AlMoutmag 1.1

AlMoutmag 1.1

Enables cloud AI agents to securely connect to a local Windows machine and execute tools such as system info, file operations, browser automation, and coding tasks through the Model Context Protocol.

Category
访问服务器

README

AlMoutmag 1.1

AlMoutmag 1.1 — Secure MCP (Model Context Protocol) bridge between cloud AI agents (z.ai / Claude / Cursor) and the local Windows machine.

AlMoutmag 1.1 — جسر آمن بين وكلاء الذكاء الاصطناعي السحابيين (z.ai / Claude / Cursor) وجهاز Windows المحلي، عبر بروتوكول MCP.

Backwards-compatible with 1.0 clients — the /v12/health alias and the 1.0 OAuth/DPoP flow are unchanged. See CHANGELOG sections below for what 1.1 adds.

CI Python License: MIT MCP Version Tests


English

What it is

AlMoutmag 1.1 is a Python 3.12+ server that runs on Windows 11 and exposes a local MCP (Model Context Protocol) endpoint. Cloud AI agents (z.ai / Claude / Cursor, running on Linux) connect to it through a Cloudflare Tunnel and execute tools on the user's machine — system info, file operations, browser automation, computer use, 40+ coding tools, etc. — with results returned to the AI.

It is security-first by design: 10 protective layers, deny-by-default tool allowlists, tamper-evident audit log, file-integrity monitor with kill switch, OAuth 2.1 + DPoP token binding, and structured JSON logging.

What's new in 1.1 — see the v1.1 New Features section below for the full list. Highlights: 40+ coding tools, @cached_tool performance layer, SSE streaming for long-running tools, a live-coding WebSocket, Unix-pipe-style tool composition, and background jobs.

Architecture

┌──────────────┐    Cloudflare Tunnel    ┌─────────────────┐
│  z.ai / GLM  │ ◄──────────────────────►│  AlMoutmag 1.1  │
│  Claude      │   MCP Streamable HTTP   │  (Windows 11)   │
│  Cursor      │   OAuth 2.1 + DPoP      │                 │
└──────────────┘                          └────────┬────────┘
                                                   │
                                          ┌────────┴────────┐
                                          │  Tool registry  │
                                          │  (31 categories)│
                                          │  350+ tools     │
                                          └────────┬────────┘
                                                   │
                                          ┌────────┴────────┐
                                          │ Windows machine │
                                          │ (files, apps,   │
                                          │  browser, code) │
                                          └─────────────────┘

Quick start

# 1. Clone and create venv
git clone https://github.com/USERNAME/almoutmag-1.0.git
cd almoutmag-1.0
python -m venv venv
.\venv\Scripts\Activate.ps1

# 2. Install dependencies
pip install -e ".[dev]"
playwright install chromium

# 3. Generate OAuth keys (Ed25519)
python scripts/gen_keys.py

# 4. Copy config and edit
Copy-Item config.yaml.example config.yaml
Copy-Item .env.example .env
# Edit config.yaml — set dev_mode: true for first run

# 5. Run dev server
python scripts/dev_start.py
# Server now listening on http://127.0.0.1:8452
# dev_token is printed to stderr — export it:
#   $env:ALMOUTMAG_DEV_TOKEN="<paste token>"

In dev_mode, you can now use Bearer instead of DPoP (1.1 shortcut — useful for local curl/PowerShell scripts). Production traffic still requires DPoP <token> + the DPoP proof header:

# In dev_mode, you can now use Bearer instead of DPoP:
curl -H "Authorization: Bearer $ALMOUTMAG_DEV_TOKEN" http://127.0.0.1:8452/info

# Production path is unchanged (OAuth 2.1 + DPoP):
curl -H "Authorization: DPoP $ACCESS_TOKEN" -H "DPoP: $DPoP_PROOF" \
  http://127.0.0.1:8452/info

