M16: an MCP server (illogical as tools for any agent) #5
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
#4 S14: MCP spike (rmcp, Claude Code and Codex as clients, VM reachability)
jhgaylor/illogical
Reference
jhgaylor/illogical#5
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Depends on: #4
Prerequisites already done: M3 (CLI/HTTP API), M3b/M3c (VMs), M6a, M6b, M6c, M7.
From PLAN.md, section "M16".
Any MCP client (Claude Code, Codex, Claude Desktop, an agent block) gets
illogical as typed tools: run commands in durable panes you can watch and
take over, spin up throwaway VMs, open a dev server next to its terminal,
start and supervise other agents, and search what happened yesterday. M3
already built the CLI and HTTP API, so M16 is a curated layer over them, not
new machinery.
Why it beats an agent's own Bash tool:
real pane. You see it on the phone, scroll it, take it over. It survives
the agent's session and daemon restarts, and the agent picks it up again
with
waitorread_output.runwithvm: trueis an isolated machine thatdisappears afterwards.
start_agent,waituntil it's idle orasking, read its transcript, and answer its approvals and questions (M6c),
or leave them for you.
open_portputs its dev server in a browser blockbeside its terminal.
historyandsearch.read_outputandwaitwhile asking beforerun.Decisions (2026-10-01):
pane on any host. The MCP client's own tool permissions are the guard,
which makes tool annotations matter (below).
Transports (one implementation):
/mcp, with the sameauth as the API:
WhoIson directlisteners);
illogical mcp token [--name n] [--scope …], revocable, for clients without tailnet identity;Originrule for browsers (the MCP spec requires thischeck). Non-browser clients send no
Origin.illogical mcpis a stdio bridge to that endpoint over the daemon'sUnix socket, or to another daemon with
--host. Claude Code and Codexconfigure it as a plain command:
rmcp) in the daemon. S14checks it covers Streamable HTTP, resource subscriptions and progress
notifications.
Tools. About a dozen, shaped for agents rather than mirroring every
endpoint. Each returns a short text summary plus
structuredContent, withoutput capped and pageable by offset, so a chatty pane can't flood the
agent's context.
runcwd,vm/vm_tab/machine,host,policy,wait(with a timeout). Returns the pane, and withwait, its exit code and the last lines.send_inputC-c,Up) to a paneread_outputcapture_screenwaitlistclosehistory/searchopen_portstart_agentagent_respondread_filefs), cappedrun --waitandwaitsend progress notifications. Theyalso return before the client's MCP tool timeout (S14 measures Claude
Code's) with a resumable "still running", so a long build never fails a
tool call.
isError) with a sentence an agent can acton, for example "pane %7 is gone; it exited 2 at 14:03", not protocol
errors.
Resources:
illogical://pane/%N/output(subscribable, so a client can follow a panelive),
illogical://pane/%N/screen,illogical://block/%N(state), andillogical://history.Agent blocks get it automatically, scoped to their tab:
session/newpassesmcpServerswith anillogicalserver. S13 showedclaude-agent-acpuses MCP servers passed that way.blocks in its own tab (on the tab's machine, in a VM tab), read and drive
what it created, and read the rest of its tab. It can't touch other tabs
or hosts.
HTTP endpoint on wisp's bridge address, or the bridge running host-side.
S14 checks what the guest network allows.
Safety. External clients get full scope, so:
readOnlyHint,destructiveHint,idempotentHint), which clients use to decide what to ask about;tools, ask for the rest;
"started by mcp:", and
historyrecords it.Done when:
illogical mcp, runs a long build in aVM pane. You watch it on the phone, Claude waits through it, reads the
failure, fixes it and reruns, and the pane shows "started by
mcp:claude-code".
and opens it in a browser block beside itself. A try to touch another tab
is refused.
question, and answers it.
history./mcpover HTTP with a token,and revoking the token cuts it off.