No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by provos · MCP Server · ★ 609
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is ironcurtain safe to install? View the security audit →
IronCurtain A secure\ runtime for autonomous AI agents, where security policy is derived from a human-readable constitution. \When someone writes "secure," you should immediately be skeptical. What do we mean by secure? [!WARNING] Research Prototype. IronCurtain is an early-stage research project exploring how to make AI agents safe enough to be genuinely useful. APIs, configuration formats, and architecture may change. Contributions and feedback are welcome. Demo The agent is asked to clone a repository and push changes. Both and are escalated by the policy engine, but the auto-approver approves them automatically — the user's trusted input from command mode (Ctrl-A) provided clear intent, so no manual was needed. The Problem Autonomous AI agents can manage files, run g
| Stars | 609 |
| Forks | 79 |
| Language | TypeScript |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 74.080814665882/100 |
| Open Issues | 10 |
| Last Updated | 2026-09-21 |
| Created | 2026-02-21 |
| Platforms | mcp, node |
| Est. Tokens | ~20k |
Looking for a ironcurtain alternative? If you're comparing ironcurtain with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
A desktop MCP client designed as a tool unitary utility integration, accelerating AI adoption through the Mode
A production-ready runtime framework for agent apps with secure tool sandboxing, Agent-as-a-Service APIs, scal
MCP server for semantic code research and context generation on real-time using LLM patterns | Search naturall
Ultimate Context Engineering Infrastructure, starting from MCPs and Integrations
Official SonarQube MCP Server for code quality and security in AI agents
Explore other popular mcp server tools:
ironcurtain is A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev). It is categorized as a MCP Server with 609 GitHub stars.
ironcurtain is primarily written in TypeScript. It covers topics such as agent, mcp, model-context-protocol.
You can find installation instructions and usage details in the ironcurtain GitHub repository at github.com/provos/ironcurtain. The project has 609 stars and 79 forks, indicating an active community.
ironcurtain is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to ironcurtain on Agent Skills Hub include toolhive, tuui, agentscope-runtime. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: