MCP
MCP servers are configured per profile in config.json:
{ "mcpServers": { "docs": { "command": "docs-mcp", "args": [], "env": { "DOCS_API_KEY": "${DOCS_API_KEY}" } } }}MCP auth material belongs in:
~/.duckagent/profiles/<name>/mcp-auth.jsonCommands
Section titled “Commands”duck mcp addduck mcp listduck mcp get <name>duck mcp remove <name>duck mcp auth <name>duck mcp logout <name>Sandbox relationship
Section titled “Sandbox relationship”mcpServers.<name>.env is an explicit grant to that MCP server. It is different from parent environment inheritance controlled by sandbox.env.
Tool-level sandbox policy can match exposed MCP tool names such as context7_search or context7_*.