Skip to main content
Glama

kryos-mcp

Governed code execution for AI agents, backed by the Kryos compiler's capability system. An MCP server that lets any client type-check, run, and capability-verify Kryos code — so an agent can only run code whose reach (network, filesystem, process, crypto, …) is declared and checked at compile time.

Why

Most "run this code" tools give an agent an unconstrained interpreter. kryos-mcp runs code through Kryos, where every function declares its capabilities (@capabilities(net, io)) and the compiler rejects anything that reaches further. verify_capabilities turns that into a governance verdict: ALLOW only if the code type-checks, every declared capability is inside the grant, and every function is annotated. Because Kryos enforcement is opt-in per function, unannotated functions are reported as UNCONSTRAINED rather than waved through.

Related MCP server: Aegis MCP Server

Tools

Tool

What it does

kryos_check(code, files?)

Type-check without producing artifacts; surfaces type + capability errors.

kryos_run(code, files?, timeout_ms?)

Compile and run with a hard timeout; captures stdout/stderr/exit code.

capability_manifest(code, files?, strict?)

Per-function capability manifest (JSON).

verify_capabilities(code, files?, granted[], allow_unannotated?)

ALLOW/DENY against a capability grant; reports unconstrained functions.

kryos_audit(code, files?)

Full audit: capability usage, extern/FFI surface, secret-pattern scan.

files is an optional map of sibling .kry module files (name → content) so use <mod> resolves.

Install

Requires the Kryos toolchain on PATH (or set KRYOS_BIN).

npm install
claude mcp add kryos --scope user -- node /abs/path/to/kryos-mcp/server.mjs

Verify

node smoke-test.mjs   # spawns the server, exercises every tool incl. a DENY and an ALLOW verdict

Capabilities reference

Valid grants (case-insensitive): net, io, ffi, compute, crypto, process, env, term, db, time, all. Notable gotchas the manifest reflects: env_get/exit require process; time_now requires time; network builtins require net.

MIT.

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    An enforcement layer that validates AI agent actions against governance policies, including path permissions and content scanning, at runtime. It enables secure, role-based execution of file operations and commands with zero token overhead by processing policies independently from the agent's context.
    90
    3
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides sandboxed code execution for AI agents with support for Python, JavaScript, and shell commands. Includes comprehensive safety features like destructive pattern blocking, timeout protection, and restricted file access for secure production use.
    69
    MIT

View all related MCP servers

Related MCP Connectors

  • Build, validate, and deploy multi-agent AI solutions from any AI environment.

  • Runtime permission, approval, and audit layer for AI agent tool execution.

  • Sovereign Agent OS — Persistent Memory, Governance & Compliance for AI Agents.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/NORTHTEKDevs/kryos-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server