mcp-context-forge — security grade SAFE, quality 72/100

Security audit verdict: SAFE · quality 72/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by IBM · MCP Server · ★ 4.5k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-context-forge safe to install? View the security audit →

About mcp-context-forge

ContextForge An open source registry and proxy that federates MCP, A2A, and REST/gRPC APIs with centralized governance, discovery, and observability. Optimizes Agent & Tool calling, and supports plugins.           [![Deploy to

agentsaiapi-gatewayasyncioauthentication-middlewaredevopsdockerfastapifederationgateway

Quick Facts

Stars4,515
Forks886
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score72.0333751542074/100
Open Issues971
Last Updated2026-09-22
Created2025-05-08
Platformsdocker, k8s, mcp, python
Est. Tokens~23k

Compatible Skills

These tools work well together with mcp-context-forge for enhanced workflows:

  • bifrost — semantic(0.35)+shared_fw(anthropic,openai)+rare_topics+similar_pop+shared_platform (58%)
  • lm-proxy — semantic(0.18)+complementary+shared_fw(anthropic,openai)+same_lang+shared_platform (57%)
  • kiro-gateway — semantic(0.22)+complementary+rare_topics+same_lang+similar_pop+shared_platform (57%)
  • litellm — semantic(0.29)+shared_fw(anthropic,openai)+rare_topics+same_lang+shared_platform (56%)
  • agent-cli-to-api — semantic(0.16)+complementary+shared_fw(openai)+rare_topics+same_lang+shared_platform (53%)

mcp-context-forge alternative? Top 6 similar tools

Looking for a mcp-context-forge alternative? If you're comparing mcp-context-forge with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-agent by lastmile-ai · ⭐ 8.5k

    Build effective agents using Model Context Protocol and simple workflow patterns

  • bytebot by bytebot-ai · ⭐ 11.1k

    Bytebot is a self-hosted AI desktop agent that automates computer tasks through natural language commands, ope

  • valuecell by ValueCell-ai · ⭐ 11.0k

    ValueCell is a community-driven, multi-agent platform for financial applications.

  • voltagent by VoltAgent · ⭐ 10.4k

    AI Agent Engineering Platform built on an Open Source TypeScript AI Agent Framework

  • cursor-talk-to-figma-mcp by grab · ⭐ 7.0k

    TalkToFigma: MCP integration between AI Agent (Cursor, Claude Code, Codex) and Figma, allowing Agentic AI to c

  • sdk-python by strands-agents · ⭐ 6.0k

    A model-driven approach to building AI agents in just a few lines of code.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is mcp-context-forge?

mcp-context-forge is An AI Gateway, registry, and proxy that sits in front of any MCP, A2A, or REST/gRPC APIs, exposing a unified endpoint with centralized discovery, guardrails and management. Optimizes Agent & Tool call. It is categorized as a MCP Server with 4.5k GitHub stars.

What programming language is mcp-context-forge written in?

mcp-context-forge is primarily written in Python. It covers topics such as agents, ai, api-gateway.

How do I install or use mcp-context-forge?

You can find installation instructions and usage details in the mcp-context-forge GitHub repository at github.com/IBM/mcp-context-forge. The project has 4.5k stars and 886 forks, indicating an active community.

What license does mcp-context-forge use?

mcp-context-forge is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to mcp-context-forge?

The top alternatives to mcp-context-forge on Agent Skills Hub include mcp-agent, bytebot, valuecell. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools