跳到主内容
@wquguru
精选88r/LLMDevs(Reddit)技巧与观点

开源Discord AI助手Zauq v4发布:支持MCP与有界Agent

A month ago I shared my open-source Discord AI assistant... I just released v4 with MCP, bounded agents, multi-provider tool calling and sandboxed code verification

原文
发到 X
推荐理由

Agent工程实践干货,有界运行时与MCP权限设计的取舍值得参考,建议收藏研究其架构解耦思路。

A month ago I shared Zauq(ذوق) here... an open-source AI assistant I was building for Discord communities.

一个月前,我在这里分享了 Zauq(ذوق)……一个我为 Discord 社区构建的开源 AI 助手。

At the time, it already had multi-model routing, persistent memory/RAG, web search, file handling, and sandboxed code execution.

当时,它已经具备多模型路由、持久化记忆/RAG、网络搜索、文件处理和沙盒代码执行功能。

Since then, I ended up doing a fairly major architectural rewrite and have now released Zauq v4.

此后,我进行了一次相当重大的架构重写,并现已发布 Zauq v4。

The main goal was to make it more genuinely agentic without turning it into an uncontrolled plan → act → reflect → repeat loop.

主要目标是使其成为更真正的智能体(agentic),同时避免将其变成不受控制的计划→行动→反思→循环重复过程。

The biggest changes are:

最大的变化包括:

  • Bounded agent runtime: tool usage now runs under hard step limits, deadlines, resource budgets, and duplicate-call protection.
  • MCP client support: Zauq can connect to trusted MCP servers and dynamically discover tools, with guild scopes, allowlists, namespaces, and risk classification.
  • Native multi-provider support: Gemini, Claude, Qwen, DeepSeek, and DigitalOcean APIs, plus Ollama and Kaggle workers.
  • Unified tool layer: native tools and MCP tools go through the same registry, schema validation, policy, timeout, and execution pipeline.
  • Serper-powered web research: search, page fetching, caching, source attribution, and bounded deep research are now separated into their own retrieval subsystem.
  • Automatic sandboxed code verification: generated Python/JS/Bash code can optionally be tested in Docker with off, auto, or always modes.
  • Human-in-the-loop actions: write/destructive tools can require explicit approval before execution.
  • Separate sandbox runner: the main backend no longer needs direct Docker privileges in the recommended deployment.
  • Improved observability: tool calls, search usage, sandbox runs, MCP calls, latency, tokens, and optional cost estimates can be tracked.
  • 有界智能体运行时:工具使用现在在严格的步骤限制、截止时间、资源预算和重复调用保护下运行。
  • MCP 客户端支持:Zauq 可以连接到受信任的 MCP 服务器并动态发现工具,支持公会范围、白名单、命名空间和风险分类。
  • 原生多提供商支持:Gemini、Claude、Qwen、DeepSeek 和 DigitalOcean API,以及 Ollama 和 Kaggle 工作节点。
  • 统一工具层:原生工具和 MCP 工具都通过相同的注册表、模式验证、策略、超时和执行管道。
  • Serper 驱动的网络研究:搜索、页面抓取、缓存、来源归因和有界深度研究现在被分离到它们自己的检索子系统中。
  • 自动沙盒代码验证:生成的 Python/JS/Bash 代码可以选择在 Docker 中测试,支持关闭、自动或始终模式。
  • 人在回路操作:写入/破坏性工具可以在执行前要求明确批准。
  • 独立沙盒运行器:推荐部署中,主后端不再需要直接的 Docker 权限。
  • 改进的可观测性:可以跟踪工具调用、搜索使用情况、沙盒运行、MCP 调用、延迟、令牌数和可选的成本估算。

The architecture now looks roughly like:

现在的架构大致如下:

代码 · 1 行
Discord ↓ FastAPI Orchestrator ↓ Bounded Agent Runtime ↓ Tool Registry / Policy ├── Web Search ├── Sandbox ├── MCP Tools └── Other Native Tools ↓ Gemini / Claude / Qwen / DeepSeek / DO / Ollama / Kaggle

One principle I tried to keep throughout the update was:

在整个更新过程中,我试图保持的一个原则是:

The model can choose a tool, but it should never be the authority on whether that tool is allowed to execute.

模型可以选择一个工具,但它不应成为该工具是否允许执行的最终权威。

So reasoning, authorization, and execution are intentionally kept separate.

因此,推理、授权和执行被有意地分开处理。

I also avoided adding Redis, Celery, Chromium, local rerankers, or always-on local LLMs to the default architecture because I still want Zauq to be practical on a relatively small VPS.

我还避免在默认架构中添加 Redis、Celery、Chromium、本地重排序器或常驻本地 LLM,因为我仍希望 Zauq 在相对较小的 VPS 上保持实用性。

The project is still fully open source under Apache 2.0.

该项目仍在 Apache 2.0 许可下完全开源。

GitHub:

GitHub:

https://github.com/Muhammad-Hassan12/Zauq

I’d especially like feedback on:

我特别希望就以下方面获得反馈:

  • the MCP permission model
  • the bounded-agent design
  • the sandbox architecture
  • provider abstraction/tool calling
  • whether this still feels appropriately scoped, or if I’m overengineering it now 😅
  • MCP 权限模型
  • 有界智能体设计
  • 沙箱架构
  • 提供者抽象/工具调用
  • 这是否仍然感觉范围恰当,或者我现在是否过度设计了 😅

I’m not claiming this is production-perfect. I’m mainly interested in what people who build agent systems would simplify, redesign, or remove.

我并非声称这是生产环境完美的方案。我主要感兴趣的是,那些构建智能体系统的人会如何简化、重新设计或移除其中的内容。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件