The Lab — MCP Servers

The Universal Plug for AI Agents.

For years, connecting AI models to real-world tools meant writing custom integration code for every combination of model and capability. The Model Context Protocol changes that. MCP is the USB-C of AI — a single, open standard that lets any agent connect to any tool, any data source, any service. I think it's one of the most important infrastructure developments in AI right now, and I'm building on top of it.

What Is MCP?

The core idea

"MCP is to AI agents what REST APIs were to web services — a common language that makes everything composable."

The Model Context Protocol (MCP) is an open standard developed by Anthropic that defines how AI models communicate with external tools and data sources. Instead of every AI application building its own bespoke integrations, MCP provides a universal interface: a server exposes capabilities, a client (the AI model or agent) connects to it, and they communicate through a standardized protocol.

An MCP server is a lightweight service that wraps a capability — a database, an API, a file system, a code executor, a web browser — and exposes it to any MCP-compatible AI client. Build the server once, and any agent that speaks MCP can use it.

This is a fundamental shift. Before MCP, tool integration was a bespoke, fragile, per-model problem. With MCP, it becomes infrastructure — composable, reusable, and model-agnostic.

Why MCP Matters for Agent Systems

The real power of MCP isn't any single server — it's what becomes possible when agents can dynamically discover and compose capabilities at runtime.

01

Model Agnosticism

An MCP server works with Claude, GPT-4, Gemini, local LLMs — any model that implements the client protocol. You build the integration once and it works everywhere. No more rewriting tool integrations every time you switch models.

02

Dynamic Tool Discovery

Agents can query an MCP server at runtime to discover what tools are available, what parameters they take, and what they return. The agent doesn't need to know the tools in advance — it can adapt to whatever capabilities are present.

03

Composable Architecture

Multiple MCP servers can be combined. An agent can simultaneously connect to a database server, a web search server, a code execution server, and a file system server — composing capabilities on the fly to solve complex tasks.

04

Clean Separation of Concerns

MCP separates the AI reasoning layer from the tool implementation layer. The agent focuses on what to do; the MCP server handles how to do it. This makes both layers easier to build, test, and maintain independently.

05

Security Boundary

MCP servers act as a controlled gateway. You define exactly what capabilities are exposed, with what permissions, under what constraints. The agent never has direct access to your systems — it goes through the server.

06

Ecosystem Momentum

The MCP ecosystem is growing fast. Hundreds of servers are already available for common services. Building on MCP means your agents can immediately leverage a growing library of pre-built integrations.

Servers I'm Building

Active MCP server projects in the lab — each one solving a real integration problem for agent systems.

Active

Infrastructure Ops Server

An MCP server that exposes infrastructure management capabilities to AI agents — querying server health, reading logs, executing runbooks, and triggering alerts. Built to power the Enterprise Ops Swarm, it gives agents safe, audited access to production systems without direct shell access.

Capabilities

Server health queriesLog retrieval and searchRunbook executionAlert management

Stack

TypeScript · Node.js · SSH · Prometheus API

Active

Knowledge Base Server

An MCP server that wraps a pgvector-backed RAG pipeline and exposes it as a tool. Agents can search the knowledge base with natural language, retrieve relevant documents with citations, and ask follow-up questions — all through a clean MCP interface.

Capabilities

Semantic searchDocument retrieval with citationsChunk-level contextCollection filtering

Stack

TypeScript · pgvector · PostgreSQL · OpenAI Embeddings

Active

Code Execution Server

A sandboxed MCP server that lets agents write and execute code in isolated Docker containers. Supports Python, TypeScript, and shell. Returns stdout, stderr, exit codes, and generated files. Built with hard resource limits and no network access by default.

Capabilities

Python executionTypeScript executionShell commandsFile output retrieval

Stack

TypeScript · Docker · Node.js

Experimental

Web Intelligence Server

An MCP server that gives agents structured web access — search, scrape, extract, and summarize web content. Uses a headless browser for JavaScript-heavy sites and returns clean, structured data rather than raw HTML.

