Emisar
Give AI agents Zero-Trust access to production infrastructure without the risks of granting them shell access. Actions are bounded by policy and an on-host runner.
README
emisar
Leave the agent working. Keep production authority bounded.
emisar gives MCP-capable agents a catalog of declared infrastructure actions instead of a shell. Policy decides what runs, what waits for a person, and what is denied. A small outbound-only runner checks the action again on the host before it executes anything.
Start with the public pack catalog, let emisar suggest the packs that match a host, and add your own actions without adding another MCP server to every client.
Start with one host
You need an emisar account, a Linux host with
systemd and sudo, and outbound HTTPS access to emisar.dev:443. You do not
open an inbound port on the host.
-
In the dashboard, choose Connect a runner. Copy the generated command; it contains a fresh, single-use enrollment key.
-
Run it on the host:
curl -sSL https://emisar.dev/install.sh \ | sudo EMISAR_ENROLLMENT_KEY=emkey-enroll-... EMISAR_URL=https://emisar.dev bashThe installer verifies the release checksum, creates the service, installs host-matched starter packs, and starts the runner.
-
Confirm the runner is online in the dashboard, then dispatch
linux.uptimewith a reason. You are done when the output appears and the run is present in the audit trail. -
Open LLM agents and connect your client. Remote MCP clients use OAuth; local stdio clients can use the
emisar-mcpbridge and its browser approval flow.
The complete walkthrough, including expected output and troubleshooting, is at
emisar.dev/docs/quickstart. An agent can
perform and certify the setup with the public
install-emisar skill.
How an action runs
AI client
| MCP: discover actions, request one with typed arguments
v
emisar control plane
| authenticate, scope, apply policy, wait for approval when required
v
outbound-only runner
| verify pack hash, validate arguments, enforce local limits
v
declared host command
stream redacted output, journal the attempt, update fleet audit
The action pack is the contract. It fixes the executable, argv shape, argument schema, risk, timeout, output limits, redaction, and side-effect description. The model selects from that contract; it does not invent a command line for the runner to execute.
Adding a pack adds capabilities behind the same MCP surface. Operators do not need to deploy another tool server or reconfigure every agent when the catalog changes.
What holds the boundary
- No inbound runner listener. The runner dials the control plane over a TLS websocket.
- Declared actions only. Cloud input is limited to typed, schema-bounded arguments. The runner rejects unknown actions and arguments.
- Content-addressed packs. The control plane pins the trusted pack hash; the runner recomputes it from disk before execution. New or changed custom packs wait for trust.
- Policy before side effects. Runner scope, risk policy, action overrides, standing grants, and conditional approval are evaluated before dispatch.
- Host-side enforcement. The runner clamps execution options to the pack's limits, runs the declared binary and argv, and redacts output before it leaves the host.
- Two records. The control-plane audit includes denied and pending requests; every runner also writes its execution attempts and local refusals to a hash-chained JSONL journal.
- Optional client-attested dispatch. A runner can require an Ed25519 intent signed by the MCP client, so the control plane cannot originate or widen a permitted call.
Read the exact guarantees, limitations, and threat model in
docs/security-model.md.
What emisar is not
- It is not a sandbox or process isolator. We recommend using one, such as coop.
- It is not a generic
execute(command)tool or a replacement for SSH. - It does not replace OS least privilege, change management, or configuration management.
- It does not make a permitted destructive action harmless. The safety boundary is only as strong as the actions, pack trust, policy, runner configuration, and host permissions in use.
The staging-only shell pack is the explicit break-glass exception to the
declared-action model. It is critical-risk, default-denied, never suggested,
and should not be installed on production runners.
Find the right surface
| Goal | Start here |
|---|---|
| Install, upgrade, harden, or diagnose a host | runner/README.md |
| Connect Claude, ChatGPT, Cursor, Codex, or another MCP client | Connect an LLM |
| Inspect or develop the stdio bridge | mcp/README.md |
| Browse, install, or author action packs | packs/README.md |
| Let an agent install emisar, connect a client, or author a pack | skills/README.md |
| Review architecture and trust boundaries | docs/architecture.md |
| Review protocol contracts | docs/wire-protocol.md and docs/mcp-api-spec.md |
| Contribute to the control plane | portal/README.md |
| Review the production GCP infrastructure | infra/README.md |
Repository layout
portal/ Elixir/Phoenix control plane, operator console, website, and MCP API
runner/ Go host runner and operator CLI
mcp/ Go stdio-to-HTTP MCP bridge
packs/ Versioned action-pack catalog
skills/ Standalone customer skills for coding agents
infra/ Production Terraform for emisar on Google Cloud
tools/ Pack-authoring support, repository checks, and maintainer E2E drivers
docs/ Architecture, security, protocol, release, and distribution references
Each top-level project has its own AGENTS.md with its architecture, security
rules, and verification gate.
Develop locally
The root Compose stack starts PostgreSQL, the portal, seeded demo data, and three sample runners:
docker compose up --build
Open http://localhost:4010. See portal/README.md for
native Phoenix development and dev/README.md for the seeded
runner fixtures, pack harness, and signed-dispatch test stack.
License
This repository is dual-licensed:
runner/,mcp/, andpacks/are open source under the Apache License 2.0. You can inspect, build, package, and operate the on-host components independently.- Everything else, including
portal/, is source-available under the Business Source License 1.1. Non-production use is free. Production use is permitted only as needed to operate the Apache-licensed components or the hosted service under the Additional Use Grant; other production use requires a commercial license. Each version converts to Apache 2.0 on its Change Date.
See contributing, security,
and the CLA. For commercial licensing, contact
licensing@emisar.dev.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。