uriel-tools
Enforces access control for MCP tools based on the caller's Authelia user groups, which are forwarded as metadata by the gateway.
Integrates with Nextcloud to index and search documents in opted-in folders, and enables reading, editing, signing, and managing documents within the caller's Nextcloud shares.
Uses SearXNG to perform web searches, returning results with title, URL, and snippet without fetching page content.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@uriel-toolssearch my documents for the water bill from March"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
uriel-tools
The MCP tool server behind Uriel, the local family
assistant. Each tool is gated by the caller's Authelia groups, which the gateway forwards as MCP _meta. See
docs/contract.md.
What the tools do and how to give Uriel your documents: docs/guide.md.
Versioned and released separately from uriel-agent. The code was imported from uriel-agent@5e476ef.
Develop
uv sync
uv run pytest # unit tests; DB tests skip without a database
docker run -d --rm --name uriel-tools-test-pg -e POSTGRES_PASSWORD=test -p 55442:5432 pgvector/pgvector:pg17
URIEL_TEST_DATABASE_URL=postgresql://postgres:test@localhost:55442/postgres uv run pytest -m "db or not db"
uv run ruff check . && uv run ruff format --check .Models come from the deployment-wide models.yaml in uriel-agent's config/ (one file for every process; each
reads only its roles). The local compose mounts it from a sibling ../uriel-agent checkout; set
URIEL_SHARED_CONFIG to point elsewhere.
Processes, all from one image: python -m uriel_tools (MCP, 8001), python -m uriel_tools.events (webhooks,
8002) and python -m uriel_tools.indexer (job worker).
End to end (fake Nextcloud, stub models, no GPU): see deploy/compose.e2e.yaml and CI's Compose e2e step.
Against your real Nextcloud:
Put
URIEL_NC_APP_PASSWORD=<the uriel account's app password>in.env. It's in Vaultwarden,Homelab/ "Nextcloud: uriel", in the "app password (uriel-tools indexer)" field.Share a folder with
uriel(or withuriel-family) in Nextcloud.Run
docker compose -f deploy/compose.yaml up -d --build.
The indexer lists the shares at startup and every 5 minutes. Webhooks can't reach your machine, so use
scripts/send-test-webhook.sh <owner> <path> (any path of a sharing owner re-checks their folders), or wait for
the next poll.
Related MCP server: Sentinel Core Agent
Release
Push a bare-semver tag (0.3.0). CI builds and pushes git.example.com/anthony-headband/uriel-tools:<tag>
and prints the digest. Then bump the pin in uriel-agent's deploy/compose.yaml and in homelab-apps.
Tools
tool | groups | status |
| admins | stub |
| family | stub |
| family | hybrid search over opted-in Nextcloud folders |
| family | reads one of the caller's scans now instead of overnight |
| family | a document's form fields, signature fields, and whether edits can be saved |
| family | fills a PDF form (fields, or beside labels on flat forms) into an |
| family | text changes and notes in Word/LibreOffice/text/PDF, saved as an |
| family | places the caller's own signature image after confirmation |
| family | marks an |
| family | drafts recurring work for the caller, then creates it after a yes |
| family | the caller's schedules, their runs, stopping one, their timezone |
| family | SearXNG results (title, url, snippet), no page fetching |
| uriel-internal | hidden: the gateway's runner claims and reports scheduled runs |
This server cannot be deployed
Maintenance
Related MCP Connectors
Gateway between LLM agents and world data through eight tools and a bundled endpoint catalog.
Runtime permission, approval, and audit layer for AI agent tool execution.
Your org's AI agents, tasks, runs, search, and brain files as MCP tools and resources.
Securely search and manage workspace context files for AI agents and teams.
Related MCP Servers
- AlicenseAqualityCmaintenanceProvides filesystem, web search, SQLite, and system tools for AI assistants like Claude, enabling secure access to local resources and the web.6MIT
- FlicenseNot gradedqualityDmaintenanceEnables file system operations, web scraping, and AI-powered search through MCP tools for use by LLM agents.1-
- AlicenseNot gradedqualityCmaintenanceExposes standard MCP tools for secure calculation, knowledge-base retrieval, document statistics, and sensitive operations like email, export, and deletion with human-in-the-loop approval.MIT
- FlicenseAqualityDmaintenanceEnables an LLM agent to search files, list directories, read and write UTF-8 text files, move or delete paths, list terminal processes, and launch a terminal in a chosen folder.8-