Capabilities

Web searchPage scrapingContent extractionLink graph traversal

Stack

TypeScript · Playwright · Cheerio · Brave Search API

How I Structure MCP Servers

Every MCP server I build follows the same architectural principles — regardless of what capability it wraps.

01

Single Responsibility

Each server does one thing well. An infrastructure server doesn't also do web search. Focused servers are easier to secure, test, version, and reason about.

02

Explicit Tool Schemas

Every tool exposed by the server has a precise JSON Schema definition — parameter names, types, descriptions, and constraints. Good schemas are what allow agents to use tools correctly without trial and error.

03

Structured Error Responses

Errors are first-class citizens. Every tool returns structured error information that an agent can reason about — not just a stack trace. The agent needs to know what went wrong and whether it can retry.

04

Audit Logging

Every tool invocation is logged with the caller identity, parameters, result, and timestamp. When an agent does something unexpected, you need to know exactly what it called and what it got back.

05

Transport Flexibility

I build servers to support both stdio (for local/embedded use) and HTTP+SSE (for remote/multi-client use). The capability layer is transport-agnostic — switching transports doesn't require rewriting tools.

Tool Categories I Expose

Across my MCP servers, these are the categories of capabilities I expose to agents.

Data & Knowledge

Vector search over document collections
Structured database queries (read-only)
Document retrieval with source attribution
Knowledge graph traversal

Execution & Compute

Sandboxed code execution (Python, TypeScript)
Shell command execution with resource limits
File read/write within scoped directories
HTTP requests to approved external APIs

Infrastructure & Ops

Server health and metrics queries
Log retrieval and structured search
Runbook lookup and execution
Alert creation and acknowledgement

Web & External

Web search with structured results
Page content extraction and summarization
RSS feed ingestion
API polling and webhook registration

Challenges & Lessons Learned

MCP is powerful, but building production-grade servers has taught me things the documentation doesn't cover.

01

Schema Quality Is Everything

The quality of your tool schemas directly determines how well agents use your server. Vague parameter descriptions lead to incorrect calls. I now treat schema writing as a first-class engineering task — as important as the implementation itself.

02

Agents Will Find Edge Cases You Didn't

Agents explore the parameter space in ways humans don't. They'll pass empty strings, null values, extremely long inputs, and combinations you never tested. Defensive input validation isn't optional — it's the first line of reliability.

03

Idempotency Matters More Than You Think

Agents retry failed tool calls. If your tools have side effects and aren't idempotent, retries cause duplicate actions — duplicate database writes, duplicate API calls, duplicate alerts. Design for idempotency from the start.

04

Timeouts Need to Be Explicit

Agents have their own context window and reasoning budgets. A tool that takes 30 seconds to respond can derail an entire agent run. Every tool needs an explicit timeout, a fast failure path, and a clear error message when it times out.

05

The Permission Model Is Your Security Model

What you expose through MCP is what agents can do. I treat every tool as a potential attack surface and apply least-privilege principles — agents get exactly the access they need for their role, nothing more.

Tech Stack

The tools and frameworks I use to build and run MCP servers.

Core

@modelcontextprotocol/sdk — Official MCP TypeScript SDK
TypeScript — Primary implementation language
Node.js — Runtime for all servers
Zod — Runtime schema validation for tool inputs

Transport & Communication

stdio transport — Local and embedded agent use
HTTP + SSE transport — Remote and multi-client deployments
Express — HTTP server layer for remote transport

Infrastructure

Docker — Isolated server environments and sandboxing
OpenTelemetry — Distributed tracing and audit logging
PostgreSQL — Persistent state and audit logs

Explore More of the Lab

MCP servers are the tool layer that powers agent swarms and RAG systems. See how they fit into the bigger picture.

JoeCairns.AI

Building AI agents, automation workflows, and MCP servers — and documenting every lesson learned along the way.

Connect

© 2026 AI with Joe. All rights reserved.

Building AI that actually works

Admin