Skip to content
Model Context Protocol · Docs

MCP Tools

Model Context Protocol servers provisioned into Frontal's agent sandboxes. Every capability an agent can touch is explicitly provisioned, never implicit — discoverable, auditable, and isolated by default.

Foundations

What is MCP?

An open standard for connecting LLM agents to the outside world — and Frontal's only door in.

MCP (Model Context Protocol) is an open standard for giving LLM agents access to external tools, data sources, and capabilities. Frontal uses MCP servers as the ONLY way agents access tools — every capability is explicitly provisioned, never implicit.

Agents communicate with MCP servers over stdio using JSON-RPC. The Pi engine discovers a server's tools via tools/list, calls them via tools/call, and hot-reloads new servers without restarting the session.

Architecture

How an agent reaches a tool.

Four hops, all inside the sandbox. The agent never touches the host directly.

Agent Session → Pi Engine → stdio JSON-RPC → MCP Server (sandboxed)
Tool Execution · inside Docker · default-deny egress
WIRE FORMAT

JSON-RPC over stdio. Pi is the only process that speaks it — isolated in pi_adapter.py.

DISCOVERY

Servers are written into .mcp.json inside the worktree. Pi hot-reloads via /reload.

ISOLATION

Provisioned servers run INSIDE the Docker sandbox — never on the host. The agent, the engine, and the tool share one container.

Built-in MCP Servers

Two servers. Always on.

Frontal injects these automatically — no configuration required. They are the agent's memory and its lifeline to you.

frontal-memory

Always included

Auto-attached when ArangoDB is available.

Gives agents access to the Context Engine — decisions, constraints, contracts, code symbols, and gotchas touching their task's file scope. Without this, every task starts from scratch.

Tool Description
memory.get_context_pack(task_id) Re-fetch the budgeted context pack for the current task. ~2,000 tokens.
memory.search(query, filters) BM25 hybrid search over Note / Evidence / Decision nodes. Type and plane filters available.
memory.expand(node_id) Retrieve L2 full content of a specific node by reference.
memory.propose_note(content, links) Propose a durable note. The pipeline validates, deduplicates, and inserts via the event log.

frontal-ask-user

Always included

Auto-attached for sessions that may need clarification.

Allows agents to ask the user a clarifying question when requirements are ambiguous. Blocking — waits up to 600 seconds for an answer.

Tool Description
ask_user(question, options?, default?) Ask the user a clarifying question. Returns the answer or the default on timeout.
REQUEST FLOW
Pi calls tool → POST /api/internal/ask → SSE → Frontend → User answers → Response → Pi
Discovery & Provisioning

Dynamic MCP servers, on demand.

How a task gets a new tool mid-flight — five steps, no session restart.

01

Search the registry

The intent is matched against mcp.1mcpserver.com — 2,480+ indexed servers.

$ GET /api/discovery/search?intent=fetch+live+currency+rates
02

Provision the chosen server

POST the server config. Frontal validates the container image and tool schema.

$ POST /api/discovery/provision
03

Write the bridge config

mcp_bridge writes .mcp.json into the sandbox worktree.

.mcp.json written
04

Resolve secrets at exec time

mcp_launcher pulls vault secrets into the subprocess env ONLY — never into .mcp.json.

vault:// resolved
05

Hot-reload — tool is live

Pi reloads via /reload. The agent gets the new tool immediately, mid-session.

tool available
Trust & Security

Provisioned does not mean trusted.

Every MCP server is treated as untrusted code running in a hostile boundary. Five layers hold the line.

Registry trust policy

Only official/verified registry entries are auto-installable by default. Unverified servers require explicit user approval via the Needs-Attention flow.

Version pinning

Versions are pinned at install time. No floating latest — a server that worked when you approved it keeps working the same way.

Audit chain

Every tool_installed event is appended to the HMAC-chained event log. You can reconstruct exactly which tools ran, when, and why.

Sandbox isolation

Provisioned MCP servers run INSIDE the Docker sandbox, not on the host. Default-deny egress; the agent, engine, and tool share one sealed container.

Secret handling

D-017

Secrets are resolved from the encrypted vault into the launcher environment at exec time ONLY. They never appear in:

  • .mcp.json files
  • Logs
  • Event log
  • Memory graph
  • Pi context / prompts
Bring Your Own

Add a custom MCP server.

Point Frontal at any container image. Secrets use vault:// references — resolved at exec time, never stored in plaintext.

provision a custom server
curl -X POST http://localhost:8400/api/discovery/provision \
  -H "Content-Type: application/json" \
  -d '{
    "project_id": "proj_abc123",
    "name": "my-custom-server",
    "container": "my-registry/mcp-server:1.0",
    "env": {
      "API_KEY": "vault://my-api-key"
    },
    "tools_schema": { ... }
  }'

Secrets use vault:// references — the launcher resolves them from the encrypted vault at exec time. The value never appears in the request body, the config file, or any log.

Cloud · Pro & Enterprise

500+ servers, ready out of the box.

Cloud users get the official registry pre-wired — no setup, no secret juggling.

Build your own

Want to build your own
MCP server?

The spec is open. The registry is public. Ship a tool, and every Frontal agent can use it.