The first working reference agent I built and published for Stealth Startup, an AI agent marketplace. It is an OpenAI Agents SDK assistant that reads local files through the Model Context Protocol (MCP) filesystem server, packaged so that it runs cleanly inside a sandboxed marketplace deployment.
main.py starts the MCP filesystem server (@modelcontextprotocol/server-filesystem) over stdio with npx, scoped to the sample_files/ folder, then runs three prompts through an Agents SDK Agent:
- list the files it can read;
- read
favorite_books.txtand name the number one book; - read
favorite_songs.txtand suggest one new song.
Each run is traced, and the trace URL is printed at startup.
The agent logic starts from the filesystem_example in openai/openai-agents-python. My work is the hardening a marketplace sandbox needs, all of it in main.py:
- a 30 second MCP session timeout, because the first
npx -yon a cold sandbox downloads the server package and blows past the SDK's 5 second default, which killed the init handshake; - startup checks for
npxon PATH and forOPENAI_API_KEY, each exiting with a one line message; - clean handling of 401 (rejected key), 429 (no quota), and network egress failures instead of tracebacks, so an orchestrator sees a single explanatory line.
STEALTH_STARTUP_UPLOAD_NOTES.txt records what to upload, the runtime and environment variables, and the sandbox flags to watch: Node absent from the template, the cold npx timeout, the two egress destinations, the filesystem scope, and the non-interactive run.
Run locally on Python 3.13 and Node 25 with openai-agents==0.18.0. The MCP server connection was verified end to end. The paid model call was intentionally not exercised during packaging, and the notes say so.
Requirements: Python 3.10 or newer, Node.js (for npx), and an OPENAI_API_KEY on a funded project.
pip install -r requirements.txt
npm install -g @modelcontextprotocol/server-filesystem # optional, removes the cold-start download
export OPENAI_API_KEY=...
python main.pySet OPENAI_AGENTS_DISABLE_TRACING=1 to stop the SDK from posting traces to OpenAI.