Skip to main content
Glama

NexusMCP — Production Stateless Model Context Protocol Gateway & Secure Tooling Suite

License: Apache 2.0 Python: 3.10+ MCP Protocol: 2026 Compliant Tests: 28 Passed Deterministic Web Dashboard: Built-in Docker: Hardened Non-Root

Stop letting autonomous coding agents execute dangerous commands on your production infrastructure.
NexusMCP is a production-grade, stateless Model Context Protocol (MCP) gateway that provides isolated AST code sandboxing, safe SQL circuit-breakers, and semantic token routing for Cursor, Windsurf, Claude Desktop, and autonomous LLM agents.


🖥️ Built-in Dark Cyber Web Dashboard

NexusMCP includes an out-of-the-box, zero-dependency Security Operations Center (SOC) Web Dashboard served directly on http://localhost:8080/:

  • Live Threat Intercept Ledger: Real-time telemetry monitoring blocked DROP TABLE queries, forbidden shell escapes, and unauthorized attribute visits.

  • Token Cost Savings Analytics: Live tracking of token costs saved by routing routine tasks to DeepSeek V4.1-Flash ($0.20/M) vs frontier models (Claude 5 Fable at $12/M / GPT-6 Astra at $10/M).

  • Interactive Threat Simulator: Test the AST Sandbox, Safe SQL Engine, and Cost Router directly in the browser with 1-click attack presets.


Related MCP server: py-sandbox

Why NexusMCP?

Autonomous agents like Claude 5 Fable, GPT-6 Astra, and Cursor are incredibly powerful, but unconstrained tool access leads to catastrophic failure modes:

  1. Unbounded Destruction: Agents running DELETE or DROP TABLE without safeguards.

  2. System Escapes: Arbitrary shell execution (os.system, subprocess) compromising local credentials.

  3. Runaway Token Costs: Routing trivial linting or formatting tasks to expensive $15/M reasoning models.

NexusMCP solves this with an audited, zero-dependency stateless gateway that acts as a secure boundary.


3-Pillar Architecture

[ Cursor / Windsurf / Claude Desktop ]
                   │
                   ▼ (Stateless JSON-RPC 2.0 / SSE)
        ┌───────────────────────────────────┐
        │       NexusMCP Gateway (:8080)     │ ──► [ Web Dashboard / SOC ]
        └─────────────────┬─────────────────┘
                          │
          ┌───────────────┼───────────────┐
          ▼               ▼               ▼
   [ AST Sandbox ]  [ Safe SQL ]    [ Token Router ]
   Static AST       AST Guard       DeepSeek V4.1-Flash
   Memory/Timeout   Read-Only Mode  vs Claude 5 Fable
   Zero Network     Anti-DROP/TRUNC (-70% Token Costs)

Included Production Tools

Tool Name

Wire Identifier

Security Safeguards

Latency

AST Code Sandbox

execute_python_sandbox

AST node visitor, bans sockets/subprocess/eval/exec, CPU timeout watchdog.

~0.2 ms

Safe SQL Engine

safe_sql_query

Intercepts DROP/TRUNCATE/unbounded mutations, enforce read-only transactions.

~0.05 ms

Model Cost Router

calculate_model_route

Semantic task arbitrator dispatching between DeepSeek V4.1-Flash and Claude 5.

~0.01 ms


🚀 10-Second Quickstart

Option A: Pure Python (Zero External Dependencies)

python -m src.server

Visit http://localhost:8080/ to view the live Cyber Web Dashboard!

Option B: 1-Click Docker Compose

git clone https://github.com/trobasuj-cpu/nexus-mcp-gateway.git
cd nexus-mcp-gateway
docker compose up -d

The server starts on http://localhost:8080 with the Web Dashboard on /, MCP on /mcp, and health checks on /health.

Run Deterministic Verification Harness

python run_tests.py
# Or with pytest:
pytest tests/ -v

(Runs 28 comprehensive security and live HTTP tests in <500ms).


🔌 1-Click Cursor & Claude Desktop Integration

Cursor IDE Setup (.cursor/mcp.json)

Copy the included configuration into your project root:

{
  "mcpServers": {
    "nexus-mcp-gateway": {
      "url": "http://localhost:8080/sse",
      "transport": "sse"
    }
  }
}

Claude Desktop Setup

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "nexus-mcp": {
      "command": "python",
      "args": ["-m", "src.server"],
      "env": {
        "NEXUS_MCP_PORT": "8080"
      }
    }
  }
}

🏆 NexusMCP Pro Developer Suite ($29)

For engineering teams requiring enterprise isolation, the Pro Suite adds:

  • KMS / Vault Secret Enclave: Stateless HMAC-signed credential injector (agents never see raw tokens).

  • Atomic Git Ops Tool: Automated branch, commit, and PR creation with automated rollback.

  • Sliding Window Rate Limiter: Redis & In-memory token bucket protection.

  • Cryptographic Audit Trail: Chained tamper-proof logs for regulatory compliance.

  • Commercial Client License: Unlimited deployments for your SaaS and client projects.

👉 Get the Pro Suite on Gumroad ($29)


License

Open-core edition is distributed under the Apache 2.0 License. See LICENSE for details.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    A
    maintenance
    A production-ready MCP gateway and control plane that provides credential vault, policy engine, audit logging, and managed runtime for routing tool calls between AI agents and downstream MCP servers.
    58
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to execute arbitrary Python code securely in a sandboxed environment with resource limits and security constraints via MCP protocol.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Governed MCP gateway that lets AI agents call tools with policy enforcement, prompt-injection screening, a kill-switch, and tamper-evident signed audit logs.
    Apache 2.0