[Unit] Description=MCP Agent After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/local/bin/mcp-agent server --config /srv/mcp/mcp-agent.toml Restart=on-failure RestartSec=5 User=mcp Group=mcp NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictSUIDSGID=true RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true ReadWritePaths=/srv [Install] WantedBy=multi-user.target