MCP server for integrate with external AGENT and recover session info (ip, hostname, user and pswd)

MCP server for integrate with external AGENT and recover session info (ip, hostname, user and pswd)

1 vote

avatar

I'm working on a Agent that aim's to help SAP basis Administrator people.
You can have an idea here:
https://lnkd.in/p/dynBwZT9
At the moment the agent know the info of SAP system from local config files.
Due to the fact that I store all the info in sessions into RDM (several session for the same SAP system).
I'm wander if I can "ask" to RDM to recover the info to connect to a SAP system (this mean IP, user, pswd, and other parameters) and RDM pass these info to the agent without writing these in file.

Do you think that is possible ?
Is already in place an MCP server for these pourposes?
THX

All Comments (1)

avatar

Hi @pico

I'm Maxime, AI Software Architect at Devolutions. I work on the MCP server and the AI Assistant integration for RDM, and soon, an unreleased tool.

Let's start by going over what RDM's MCP Server can and cannot do. We offer many tools through the MCP server. I've got a couple of tools that are important to the flow you're discussing in order to retrieve the Session entry in RDM: RDM_list_datasources, RDM_list_vaults, RDM_search_entries, RDM_get_entry. You can list the datasources (now called workspaces—just not renamed in the MCP tools yet), list your vaults, search for entries (list entries), and use the last one to get the full details of an entry.

We allow sending sensitive information through the MCP response (e.g., passwords) only if the user allows it in their RDM settings (AI Assistant > MCP Server > Exclude sensitive [...] unchecked). With that said, if you uncheck this, you must be aware that the AI model will have access to the sensitive information. Depending on the provider used, it might write it to a file. I've seen the Copilot provider do that in cases where the length of the data received is too large, in order to aggregate after. I don't think I've seen this behavior with Anthropic or OpenAI providers.

I feel like RDM MCP could be working for you if—and only if—the security aspect is something that you have leverage on. Unchecking the "Exclude sensitive [...]" checkbox means knowing that the data will include sensitive information for the AI. If I may suggest, letting any AI provider access passwords is far from ideal and is not something I would recommend.

You could have RDM open and use Devolutions Agent on the machines, and drive the MCP Server to connect to the machine and answer "What does the system log say since this morning? Any critical errors?" We have an SSH terminal entry that you could use for this use case, which can be driven by the MCP server. I've used it multiple times for demos where I show the top 5 processes running on a machine. The IP, hostname, and passwords never leave RDM using that method; all you need is the entry's ID, which you can find using the RDM_search_entry tool.

---

This brings me to the next part, an unreleased tool we have been developing that is not yet ready for customers: Devolutions CLI. The CLI we're working on will have a syntax similar to this:
devo secret run --env-ref HOST=devo://…/field/host --env-ref PASS=devo://…/field/password -- <tool>

This will allow an Agent to run the Devo CLI to obtain sensitive information (password) and store it in environment variables. We're building it for a use case with IronRDP, where we want to connect to a remote machine without passing the credentials in plain text, driven by an AI model.

---

Let me know if I was clear enough or if there's something else that needs clarification. I'm here to help.


Best regards,

Maxime Forest