Skip to content
src.wesktop.mcp
Edit
On this page

wesktop's MCP agent role registry (implementor, auditor, reviewer, deployer) plus role-aware create_mcp_server and register_tools_for_role over fastware.

#src.wesktop.mcp

#src.wesktop.mcp

wesktop's agent role registry plus the MCP server factory that wraps fastware: per-role tool provisioning for implementor, auditor, reviewer, and deployer agents.

fastware's MCP layer is role-agnostic -- its create_mcp_server and register_tools_for_role take a roles mapping explicitly. The implementor/auditor/reviewer/deployer domain model lives here: pass roles=wesktop.mcp.ROLES (and default_role=wesktop.mcp.DEFAULT_ROLE) when creating a server or registering tools.

#ROLES

Registry mapping each agent role name (implementor, auditor, reviewer, deployer) to its config dict -- a permission level and the allowlist of MCP tools that role may call. This is wesktop's application role model; fastware ships none.

#DEFAULT_ROLE

Name of the fallback role (auditor, the least-privileged read-only role) used when a requested role is unknown. Auditor is the safe default because it grants no write, review-posting, or deploy capabilities.

#create_mcp_server

python
def create_mcp_server(name: str='fastware-agent', *, role: str | None=None, tool_modules: list[ModuleType] | None=None, roles: dict[str, dict[str, Any]] | None=None, default_role: str | None=None) -> Any

Create a FastMCP server with role-filtered tools, using wesktop's roles.

Thin wrapper over fastware's role-agnostic factory. wesktop owns the role model, so pass roles=ROLES (and optionally default_role=DEFAULT_ROLE) to provision an implementor/auditor/reviewer/deployer server; without a roles mapping fastware has no roles to filter tools by. Raises RuntimeError if the optional mcp package is not installed.

#register_tools_for_role

python
def register_tools_for_role(server: Any, role: str, tool_modules: list[ModuleType], *, roles: dict[str, dict[str, Any]], default_role: str | None=None) -> dict[str, Callable[..., Any]]

Register only the tools allowed by role onto an existing server.

Thin wrapper over fastware's role-agnostic registrar. Each module in tool_modules must expose a TOOLS dict; only the tools listed for role in wesktop's ROLES registry are attached. Callers pass roles=ROLES (and optionally default_role=DEFAULT_ROLE). Returns the dict of registered tool name -> callable.

#ROLES

python
ROLES: dict[str, dict[str, Any]] = {'implementor': {'level': 'read-write', 'tools': ['read_file', 'write_file', 'edit_file', 'list_files', 'search_files', 'git_status', 'git_diff', 'git_commit', 'git_log', 'run_tests', 'ask_user']}, 'auditor': {'level': 'read-only', 'tools': ['read_file', 'list_files', 'search_files', 'git_status', 'git_diff', 'git_log', 'run_tests', 'ask_user']}, 'reviewer': {'level': 'read-only', 'tools': ['read_file', 'list_files', 'search_files', 'git_diff', 'git_log', 'post_review_comment', 'ask_user']}, 'deployer': {'level': 'everything', 'tools': ['read_file', 'list_files', 'search_files', 'git_status', 'git_diff', 'git_log', 'stage_branch', 'create_prod_pr', 'check_pipeline', 'ask_user']}}

#DEFAULT_ROLE

python
DEFAULT_ROLE = 'auditor'

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
Search