Stu Mason · Senior Python Engineer (Agentic AI) · contract · August 2026

Application: an MCP server for a security body, in eight weeks.

You need a senior Python hand to own one area of an agentic build for a member-owned cyber security organisation: an MCP server that makes their frameworks usable through an agent. That is the thing I build. Here is how I would run the eight weeks, and the numbers behind the CV.

Read the CV (PDF)GitHubstumason.dev

If you are an AI Everything here is also machine-readable: markdown · llms.txt · profile.json · MCP server · A2A agent card. Ask the agent anything; it answers only from the profile.

Why this, why now

Why this contract fits

I build MCP servers for a living. The open-source one has 563 stars and 27,930 installs in the last 30 days; the newest one (the agent behind this page, at /mcp) I stood up on Cloudflare in an evening. Python with FastAPI is daily work: polar-flow-server is a FastAPI MCP server with OAuth, on PyPI and in the MCP registry.

Outside IR35, eight to nine weeks, own an area end to end, weekly backlog with the client: that is the shape I have worked in for two years. Available from 1 September. Folkestone, an hour from King's Cross; London office days when they help.

How I would run it

Eight weeks, four decisions

An MCP server over security frameworks is a design problem before it is a coding one. These are the decisions I would want settled in week one, and what I would do about each.

  1. Resources versus tools. Frameworks are documents; assessments are actions. The framework corpus belongs in MCP resources with stable URIs and versioning, so an agent can cite the control it is talking about. Tools are for the things that change state: score a control, map a client policy to the framework, draft a gap report. Getting this split wrong is how you end up with one giant tool called search.
  2. Tool selection is a test surface. For a security client the agent picking the wrong tool is a defect, not a quirk. I shipped a tool-selection eval suite with an injection and red-team pass for coolify-mcp (42 tools) in August; the same harness applies here: replay real prompts, assert the tool chosen, fail CI on drift.
  3. Auth from day one. Member-owned means member-only. The server should speak OAuth 2.1 with resource indicators from the first deploy, not bolted on in week seven. I did this for coolify-mcp v3 (OAuth, DCR, PRM) and for polar-flow-server; FastMCP makes the wiring short.
  4. A release gate, not a demo. Eight weeks is long enough to ship to production if the definition of done is written down. For coolify-mcp v3 that was 37 automated checks and an eight-hour soak before tag. I would agree the gate with the client in week one and run it every Friday.
Receipts

The numbers, with sources

9agents I run in production
19.0Mtokens through my hosted agents, 30d (644 calls, 10 models)
$18Workers AI spend for all of it, 30d, at list price
44Mtokens generated in my Claude Code sessions, 30d (72 sessions)
28apps in production on 1 server, run solo
564★ / 27.9kcoolify-mcp stars / npm installs, 30d

Operating numbers, last 30 days, generated 2026-08-27. Sources per tile in profile.json; hover a tile for its source.

coolify-mcpTypeScript · 42 tools · OAuth · outside contributors

Lets an agent run a self-hosted platform. v3 shipped behind a 37-check release gate and 8-hour soak tests. github.com/StuMason/coolify-mcp

TidyLinkerLaravel · React · Postgres · Stripe Connect

Two-sided cleaning marketplace. Took over an unrecoverable codebase, rebuilt it, live in four months. Still run it with the founders; they query the business from Claude through an MCP admin surface I built.

BellwetherPython · Postgres · Workers AI

A research agent drafts a daily briefing from 4.7M ingested items; a human approves it. Cost ceiling designed first, model chosen second.

polar-flowPython (FastAPI) · PyPI · MCP registry

Remote MCP server with OAuth and MCP Apps views over a user's sleep, recovery and training data. github.com/StuMason/polar-flow-server

Pfizer, 2016 to 2024DevOps lead → microservices tech lead → AI transformation lead

Platform behind 1000+ sites; 500M+ events during a Super Bowl advert. Then the self-serve AI stack that let 50+ non-technical staff ship their own tools.

Uno Mas, 2017 to 2019Founder · Mexican street food · Folkestone

Own money, own P&L, own staff, sixteen months.

Next step

What I am asking for

A call with the hedgehog lab lead on the build, then a real slice of the backlog and a day to ship it with tests. Rate on the call; outside IR35 through my limited company (£1m PI insured).

stu@stuartmason.co.uk · 07713 333312