The io.github.mastyf-ai/mastyf.ai server provides a runtime proxy for MCP security, cost governance, and an audit trail for AI actions. Its purpose is perimeter security through runtime enforcement and policy control, as described in the repository excerpt.
๐ ๏ธ Key Features
Runtime enforcement
Policy control
Full audit trail for every AI action
Cost governance (for MCP usage)
๐ Use Cases
Securing MCP interactions with runtime checks
Applying policy governance to AI actions
Auditing AI activity in an MCP context
Controlling cost during AI agent operations
โก Developer Benefits
Centralized runtime enforcement for MCP security
Policy-driven governance for AI action execution
Audit trail support for tracking AI actions
Cost governance for operational oversight
โ ๏ธ Limitations
The provided excerpt does not specify supported platforms, configuration options, or concrete tool interfaces.
AI agents can read your files, push code, query databases, execute shell commands, and call external APIs. They do it autonomously, at machine speed.
Traditional security controls weren't built for that.
Mastyf.ai acts as a perimeter security layer for AI. It intercepts every tool call, evaluates it against your security policies using multi-agent swarm analysis, and blocks malicious or unauthorized actions before they execute.
Every decision is enforced, logged, and auditable.
What it stops
Threat
What it looks like
Prompt injection
Malicious instructions embedded in tool arguments to hijack agent behavior
Path traversal
Attempts to access /etc/passwd, .ssh/id_rsa, .aws/credentials
Secret exfiltration
API keys and tokens leaking through tool arguments
If the dashboard is running, verify the HTTP bridge:
bash
curl -X POST http://localhost:4000/mcp -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","id":"1","method":"tools/list","params":{}}'
Dashboard
Full visibility into every action your AI takes.
20260628-1234-42 0110563
Section
What you see
Protection
Block rate, top triggered rules, live threat feed
Activity
Every tool call with full arguments, allow or block status, timestamp
Policy
Live rule editor with hot-reload from YAML
Threat Lab
AI-suggested attack tests, reviewed and approved before anything applies
Cost
Token usage and cost estimates broken down per tool call
Do not expose port 4000 publicly without enabling dashboard auth. The default local dev config has DASHBOARD_AUTH_DISABLED=true.
How enforcement works
Every tool call passes through three layers before it reaches your infrastructure.
Layer 1 - Pattern detection
Regex-based scanning for injection, dangerous paths, leaked secrets, shell commands, and encoding tricks. Runs in microseconds with no external dependencies.
Layer 2 - Schema validation
Rejects malformed payloads, oversized arguments, and JSON-RPC violations before they reach policy evaluation.
Layer 3 - Semantic review
An optional local LLM (Ollama) or cloud model evaluates borderline calls that pass pattern checks. Falls back to heuristics if no model is configured.
Anything that fails is blocked. The tool never runs. Everything is logged.
image
Policy
Your rules live in default-policy.yaml. You own them. mastyf.ai enforces them.
Pre-built templates for HIPAA, PCI-DSS, GxP, and data residency are in policy-templates/.
image
Architecture
mastyf.ai runs two coordinated swarms. The CI Swarm attacks your policy before code ships. The Runtime Swarm enforces and learns from every live tool call in production. Four feedback loops connect them so the system gets harder to bypass over time.
flowchart TB
AI["๐ค AI Clients\nCursor ยท Claude Desktop ยท Cline"]
subgraph CI["๐ต CI Swarm (PR + Nightly)"]
direction LR
Scout["๐ Scout Agent\nSAST, deps, config scan"]
Corpus["๐ Corpus Agent\n228 fixtures eval"]
Evasion["โก Evasion Agent\n120+ probes + generate new"]
Parity["๐ Parity Agent\nNode vs Python"]
ProxyA["๐ฅ๏ธ Proxy Agent\nLive stdio MCP tests"]
Report["๐ Report Agent\nsecurity-swarm/latest.json"]
Scout --> Corpus --> Evasion --> Parity --> ProxyA --> Report
end
subgraph Runtime["๐ข Runtime Swarm (Production Proxy)"]
direction LR
BG["๐ก๏ธ BlockGuard\nsync policy"]
IL["๐ InstantLearner\nper-block stats + suggestions"]
SA["๐ง SemanticAuditor\nasync LLM, optional"]
PS["๐ PatternSynthesizer\nbatch suggestions"]
Cal["โ๏ธ Calibrator\nlabels + thresholds"]
BG --> IL --> PS --> Cal
BG --> SA --> PS
end
Tools["๐๏ธ MCP Tools\nfilesystem ยท GitHub ยท databases ยท APIs"]
AI -->|"every tool call"| BG
BG -->|"โ allowed"| Tools
Report -->|"๐ Loop A: bypasses to corpus"| Corpus
Cal -->|"๐ Loop B: blocks to rules"| BG
Cal -->|"๐ Loop C: labels to LLM"| SA
Report -->|"๐ Loop D: CI metrics weekly"| Cal
style CI fill:#EFF6FF,stroke:#3B82F6,stroke-width:2px,color:#1E3A5F
style Runtime fill:#F0FDF4,stroke:#22C55E,stroke-width:2px,color:#14532D
style Scout fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style Corpus fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style Evasion fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style Parity fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style ProxyA fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style Report fill:#DBEAFE,stroke:#3B82F6,color:#1E40AF
style BG fill:#BBF7D0,stroke:#16A34A,color:#14532D
style IL fill:#BBF7D0,stroke:#16A34A,color:#14532D
style SA fill:#BBF7D0,stroke:#16A34A,color:#14532D
style PS fill:#BBF7D0,stroke:#16A34A,color:#14532D
style Cal fill:#BBF7D0,stroke:#16A34A,color:#14532D
style AI fill:#FEF3C7,stroke:#F59E0B,stroke-width:2px,color:#78350F
style Tools fill:#FEF3C7,stroke:#F59E0B,stroke-width:2px,color:#78350F
Threat Lab watches live traffic and uses a local LLM to propose new attack test cases when it detects suspicious patterns. Nothing is applied automatically. You review and approve every suggestion in the dashboard before it becomes a rule.
Approved discoveries feed back into the CI attack corpus for ongoing regression testing.
Before installing any MCP server from npm, check its trust score at https://www.mastyf.ai/certified. Scores cover CVE exposure, typo-squat risk, maintainer signals, and known attack patterns. Free, no account required.
Common commands
Command
What it does
node dist/cli.js start
Start proxy and dashboard on port 4000
node dist/cli.js onboard
Wrap your MCP config to route through the proxy
node dist/cli.js doctor
Health check for DB, policy, and environment
node dist/cli.js scan --all
Scan MCP configs for CVEs and injection risks
pnpm test
Run the full test suite
pnpm security-swarm:fast
Quick security regression, 5 to 15 minutes
pnpm security-swarm:analyze
Full adversarial analysis
Troubleshooting
Problem
Fix
Dashboard shows no data
Proxy and dashboard must share the same MASTYF_AI_DB_PATH. Default is ~/.mastyf-ai/history.db
dist/cli.js not found
Run pnpm build
AI still hitting tools directly
Run node dist/cli.js onboard --apply
Ollama warnings at startup
Run ollama serve or remove MASTYF_AI_LLM_PROVIDER from your environment
npm install fails
npm publish is not live yet. Use git clone and pnpm install