Mastyf AI MCP server
Runtime proxy for MCP security, cost governance & audit
20 stars246 downloads/wk
Reviews
Write oneNobody has reviewed Mastyf AI yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Mastyf AI tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it
- Code scansource not scanned: tarball over 25MB25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 1 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
What the publisher says
From the Mastyf AI repository's README, as published. We do not edit it. Read it on GitHub
mastyf.ai
Secure the Action Boundary, Not Just the Prompt.
A local reference monitor and security gateway for AI agents and MCP.Your LLM proposes actions. Mastyf decides whether those actions reach the real world.
Website · Quick start · Policy · Dashboard · GitHub
[!IMPORTANT]
Security Qualification Status: Levels 0–2 passed. Levels 3–5 are not complete (Level 4 physical chaos and Level 5 independent red team remain next/planned). Do not treat enterprise validation as shipped. See reports/enterprisesecurityqualification_report.json.
The problem
AI agents can read your files, push code, query databases, execute shell commands, and call external APIs. They do it autonomously, at machine speed.
Traditional security controls weren't built for that.
Mastyf.ai acts as a perimeter security layer for AI. It intercepts every tool call, evaluates it against your security policies using multi-agent swarm analysis, and blocks malicious or unauthorized actions before they execute.
Every decision is enforced, logged, and auditable.
What it stops
Quick start
🛡️ Mastyf Security Gateway & Protected Agent (Python Quickstart)
Run the local reference monitor, MCP discovery, and plain-English protected agent runtime:
# Install Mastyf Gateway package
git clone https://github.com/mastyf-ai/mastyf.ai.git
cd mastyf.ai/mastyf_gateway
pip install -e .
# Launch Mastyf (Auto-discovers tools, prompts for permissions, and starts protected agent)
mastyfShortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y @mastyf_ai/server on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mastyf.ai -- npx -y @mastyf_ai/server
Mastyf AI: common questions
- Is Mastyf AI MCP server safe?
- Mostly: it is graded B (80/100). Read the Mastyf AI safety report
- How do I install Mastyf AI?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Mastyf AI need an API key?
- Yes. The registry entry asks for
ALERT_WEBHOOK_URL. - Is Mastyf AI maintained?
- The last commit was in the last day (2026-09-25). The latest release is v4.1.12.
- What can I use instead of Mastyf AI?
- Servers from other publishers that do the same job: Bastion MCP server, MCPProxy MCP server and npm Registry MCP Server. Compare all Mastyf AI alternatives.
Alternatives to Mastyf AI
Same job from other publishers: the closest match first, then the best rated.
- BastionReliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.not reviewedGrowingA
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- grim-mcpSecurity audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.not reviewedGrowingC
- GuardvibeDeterministic security layer your AI can't be. 503 rules, 39 tools, CLI + doctor + host audit.not reviewedGrowingC