第 3 章:用 MCP 给 Agent 装上工具
第 3 章:用 MCP 给 Agent 装上工具
关于本课
本课程的视频是某个时间点的快照。Strands 一直在积极开发,所以这一页上的代码反映的是最新的写法,但视频里讲的概念依然成立。拿不准的时候,以代码为准。
本课代码:samples/03-mcp-tools
工具从哪来
工具让 Agent 能够执行动作、获取信息,突破 Model 训练数据里的那点内容。定义工具的方式不止一种。工具可以来自不同地方,它们都并排待在同一个 Agent 的 tools 列表里:
- 自定义工具(Custom tools),你自己用
@tool装饰器写的(第 1 课里已经见过) - vended tools,SDK 自带,位于
strands.vended_tools:文件编辑、shell、web fetch - MCP server,通过标准协议把工具暴露出来,不管是你在跑还是别人在跑
- 其他 Agent,第 10 课讲把 Agent 当工具用时你会看到
MCP 特别有用,因为它能让你把 Agent 接到由外部管理的工具服务器上。Agent 在运行时动态发现可用的工具,而不是把它们硬编码进去。
MCP(Model Context Protocol)
MCP 是一个开放标准,给 Agent 提供了一致的方式,通过标准协议去发现和调用外部能力(GitHub、AWS、数据库、浏览器工具)。Server 可以作为子进程在本地跑(stdio),也可以远程通过 HTTP 跑。
from mcp import stdio_client, StdioServerParameters
from strands import Agent
from strands.tools.mcp import MCPClient
# Remote MCP server (Streamable HTTP): pass the URL and Strands builds the transport
aws_knowledge = MCPClient(
url="https://knowledge-mcp.global.api.aws",
prefix="knowledge",
)
# Local MCP server (stdio)
aws_pricing = MCPClient(
lambda: stdio_client(StdioServerParameters(
command="uvx",
args=["awslabs.aws-pricing-mcp-server@latest"],
env={"AWS_REGION": "us-east-1"}
)),
prefix="pricing"
)
agent = Agent(tools=[aws_knowledge, aws_pricing], system_prompt="You are an AWS architect.")
agent("What AWS services should I use for a serverless FastAPI backend?")
prefix 参数给每个 server 的工具名加上命名空间,这样两个 server 暴露同名工具时不会撞车。
把 MCP 工具和 vended tools 混着用
MCP client 就是 tools 列表里的一个条目,跟其他工具平起平坐。下面这个 coding assistant 通过 MCP 拿到 AWS 文档,同时通过 vended tools 拿到本地文件和 shell 访问能力:
from strands import Agent
from strands.tools.mcp import MCPClient
from strands.vended_tools import file_editor, shell
# Connect to the AWS MCP server (streamable HTTP)
aws_mcp = MCPClient(url="https://aws-mcp.us-east-1.api.aws/mcp")
SYSTEM_PROMPT = """You are a coding assistant with AWS expertise.
Use the AWS MCP tools to look up documentation, architecture patterns,
and service details when answering questions about building on AWS.
Be concise and actionable in your recommendations."""
agent = Agent(
tools=[aws_mcp, file_editor, shell],
system_prompt=SYSTEM_PROMPT,
)
agent("I need to build a serverless FastAPI backend with authentication "
"and file uploads. What AWS services should I use and how should "
"I architect this?")
工具过滤
工具太多会导致工具选择变差、编造出不存在的工具名、白白浪费上下文。生产环境里要用 tool_filters 限制 Agent 能访问哪些工具,只暴露它真正需要的那几个:
from strands import Agent
from strands.tools.mcp import MCPClient
# Filter to only documentation tools
filtered_mcp = MCPClient(
url="https://aws-mcp.us-east-1.api.aws/mcp",
tool_filters={
"allowed": ["aws___search_documentation", "aws___read_documentation"]
},
)
agent = Agent(
tools=[filtered_mcp],
system_prompt="You are an AWS documentation assistant.",
)
控制工具执行
默认情况下,Strands 会把单个 Model turn 里产生的多个工具调用并发执行。当工具之间有互相依赖的副作用时,换成顺序执行的 executor:
from strands import Agent, tool
from strands.tools.executors import SequentialToolExecutor
@tool
def step_one() -> str:
"""Perform the first step of the workflow."""
return "Step one complete - file created."
@tool
def step_two() -> str:
"""Perform the second step that depends on step one."""
return "Step two complete - file processed."
agent = Agent(
tools=[step_one, step_two],
tool_executor=SequentialToolExecutor(),
)
agent("Run step one and then step two.")
安全边界
工具是以宿主进程的权限去执行的。你要是给了 Agent shell 工具,就等于把整台机器交出去了。用 MCP 的时候,你等于把别人控制的工具塞给了自己的 Agent。接什么之前先想清楚。
想要沙箱化的执行环境,可以看看 Strands Shell,它给 Agent 提供隔离的文件系统和网络访问。
参考资源
- 📖 Tools 概览
- 📖 MCP 工具
- 📖 自定义工具
- 🛠️ Strands Shell