MCP endpoints

Endpoint Method Description
/mcp POST MCP JSON-RPC 2.0 (initialize, tools/list, tools/call, ...)
/auth/token POST OAuth 2.1 token endpoint (DPoP-bound)
/auth/revoke POST Revoke access/refresh token
/auth/protected-resource GET RFC9728 metadata
/execute POST Execute single tool (REST)
/execute/stream POST SSE stream of tool output (v1.1)
/batch POST Execute multiple tools (REST)
/workflow POST Execute multi-step workflow
/tools GET List all tools
/openapi.json GET OpenAPI 3.1 spec
/docs GET Swagger UI
/health GET Liveness (no auth, includes tools_loaded)
/health/ready GET Readiness (no auth)
/metrics GET Prometheus metrics
/ws/monitor WS Real-time CPU/RAM/disk
/ws/events WS File/process/network events
/ws/audit WS Live audit log stream
/ws/code_session WS Live coding session (v1.1)

v1.1 New Features (Coding Tools + Performance)

The 1.1 release turns AlMoutmag into a powerful programming assistant on the user's Windows machine, while preserving every 1.0 behaviour.

Feature Where What it does
40+ coding tools docs/CODING_TOOLS.md Code reading, writing, execution, git, analysis, debugging, documentation. Defined in tools/ai/coding.py.
Caching layer core/registry.py @cached_tool Per-tool TTL cache. Inspect via cache_stats, clear via cache_clear (tools/system/cache.py).
SSE streaming POST /execute/stream Server-Sent Events stream of tool output — emits start, complete, error, blocked events. Ideal for code_run_python, code_run_tests, git_log.
WebSocket live coding WS /ws/code_session Per-session tempdir + write_file / read_file / list_files / run / close actions. Isolated and cleaned up on disconnect.
Tool composition tools/workflows/pipes.py pipe_run chains tools Unix-pipe-style (output of step N → _input of step N+1). filter_field and sort_by_field are post-processing steps.
Background jobs tools/workflows/background_jobs.py job_start_background, job_status, job_result, job_cancel, job_list — fire-and-poll for long-running tools.
Bearer dev shortcut server/middleware.py In dev_mode, Authorization: Bearer $DEV_TOKEN bypasses the DPoP proof requirement. Production traffic is unaffected.
tools_loaded field GET /health Health response now reports whether the tool registry finished loading.
AppKey migration core/auth.py Existing 1.0 AppKey clients continue to work; migration is automatic on first token refresh.
213 LIVE tests tests/test_coding.py (+49) Up from 164 in 1.0. All tests are LIVE HTTP — no static grep assertions.

See docs/CODING_TOOLS.md for the full tool reference with example MCP requests/responses for every tool.

Dependencies (12 — strict)

Package Purpose
fastmcp MCP server framework
aiohttp HTTP server + WebSocket
aiosqlite Async SQLite (audit log)
cryptography AES-256-GCM, Ed25519, HMAC
pydantic Settings + validation
structlog Structured JSON logging
psutil System info
pyyaml YAML config
pywinauto Windows UI automation
playwright Browser automation
Pillow Image processing
pytesseract OCR

Dev: pytest, pytest-asyncio, ruff, mypy, pyinstaller.

Tests

python -m pytest tests/ -v
python -m ruff check .
python -m mypy core/ server/

All tests are LIVE integration tests — they send real HTTP requests to a aiohttp.test_utils.TestClient instance. No static grep tests.

213 passed (up from 164 in 1.0 — the 49 new tests cover the coding tools, caching, SSE stream, WebSocket code session, pipe_run, and background jobs in tests/test_coding.py).

Documentation

Build .exe

python scripts/build_exe.py
# Output: dist/AlMoutmag.exe

العربية

ما هو AlMoutmag 1.1؟

خادم Python 3.12+ يعمل على Windows 11 ويوفّر نقطة نهاية MCP محلية. يتصل به وكلاء الذكاء الاصطناعي السحابيون (z.ai / Claude / Cursor، العاملون على Linux) عبر نفق Cloudflare Tunnel، وينفّذون أدوات على جهاز المستخدم — معلومات النظام، عمليات الملفات، أتمتة المتصفح، التحكم بالحاسوب، أكثر من 40 أداة برمجة، إلخ — وتُعاد النتائج للـ AI.

متوافق تماماً مع إصدار 1.0 (نقطة /v12/health ومسار OAuth/DPoP لم يتغيّرا).

الجديد في 1.1 — 40+ أداة برمجة، طبقة تخزين مؤقت @cached_tool، بث SSE للأدوات طويلة التشغيل، WebSocket للبرمجة الحيّة، تركيب الأدوات بطريقة pipe، والمهام في الخلفية. التفاصيل في docs/CODING_TOOLS.md.

مبني بالأمان أولاً بالتصميم: 10 طبقات حماية، قوائم سماح deny-by-default، سجل تدقيق tamper-evident، مراقب سلامة الملفات مع kill switch، ربط OAuth 2.1 + DPoP، وسجلّات JSON منظمة.

البنية

┌──────────────┐    Cloudflare Tunnel    ┌─────────────────┐
│  z.ai / GLM  │ ◄──────────────────────►│  AlMoutmag 1.0  │
│  Claude      │   MCP Streamable HTTP   │  (Windows 11)   │
│  Cursor      │   OAuth 2.1 + DPoP      │                 │
└──────────────┘                          └────────┬────────┘
                                                   │
                                          ┌────────┴────────┐
                                          │  سجل الأدوات    │
                                          │  (30 فئة)       │
                                          └────────┬────────┘
                                                   │
                                          ┌────────┴────────┐
                                          │  جهاز Windows   │
                                          │  (ملفات، تطبيقات│
                                          │   متصفح، ...)   │
                                          └─────────────────┘

البدء السريع

# 1. استنساخ وإنشاء venv
git clone https://github.com/USERNAME/almoutmag-1.0.git
cd almoutmag-1.0
python -m venv venv
.\venv\Scripts\Activate.ps1

# 2. تثبيت التبعيات
pip install -e ".[dev]"
playwright install chromium

# 3. توليد مفاتيح OAuth (Ed25519)
python scripts/gen_keys.py

# 4. نسخ الإعدادات وتعديلها
Copy-Item config.yaml.example config.yaml
Copy-Item .env.example .env
# عدّل config.yaml — اضبط dev_mode: true لأول تشغيل

# 5. تشغيل خادم التطوير
python scripts/dev_start.py
# الخادم يستمع على http://127.0.0.1:8452

طبقات الأمان العشر

  1. OAuth 2.1 + DPoP — ربط الـ token بمفتاح Ed25519 من العميل
  2. 5 مستويات danger_level (0=public، 4=دائماً مرفوض)
  3. Safety Layer — deny by default، 60+ أمر آمن فقط
  4. Audit Log — SQLite WAL + AES-256-GCM + HMAC-SHA256 chain
  5. FIM — مراقب سلامة الملفات + kill switch (os._exit(99))
  6. Rate Limiting — 100/دقيقة per IP، 1000/ساعة per token
  7. Anomaly Detection — تنبيه عند 3x، حظر عند 5x
  8. Honeytokens — مفاتيح وهمية للكشف عن الاختراق
  9. Network Security — localhost فقط افتراضياً، Cloudflare Tunnel اختياري
  10. Request ID + Structured Logging — UUID لكل طلب + إخفاء الـ secrets

الاعتماديات (12 فقط — صارم)

الحزمة الغرض
fastmcp إطار خادم MCP
aiohttp خادم HTTP + WebSocket
aiosqlite SQLite غير متزامن (سجل التدقيق)
cryptography AES-256-GCM، Ed25519، HMAC
pydantic الإعدادات + التحقق
structlog سجل JSON منظّم
psutil معلومات النظام
pyyaml إعدادات YAML
pywinauto أتمتة واجهة Windows
playwright أتمتة المتصفح
Pillow معالجة الصور
pytesseract OCR

للتطوير: pytest، pytest-asyncio، ruff، mypy، pyinstaller.

الاختبارات

python -m pytest tests/ -v
python -m ruff check .
python -m mypy core/ server/

كل الاختبارات حيّة (LIVE) — ترسل طلبات HTTP فعلية عبر aiohttp.test_utils.TestClient. 213 ناجح (مقابل 164 في 1.0 — 49 اختباراً جديداً في tests/test_coding.py).

التوثيق

بناء .exe

python scripts/build_exe.py
# الناتج: dist/AlMoutmag.exe

المُحرّمات (18)

انظر docs/SECURITY.md للقائمة الكاملة. أبرزها:

  • لا AI/LLM محلي
  • لا subprocess مع shell=True
  • لا eval()/exec() على مدخلات المستخدم بدون sandboxing
  • لا danger_level=4 قابل للتجاوز
  • لا middlewares بدون @web.middleware decorator
  • لا اختبارات static grep فقط (كلها LIVE HTTP)
  • لا dependencies إضافية خارج الـ 12 المحددة

License

MIT — © 2026 AlMoutmag Team

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选