Skip to main content
Glama
ArtemKyslicyn

aichallenge-mcp-kit

aichallenge-mcp-kit

Hierarchical MCP hub for your machine. One Streamable HTTP /mcp + Bearer token. Attach child MCPs (filesystem, git, montage, …), run sandboxed Python, move files via /artifacts, then paste the tunnel URL into AIChallenge → Свой MCP.

AIChallenge never runs these processes. This kit never talks to the site database. The site only sees one URL + one token.

Architecture: chat → tunnel → hub → groups / artifacts

Why a separate public repo?

Site

Guest MCP client (SSRF-safe, chat tools)

This kit

Your PC: hierarchy, sandbox, big files

Stdio MCP servers cannot be reached from a cloud chat. The kit publishes them behind one HTTPS tunnel.

Related MCP server: ChatGPT Desktop Commander MCP

5-minute connect

Connect: clone → run → tunnel → Guest MCP

git clone https://github.com/ArtemKyslicyn/aichallenge-mcp-kit.git
cd aichallenge-mcp-kit
cp .env.example .env          # set KIT_SHARED_TOKEN (long random string)
cp kit.example.yaml kit.yaml  # enable the children you want
uv sync
uv run aichallenge-mcp-kit    # listens on 127.0.0.1:3100

In another terminal:

cloudflared tunnel --url http://127.0.0.1:3100

On the site (logged in): Свой MCP / Настройки → Подключения:

  • URL: https://<tunnel-host>/mcp

  • Token: same value as KIT_SHARED_TOKEN

Optional pack: packs/aichallenge-guest.example.json (replace the URL; never put the token in a shared pack file).

Full walkthrough: docs/connect-aichallenge.md.

What you get

  • Hierarchy: kit.yaml → groups → children. Tool names: {group}__{child}__{tool} (e.g. dev__python__exec).

  • Hub tools: hub_list_children, hub_workspace_list|put|get.

  • Python sandbox: dev__python__* — cwd under workspace/sandboxes/, network off by default.

  • Stdio / HTTP proxy: enabled children stay connected for the life of the process; tools are forwarded with prefixes.

  • Artifacts: large outputs via GET /artifacts/{id} with the same Bearer.

Python sandbox

Docs

Doc

Topic

docs/architecture.md

Hub, groups, naming

docs/connect-aichallenge.md

Tunnel + Guest MCP

docs/python-sandbox.md

Exec limits

docs/children.md

Adding stdio/HTTP children

docs/security.md

Tokens, sandbox, risks

Design origin (AIChallenge monorepo): docs/superpowers/specs/2026-09-28-mcp-kit-hub-design.md.

Requirements

  • Python 3.12+

  • uv recommended

  • cloudflared (or ngrok) for a public HTTPS URL

  • Optional: Node/npx for official filesystem MCP; uvx for git MCP

Security (read this)

Whoever has URL + Bearer can drive every enabled child and the Python sandbox on your machine (within workspace limits). Bind stays on loopback; only the tunnel is public. See docs/security.md.

License

MIT — see LICENSE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Lifts local stdio MCP servers into remote Streamable HTTP endpoints for cloud-hosted AI clients, with bearer-token auth and tool policy filtering.
    9 npm
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    A Python MCP server that allows ChatGPT to execute commands on your local PC via a secure Cloudflare tunnel.
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Exposes local stdio MCP servers to chat AIs through temporary public URLs, providing both a Streamable HTTP gateway and a REST+OpenAPI bridge for integration with ChatGPT and other clients.
    MIT