Fail-closed MCP adapter for untrusted model output over a local Tkach runtime.
io.github.ECD5A/tkach-security (MCP Server)
This MCP server is a fail-closed adapter for untrusted model output over a local Tkach runtime. It is intended to handle and constrain responses produced by a model, ensuring that processing defaults to a restrictive behavior when output cannot be trusted.
🛠️ Key Features
Fail-closed behavior for untrusted model output
Operates over a local Tkach runtime
🚀 Use Cases
Adapting model output in local Tkach runtime environments where output trust is not guaranteed
⚡ Developer Benefits
Clear safety posture via fail-closed handling of untrusted model output
⚠️ Limitations
Described only at the level of fail-closed handling and local Tkach runtime integration; no additional capabilities were provided
Put Tkach between model proposals and protected actions. Its Rust Core checks
authority and information flow before allowing an action or releasing output.
Model output remains untrusted data, even when the model is compromised.
Why Tkach
Explicit authority: protected actions need an exact-scope, Core-issued
Propusk; model text cannot create one.
Controlled data flow: permission to read is not permission to export.
Provenance and release checks remain inside the boundary.
Fail-closed decisions: invalid, denied, replayed, cancelled, or uncertain
states do not silently become permission.
Isolated secrets and bounded evidence: broker-held secrets stay outside
ordinary model context; Sled receipts do not include payloads.
These guarantees apply to paths routed through Tkach. It does not make the
model trustworthy, detect every prompt injection, or protect a compromised host.
init creates a starter request without overwriting files; check validates
its schema, not permission to execute; run --demo exercises the offline
boundary without a model connection. Use tkach ui for the interactive panel.
Prefer no Rust toolchain? Download a binary below and start with tkach init.
Binary archives include SHA-256 manifests, keyless Sigstore bundles, and GitHub
build attestations. Pin the OCI digest for deployment; verification details
live in the distribution guide.
Integrate without moving policy out of Rust
Use the HTTP contract from
your application, the Rust client,
a Python/JS/TS/Go client,
or the stdio adapter from an MCP client.
Clients and MCP require a separately started local tkach serve runtime and
its bearer token; installing a package does not enable background protection.
tkach-core stays provider-, protocol-, and language-independent. Adapters
transport requests; policy and authority stay in Rust. Follow the
integration guide or copy a working examples/
scenario. The Go client is a source module, not a separate registry package.
The supported runtime is loopback-only by default. Public internet serving,
TLS termination, Streamable HTTP, a cloud control plane, and a generic executor
are not included; see the deployment contract.
Show the cross-platform CLI window
See the boundary in action
From a repository checkout, run the offline Golden Case. It needs no model
service or credentials. It performs one create-only write inside a temporary
sandbox, then proves that a sibling path and a compromised provider proposal
are denied:
console
cargo run -p tkach-gateway --example golden_case --locked
The positive path uses trusted host configuration for the exact policy,
destination, and executor binding; the provider supplies only an untrusted
proposal. Read the architecture for the enforcement
path and the release notes for the release checks and
remaining limitations.
Keep changes small and explicit about the security boundary. Core changes need
a demonstrated security or product defect; adapters must remain thin and must
not duplicate Core logic. See CONTRIBUTING.md for required
checks, public-claim rules, and files that must remain local.
Support
If Tkach Security is useful to your work, support its continued maintenance:
TON: pointoncurve.ton
Bitcoin (BTC): 1ECDSA1b4d5TcZHtqNpcxmY8pBH1GgHntN
USDT (TRC20): TUF4vPdB6QkjCvZq18rBL4Qj4dK5ihCN75
Contact
For inquiries about Tkach Security, integrations, security research, or collaboration: