Secure execution layer for AI assistants

Jervis Desktop MCP

Lets AI assistants work inside a developer's real projects — files, git, processes, browser — over the Model Context Protocol, with read-only defaults, per-workspace permissions and an audit trail.

Role
Creator — runtime, security model, desktop companion
Period
2026
Stack
  • TypeScript
  • MCP SDK
  • Electron
  • Playwright
  • Zod
  • OIDC / JWT
Jervis Desktop MCP landing page: Your projects. Your AI. On the same page.

Context

Chat-based assistants are good at reasoning about code but can't see the project on a developer's machine. Giving them raw shell access solves that and creates a much bigger problem.

Constraints

Access has to be explicit per project, safe by default, work for both local IDE agents and a remote assistant, and leave a record of what was done.

Architecture

A single tool registry exports JSON-Schema contracts for filesystem, search, git, process/PTY, browser, sandbox and workflow tools. The same registry is served over stdio for IDE agents and over stateless Streamable HTTP for remote clients.

An Electron companion app (English and Arabic) is where the developer pairs devices, adds projects and chooses read-only or editable access for each one.

Architecture
  1. AI clients
    • ChatGPTremote
    • Claude Code · Codex · Cursor · VS Codestdio
  2. Transport & identity
    • Streamable HTTP
    • OIDC / JWTRFC 9728
    • Device leases
  3. Policy
    • Read-only default
    • Workspace roots
    • Audit chain
  4. Tool registry
    • Fileshash-guarded edits
    • Gitcheckpoints
    • ProcessesPTY
    • Browser

Decisions

Read-only is the default profile; writes require an explicit workspace grant and are confined to registered roots.

File edits are hash-guarded, so an assistant can't overwrite a file that changed since it last read it; git checkpoints make every change reversible.

Every action is appended to a tamper-evident audit chain.

Outcome

Release candidate with a bilingual landing page and desktop companion, CI for the runtime and desktop packages, and stdio support for Claude Code, Codex, Cursor and VS Code.

Screens

Kerolos Zakaria

Senior Front-End Developer · Cairo, Egypt

© 2026 Kerolos ZakariaBuilt with Nuxt. Static, bilingual, no trackers.
Esc

Pages

Home
Work
Open Source
Jervis
About
Contact

Work

Jervis BoostAI engineering control plane
Jervis Desktop MCPSecure execution layer for AI assistants
Government platforms in Egypt & Saudi ArabiaBilingual public-sector web
vue-nuxt-permissionOpen-source permission system
Frontend foundation & team toolingInternal platform work
Jervis Universal AgentLocal-first agent runtime
Jervis DevOpsSelf-hosted deployment platform
Jervis MathArabic-aware math input

Actions

Toggle theme
العربية — switch to Arabic
Copy email addresskeroloszakaria2@gmail.com
GitHubkeroloszakaria
LinkedInkerolos-zakaria
npm~keroloszakaria
VS Code Marketplacekeroloszakaria
Medium@keroloszakaria2
UpworkKerolos Z.