ironcurtain — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by provos · MCP Server · ★ 609

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is ironcurtain safe to install? View the security audit →

About ironcurtain

IronCurtain A secure\ runtime for autonomous AI agents, where security policy is derived from a human-readable constitution. \When someone writes "secure," you should immediately be skeptical. What do we mean by secure? [!WARNING] Research Prototype. IronCurtain is an early-stage research project exploring how to make AI agents safe enough to be genuinely useful. APIs, configuration formats, and architecture may change. Contributions and feedback are welcome. Demo The agent is asked to clone a repository and push changes. Both and are escalated by the policy engine, but the auto-approver approves them automatically — the user's trusted input from command mode (Ctrl-A) provided clear intent, so no manual was needed. The Problem Autonomous AI agents can manage files, run g

agentmcpmodel-context-protocolpolicysandboxsecuritytrusted-process

Quick Facts

Stars609
Forks79
LanguageTypeScript
CategoryMCP Server
LicenseApache-2.0
Quality Score74.080814665882/100
Open Issues10
Last Updated2026-09-21
Created2026-02-21
Platformsmcp, node
Est. Tokens~20k

ironcurtain alternative? Top 6 similar tools

Looking for a ironcurtain alternative? If you're comparing ironcurtain with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • toolhive by stacklok · ⭐ 2.2k

    ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

  • tuui by AI-QL · ⭐ 1.2k

    A desktop MCP client designed as a tool unitary utility integration, accelerating AI adoption through the Mode

  • agentscope-runtime by agentscope-ai · ⭐ 847

    A production-ready runtime framework for agent apps with secure tool sandboxing, Agent-as-a-Service APIs, scal

  • octocode-mcp by bgauryy · ⭐ 838

    MCP server for semantic code research and context generation on real-time using LLM patterns | Search naturall

  • context-space by context-space · ⭐ 814

    Ultimate Context Engineering Infrastructure, starting from MCPs and Integrations

  • sonarqube-mcp-server by SonarSource · ⭐ 655

    Official SonarQube MCP Server for code quality and security in AI agents

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is ironcurtain?

ironcurtain is A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev). It is categorized as a MCP Server with 609 GitHub stars.

What programming language is ironcurtain written in?

ironcurtain is primarily written in TypeScript. It covers topics such as agent, mcp, model-context-protocol.

How do I install or use ironcurtain?

You can find installation instructions and usage details in the ironcurtain GitHub repository at github.com/provos/ironcurtain. The project has 609 stars and 79 forks, indicating an active community.

What license does ironcurtain use?

ironcurtain is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to ironcurtain?

The top alternatives to ironcurtain on Agent Skills Hub include toolhive, tuui, agentscope-runtime. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools