Skip to main content

mcp-console

🚧 UNDER CONSTRUCTION 🚧

This project is not ready for use.

mcp-console is a ground-up rewrite of mcp-repl. It applies the lessons learned from mcp-repl to a substantially different product---different enough that a new name makes sense.

MCP Console is being built as a persistent, sandboxed R, Python, and DuckDB SQL console for MCP agents. It gives an MCP client one live computational workspace instead of a sequence of disposable shell commands. An agent can submit complete R, Python, or SQL cells, keep state across calls, answer interactive prompts, inspect partial output, and switch languages as a task evolves.

The built-in worker embeds R. Python runs through reticulate, and SQL uses a persistent DuckDB connection by default while allowing R code to select another DBI connection or Python code to select a DB-API connection. R and Python can access one another's globals through reticulate, while the managed DuckDB backend can query data frames in the R workspace directly. R plots made with the default device and open Matplotlib figures are returned as images, SQL results are returned as bounded previews, and long-running work can be polled or interrupted.

Install

MCP Console is currently distributed as native wheels for Apple Silicon and Intel macOS. Linux and Windows are not supported yet.

A working R installation is required. Set R_HOME or make R discoverable on PATH. Dynamic environment resolution normally starts from either ir 0.4.0 or later or uv on PATH. The first managed server start may download and install the default R and Python requirements. If no resolver bootstrap is available, the server starts a bare runtime using installed packages. See Requirements and environments for bootstrap options, managed defaults, and bare runtime behavior.

Run the published command without installing it persistently:

uv tool run mcp-console --help
uv tool run mcp-console serve

Or install it as a persistent uv tool:

uv tool install mcp-console

mcp-console --help
mcp-console serve

mcp-console serve communicates with its MCP client over standard input and output. It waits for MCP protocol input rather than presenting an interactive terminal prompt.

Working with the console

The MCP interface exposes one tool: send. It runs one complete R, Python, or SQL cell, supplies interactive input, prepares additive requirements, applies an optional interrupt or restart, or collects pending output.

Code-bearing calls to send are sequential. The current interface has one implicit session, with no named-session management. The send operation reference defines validation, preparation, control, input, and timeout ordering. The built-in runtime guide covers language state, output, graphics, and interoperability.

Example workflow

An agent investigating measurements.csv could load the data and fit a model in one R cell submitted through send:

measurements <- readr::read_csv(
  "measurements.csv",
  show_col_types = FALSE
)

fit <- lm(response ~ temperature + group, data = measurements)
measurements$.residual <- residuals(fit)

It could then query the live R data frame with DuckDB SQL:

SELECT
  "group",
  count(*) AS n,
  avg(abs(".residual")) AS mean_abs_residual
FROM measurements
GROUP BY "group"
ORDER BY mean_abs_residual DESC

And inspect or plot the same data from Python:

frame = r.measurements

import matplotlib.pyplot as plt

plt.scatter(frame["temperature"], frame[".residual"])
plt.axhline(0)

The data, model, Python imports, and DuckDB catalog remain available for later calls until the worker is restarted, replaced, or the server exits.

The server records tool calls and results in a JSONL journal with image artifacts and a Markdown transcript. It also produces a Quarto source projection, transcript.qmd. Rejected or failed submissions may appear in that file, and rendering it does not reconstruct session control. See Recording and artifacts for the file formats and rendering behavior.

Security boundary

By default, submitted R, Python, and SQL have shell-class capability inside the worker sandbox. The worker can read host files, but direct network access and regular-file writes outside its private temporary directory are denied. This is a process boundary, not a safe evaluator for untrusted code with access to sensitive readable files.

mcp-console serve --no-sandbox launches the relay directly with host permissions. The worker inherits the host temporary-directory environment, and no sandbox manager tracks or cleans up descendants. The relay still shuts down and reaps its direct worker normally.

The server installs automatically inferred or explicitly declared R and Python packages and DuckDB extensions outside the worker sandbox with server permissions. Those operations may access the network and execute installation or build code, so only trusted requirements should be supplied. See Requirements and environments for the accepted inputs and trust model.

Session records contain submitted source, standard input, requirements, results, and artifacts without redaction. Rendering the Quarto source projection executes submitted code outside the worker sandbox with the permissions of the ir and Quarto processes. Render only code you trust.

Development

Run development commands from the repository root:

scripts/format
scripts/check
scripts/test [BOUNDARY/SUITE[::CASE]]
scripts/test --list
scripts/test --update BOUNDARY/SUITE[::CASE]

See AGENTS.md for development rules and the repository map, and the boundary test guide for test selection and snapshot updates. The standalone mcp-console sandbox -- COMMAND [ARG]... command is also available for development; macOS sandbox supervision defines its lifecycle, terminal behavior, and limitations.

Documentation

The documentation index maps current documents by audience.

The project vision and other documents under design-sketches/ describe intended or exploratory future design, not the implemented system. When current prose and implementation disagree, source and public acceptance tests are authoritative.

License

MCP Console is licensed under the MIT license.

Metadata

Release files for mcp-console 0.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for mcp-console 0.0.3
File Interpreter ABI Platform
mcp_console-0.0.3-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
mcp_console-0.0.3-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 6.0 MB

Release files / mcp_console-0.0.3-py3-none-macosx_11_0_arm64.whl

Download URL mcp_console-0.0.3-py3-none-macosx_11_0_arm64.whl
Size 2.9 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
6a8b705d56813ca914cd9da4e3714af1b783b74b5875eb02e81be9bb89583a6c
BLAKE2b-256 checksum
How to use checksums
101918a81939c5b4e76ec4316d7ec2300f2e706ede14792bca4551a9be0b9b11
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.4 {"installer":{"name":"uv","version":"0.12.4","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"22.04","id":"jammy","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / mcp_console-0.0.3-py3-none-macosx_10_12_x86_64.whl

Download URL mcp_console-0.0.3-py3-none-macosx_10_12_x86_64.whl
Size 3.0 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
112556b01912cc9cea655ca215cf15cf052535f07a058fd3690fc729c23a12d7
BLAKE2b-256 checksum
How to use checksums
e511ab76d89d34843b96cff1b74de5153ffd33093a3bf3d99df106097a9f47f5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.4 {"installer":{"name":"uv","version":"0.12.4","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"22.04","id":"jammy","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.0.4

4 release files

This release

0.0.3 This release

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page