Samuel Birhanu

Samuel Birhanu

software engineer — agentic AI, Addis Ababa, Ethiopia

mcp-ops-agent, in plain English

AI agents that can run commands and poke at servers are genuinely useful, and genuinely dangerous. Give an agent too much freedom and one bad day becomes a deleted database.

mcp-ops-agent is my version of doing this properly. The agent gets real tools — it can search files, run a few harmless commands, and read the state of a Kubernetes cluster. But it can't do damage: the safety rules aren't a polite suggestion in the prompt, they're built into the tools themselves, so the agent has no way to argue its way past them. In the trace report you can watch three real runs step by step, including the moments the agent tried something it shouldn't and got blocked.

Under the hood

An MCP server (official mcp SDK, stdio transport) exposes six tools, and a LangGraph ReAct agent uses them:

Open the live trace report →
README · SPEC (tool surface, guardrails, trace format) · source tarball