIAction.webm.mp4
Chapter5/SimpleChatAgent/demo/githubCIAction.webm.mp4
Why it matters. 4224783 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
Chapter5/SimpleChatAgent/demo/pytestChapter5.mp4
Chapter5/SimpleChatAgent/demo/pytestChapter5.mp4
Why it matters. 3581927 bytes not read
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
Chapter5/SimpleChatAgent/AganticAssistant/README.md:34
4. **`conversation.py` (The Chitchat Fallback)**: If the user just says "Hello," we skip `execute` and `summarize` entirely. This node feeds the conversation history to the LLM for a direct response,
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
Chapter5/SimpleChatAgent/README.md:75
1. **Security & Isolation**: The LLM agent (the "brain") never has direct access to your email passwords or file system. It only communicates with the MCP server via strict HTTP Server-Sent Events (SS
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d259ded0a236full audit observations/trust-audit/mcp-server/zkzkgamal__agentic-ai-engineering.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d259ded0a236CAUTIONB84first audit
05

Questions

What is the Agentic AI Engineering MCP server?

Agentic AI Engineering is a production-grade engineering resource for building modern agentic AI systems with LangChain, LangGraph, RAG, MCP, local models, and deployable Python services.

What tools does Agentic AI Engineering expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agentic AI Engineering safe to connect to an agent?

With care. The audit graded it B (84/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Agentic AI Engineering need?

No credential environment variables were found in its source, so it appears to need none.

How does Agentic AI Engineering run?

It speaks sse, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (d259ded0a236), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement