omni #
One MCP endpoint in front of every open server in the mcp atlas.
live: https://omni-mcp.fastmcp.app/mcp · try it in a browser
claude mcp add omni --transport http https://omni-mcp.fastmcp.app/mcp
The registry is the configuration. At startup omni reads the atlas, mounts a
namespaced proxy per open server, and folds the whole catalog into
code mode — so a client
sees search, get_schema, list_tools, and execute rather than fifty-odd
tools across eight servers. Publish a server to the atlas and omni carries it.
atlas record → proxy mount → one catalog → search / execute
Nothing here is specific to a server: names, schemas, and tool counts all come from the registry and the live catalog at boot.
the console #
The browser page is a diagnostic,
not the interface — the interface is an agent holding the URL. It renders the
fleet from list_tools, seeds execute from a tool's real schema, and colors
every result by the server it came from.
what a stranger can spend #
execute runs untrusted Python from anonymous callers, so the boundary was
measured rather than assumed. Roughly thirty probes, identical results local and
hosted: reaching call_tool.__globals__, walking __subclasses__, eval,
exec, __import__, os, subprocess, socket, httpx, and open() are
all refused by the pydantic-monty
sandbox, and runaway loops, memory bombs, and infinite recursion all die on
limits.
What the sandbox does not bound is volume. An open endpoint is an amplifier: one
anonymous request could drive thirty seconds of calls at other people's servers.
That is what the three limits in server.py are for — 2 rps with a burst of 10,
a 5s / 50MB sandbox budget, and ten tool calls per execute.
running it #
uv run server.py # localhost:8781
uv run drive.py search '{"query": "writing"}' # call the hosted endpoint
uv run drive.py --local list_tools '{}' # or a local one
Deployed on Prefect Horizon from a source upload; the site is a static page on wisp.place.
known gaps #
The fleet is snapshotted at startup, so a new atlas record needs a redeploy to
appear. Servers requiring auth are listed but not mounted — per-caller
credentials are the open design question, and the reason authRequired entries
show as unreachable rather than broken.