one MCP endpoint in front of every open server in the mcp atlas sites.wisp.place/zzstoatzz.io/omni
README.md

omni #

One MCP endpoint in front of every open server in the mcp atlas.

live: https://omni-mcp.fastmcp.app/mcp · try it in a browser

claude mcp add omni --transport http https://omni-mcp.fastmcp.app/mcp

The registry is the configuration. At startup omni reads the atlas, mounts a namespaced proxy per open server, and folds the whole catalog into code mode — so a client sees search, get_schema, list_tools, and execute rather than fifty-odd tools across eight servers. Publish a server to the atlas and omni carries it.

atlas record → proxy mount → one catalog → search / execute

Nothing here is specific to a server: names, schemas, and tool counts all come from the registry and the live catalog at boot.

the console #

The browser page is a diagnostic, not the interface — the interface is an agent holding the URL. It renders the fleet from list_tools, seeds execute from a tool's real schema, and colors every result by the server it came from.

what a stranger can spend #

execute runs untrusted Python from anonymous callers, so the boundary was measured rather than assumed. Roughly thirty probes, identical results local and hosted: reaching call_tool.__globals__, walking __subclasses__, eval, exec, __import__, os, subprocess, socket, httpx, and open() are all refused by the pydantic-monty sandbox, and runaway loops, memory bombs, and infinite recursion all die on limits.

What the sandbox does not bound is volume. An open endpoint is an amplifier: one anonymous request could drive thirty seconds of calls at other people's servers. That is what the three limits in server.py are for — 2 rps with a burst of 10, a 5s / 50MB sandbox budget, and ten tool calls per execute.

running it #

uv run server.py                                   # localhost:8781
uv run drive.py search '{"query": "writing"}'      # call the hosted endpoint
uv run drive.py --local list_tools '{}'            # or a local one

Deployed on Prefect Horizon from a source upload; the site is a static page on wisp.place.

known gaps #

The fleet is snapshotted at startup, so a new atlas record needs a redeploy to appear. Servers requiring auth are listed but not mounted — per-caller credentials are the open design question, and the reason authRequired entries show as unreachable rather than broken.