No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by chaitin · MCP Server · ★ 201
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is OctoBus safe to install? View the security audit →
中文版 README OctoBus is a locally running single-binary gateway for managing pluggable Node.js service packages and exposing the gRPC capabilities in those packages to clients or agents by capset. The current implementation provides a Go-built binary that is responsible for: daemon: start the local control plane and public data plane, and manage Node.js subprocesses according to each service runtime mode CLI: manage services, instances, and capsets through the local admin API gateway: expose selected methods as gRPC, and expose unary methods as Connect RPC and MCP streamable HTTP storage: use SQLite to record services, instances, capsets, method bindings, descriptors, and runtime state runtime management: import service packages, prepare runtime dirs, and manage long-running or on-demand Node.js instances Project Overview OctoBus is built around the following core model: service: a service root
| Stars | 201 |
| Forks | 91 |
| Language | JavaScript |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 67.6662574238369/100 |
| Open Issues | 259 |
| Last Updated | 2026-09-23 |
| Created | 2025-12-12 |
| Platforms | mcp, node |
| Est. Tokens | ~19k |
These tools work well together with OctoBus for enhanced workflows:
Looking for a OctoBus alternative? If you're comparing OctoBus with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A unified CLI for discovering and invoking tools across OpenAPI, MCP, GraphQL, gRPC, and JSON-RPC
Runtime Security for tool-using AI agents, with local policies, pre-action enforcement, and forensic audit tra
The open source, no-code MCP Server for AI-Native API Access
Task-scoped authorization for AI agents. Cryptographic warrants constrain tools and arguments, prevent privile
Cognitive Deterministic Memory Security OS for Agentic AI. Deterministic root-cause retrieval that reaches bac
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman
Explore other popular mcp server tools:
OctoBus is A secure local gateway for AI agents to reliably call approved enterprise APIs, tools, and services.. It is categorized as a MCP Server with 201 GitHub stars.
OctoBus is primarily written in JavaScript. It covers topics such as access-control, agent-tools, ai-agents.
You can find installation instructions and usage details in the OctoBus GitHub repository at github.com/chaitin/OctoBus. The project has 201 stars and 91 forks, indicating an active community.
OctoBus is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to OctoBus on Agent Skills Hub include uxc, kontext-cli, reshapr. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: