EgyptAir MCP Server
Enables safe interaction with EgyptAir's operational data for managing flights, bookings, and compensation requests.
README
EgyptAir MCP Server
Overview
This project was developed as part of the Autonomous Agents – MCP Server Lab.
Our goal is to build a secure Model Context Protocol (MCP) server that allows an AI assistant to safely interact with EgyptAir's internal operational data without giving the language model direct access to the production database.
Instead of exposing SQL queries or shell commands, the server provides carefully designed business tools that perform validated and authorized operations.
The MCP server acts as a secure layer between the AI assistant and the database.
Architecture: LLM | ▼ MCP Client | ▼ EgyptAir MCP Server | ▼ SQLite Database
Company
EgyptAir is Egypt's national airline.
The company handles thousands of passenger bookings every day. Flight delays and cancellations often lead to customer compensation requests that must be reviewed by customer service employees and supervisors.
The objective of this project is to build an AI assistant that helps employees manage these operations safely through MCP.
Problem Statement
Without MCP, an LLM could generate arbitrary SQL queries directly against the production database, creating several risks:
- Invalid SQL queries
- Unauthorized data modification
- Prompt injection attacks
- Poor auditing
- Difficult monitoring
Instead of giving the LLM direct database access, this project exposes controlled business operations through an MCP Server.
The server handles:
- Authentication
- Authorization
- Validation
- Business rules
- Database operations
Project Structure
EgyptAir-MCP-Server/
│ ├── db/ │ ├── schema.sql │ ├── seed.sql │ ├── create_db.py │ ├── database.db │ ├── erd.mmd │ └── erd.png │ ├── mcp_server/ │ ├── app.py │ ├── server.py │ ├── database.py │ ├── config.py │ ├── authorization.py │ ├── validation.py │ ├── notifications.py │ └── tools/ │ ├── agent/ │ └── README.md
Database
SQLite was selected as the database engine because it is lightweight, portable, and easy to demonstrate during development.
The database contains the following entities:
- Employees
- Flights
- Passengers
- Bookings
- CompensationRequests
- Policies
- Reports
The complete Entity Relationship Diagram is available inside:
db/erd.png
Current MCP Tools
| Tool | Type | Purpose |
|---|---|---|
| get_flight_status | Read | Retrieve flight status |
| get_booking_details | Read | Retrieve booking information |
| get_compensation_policy | Read | Read compensation policy |
| submit_compensation_request | Write | Create a new compensation request |
| approve_compensation | Write | Approve or reject compensation |
| generate_disruption_report | Read | Generate disruption report |
| draft_passenger_email | Read | Draft passenger email |
Tool Classification
Read Tools
Read tools only retrieve information and do not modify database state.
Examples:
- get_flight_status
- get_booking_details
- get_compensation_policy
- generate_disruption_report
- draft_passenger_email
Write Tools
Write tools modify database information and require additional protection.
Examples:
- submit_compensation_request
- approve_compensation
Defensive Tool Design
Write tools are designed using secure business operations instead of exposing SQL queries to the LLM.
Security measures include:
- Parameterized SQL queries
- Server-side validation
- Authorization checks
- Business rule validation
- Structured responses
The LLM only interacts with predefined MCP tools and never executes raw SQL commands.
Validation
Validation is performed independently from MCP input schemas.
Examples:
- Verify booking exists
- Verify flight is eligible for compensation
- Verify requested amount is valid
- Verify compensation request exists
- Verify request is still pending before approval
Authorization
Only authorized employees can execute sensitive write operations.
Example:
- Customer Service → Submit compensation requests
- Supervisor / Manager → Approve compensation requests
Authorization is performed inside the MCP tool handler before any database modification.
Implemented Issue: Secure Compensation Approval Workflow
Issue
The approve_compensation tool was a high-risk write operation because it directly modified compensation requests.
The missing requirements were:
- Human confirmation before approval
- MCP notification after state changes
- Protection against accidental database updates
Solution 1: MCP Elicitation
Problem
Before implementation, the approval process updated the database immediately after authorization checks.
This could allow accidental approval of compensation requests.
Implementation
MCP Elicitation was added before the database update.
The workflow became:
Manager | approve_compensation() | Authorization Check | Request Validation | MCP Elicitation | User Confirmation | Database Update
The server asks the user for confirmation:
Example:
Are you sure you want to approve this compensation request?
Request ID: 8
Amount: $350
If the user confirms:
- Status becomes Approved
- approved_by is stored
If the user rejects:
- The operation is cancelled
- No database modification occurs
This ensures sensitive operations require explicit human approval.
Solution 2: MCP tools/list_changed Notification
Problem
After changing compensation status, connected clients needed a way to know that the server state had changed.
Implementation
After successful compensation processing, the server sends:
notifications/tools/list_changed
This allows MCP clients to refresh their available information and stay synchronized with server changes.
Implemented Issue: MCP Progress Tracking
Problem
The generate_disruption_report tool performs multiple database operations and may take time.
Previously, the client had no information about the current execution state.
Solution
MCP progress notifications were added.
The report generation now provides updates:
10% Starting report generation
30% Counting delayed flights
60% Counting cancelled flights
90% Calculating statistics
100% Report completed
After reaching 100%, the server returns the final report:
Contains:
- Delayed flights
- Cancelled flights
- Average delay
- Affected passengers
This improves user experience during long-running operations.
Current Progress
The following components have been completed:
- Project planning
- Company selection
- Problem definition
- Database schema
- Seed data
- SQLite database
- ERD
- MCP Server initialization
- Database connection layer
- Configuration module
- Validation module
- Authorization module
- Initial MCP tools
- Secure compensation approval workflow
- MCP Elicitation
- MCP tools/list_changed notification
- MCP Progress Tracking
Remaining Work
The following protocol features are still under development:
- Capability Negotiation
- Resources
- Prompts
- Sampling
- Streamable HTTP Transport
- Agent Integration
- Final Demonstration
Technologies
- Python
- SQLite
- FastMCP
- Model Context Protocol (MCP)
- LangChain (planned)
- JSON Schema
Team
- Marwan Ahmed
- Ahmed Ashraf
- Youssef Hatem
Note: This README represents the current development stage. Additional protocol features will be added as
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。