{"_id":"@aegis.org/mcp","name":"@aegis.org/mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@aegis.org/mcp","version":"0.1.0","description":"Aegis AI governance as an MCP server — one policy decision point for Claude Code, Codex, Cursor, Antigravity, and any MCP host","license":"MIT","author":{"name":"Aegis AI"},"homepage":"https://aegis-ai.dev","repository":{"type":"git","url":"git+https://github.com/aegis-ai/aegis.git"},"keywords":["mcp","model-context-protocol","ai","governance","guardrails","agent","trajectory","aegis","chakravyuha","llm-safety"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","bin":{"aegis-mcp":"dist/server.js"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","test":"tsx --test test/*.test.ts","start":"node dist/server.js","prepublishOnly":"npm run build"},"dependencies":{"@modelcontextprotocol/sdk":"^1.18.0","zod":"^3.23.0"},"devDependencies":{"@types/node":"^22.0.0","tsup":"^8.3.0","tsx":"^4.19.0","typescript":"^5.4.0"},"engines":{"node":">=18"},"gitHead":"6f25349c2795fe8f0173363223d0d5543a55a704","_id":"@aegis.org/mcp@0.1.0","bugs":{"url":"https://github.com/aegis-ai/aegis/issues"},"_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-gwi4KJqLfo5qHhaC5qit5oLwlGZ+9cG6Rw7rJZnU8cZyH3e5ATS8pex4Xpruj1go/1k07MG44RQehfW+Z9TEZQ==","shasum":"8cf2bfdd2b494be7c5c1679f4fa0e5e962ba363a","tarball":"https://registry.npmjs.org/@aegis.org/mcp/-/mcp-0.1.0.tgz","fileCount":10,"unpackedSize":34115,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDaoldRfpUB3tBXhlQWSdXrN+Ry8yz9E7v/Mig+J8rwZgIgbjw4CshpPZRfoI+tHOVK/cqrTcSLawV6Q8zYUJMdHeM="}]},"_npmUser":{"name":"jash123","email":"jaswanthalkur@gmail.com"},"directories":{},"maintainers":[{"name":"jash123","email":"jaswanthalkur@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.1.0_1780759274928_0.8087903832137755"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-06T15:21:14.746Z","0.1.0":"2026-06-06T15:21:15.086Z","modified":"2026-06-06T15:21:15.334Z"},"maintainers":[{"name":"jash123","email":"jaswanthalkur@gmail.com"}],"description":"Aegis AI governance as an MCP server — one policy decision point for Claude Code, Codex, Cursor, Antigravity, and any MCP host","homepage":"https://aegis-ai.dev","keywords":["mcp","model-context-protocol","ai","governance","guardrails","agent","trajectory","aegis","chakravyuha","llm-safety"],"repository":{"type":"git","url":"git+https://github.com/aegis-ai/aegis.git"},"author":{"name":"Aegis AI"},"bugs":{"url":"https://github.com/aegis-ai/aegis/issues"},"license":"MIT","readme":"# @aegis.org/mcp — Aegis AI governance as an MCP server\n\n> One policy decision point. Every agent. No per-agent code.\n\nAegis governs whether an AI action is safe — PII redaction, attack/intent\ndetection, regulatory policy, and multi-step **agent-trajectory** verification\n(Ring 12). This package exposes that governance over the **Model Context\nProtocol**, the protocol Claude Code, Codex, Cursor, Antigravity, and other\nhosts all speak. Install it once and every MCP host routes through the same\nhosted backend — the *policy decision point* (PDP).\n\n```\n Claude Code ┐\n Codex CLI   ├─► aegis-mcp (stdio) ─► Aegis backend (PDP) ─► ALLOW / WARN / KILL\n Cursor      ┘                         one brain, many hosts\n```\n\n## Tools\n\n| Tool | Purpose |\n|---|---|\n| `aegis_analyze` | Govern a single query → response. Returns `decision` (ALLOW/BLOCK/SUPPORT/HITL), `category`, `risk_score`, `reason`, PII-redacted `safe_query`. |\n| `aegis_begin_session` | Open a Ring 12 trajectory session against an agent **goal**. Returns a `session_id`. |\n| `aegis_evaluate` | Evaluate one agent **step** *before* executing it. Returns `ALLOW` / `WARN` / `KILL_SESSION`, `hard_block`, and the five drift signals. |\n| `aegis_end_session` | Close a trajectory session; returns the drift rollup. |\n\nA backend that can't be reached returns an MCP **tool error** — the server\n**fails closed** (an unreachable governor never looks like an ALLOW).\n\n## Configuration\n\nThe server reads its backend target from the environment:\n\n| Var | Default | Notes |\n|---|---|---|\n| `AEGIS_BASE_URL` | `http://localhost:8000` | Hosted PDP URL. Non-loopback hosts **must** be `https://` (PII in transit). |\n| `AEGIS_API_KEY` | _(none)_ | Sent as `X-API-Key`. **Required** against a multi-tenant backend (`POSTGRES_URL` set) — a missing key is a hard `401`. |\n| `AEGIS_TENANT_ID` | `demo` | Tenant scope for trajectory sessions. |\n\n## Install & run\n\n```bash\nnpm i -g @aegis.org/mcp        # or: npx -y @aegis.org/mcp\naegis-mcp                      # serves over stdio\n```\n\n### Register with a host\n\n**Claude Code** (`~/.claude/settings.json` or project `.mcp.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"aegis\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aegis.org/mcp\"],\n      \"env\": {\n        \"AEGIS_BASE_URL\": \"https://api.aegis.dev\",\n        \"AEGIS_API_KEY\": \"aeg_xxx\"\n      }\n    }\n  }\n}\n```\n\n**Codex / Cursor / Antigravity / any MCP host** — same shape; point the host's\nMCP config at the `aegis` server above. The block is identical because the\ngovernance lives in the backend, not the adapter.\n\n## Programmatic use\n\n```ts\nimport { buildServer, AegisHttpClient } from '@aegis.org/mcp';\nconst server = buildServer(new AegisHttpClient({ baseUrl: 'https://api.aegis.dev', apiKey: 'aeg_xxx' }));\n// attach your own transport, or just run the `aegis-mcp` bin.\n```\n\n## Develop\n\n```bash\nnpm install\nnpm run typecheck\nnpm run build\nnpm test           # node:test via tsx — client + in-memory MCP server tests\n```\n\nMIT · part of [Aegis AI — Chakravyuha](https://aegis-ai.dev).\n","readmeFilename":"README.md","_rev":"1-e950b8b74f51a9ffa12d76b591ba1934"}