flux7-mesh
Allows CrewAI agents to be governed by the sidecar proxy, with policy enforcement and tracing.
Supports exporting traces to Datadog via OTLP HTTP for observability.
Wraps Docker CLI commands with policy, human approval, and tracing, allowing agents to run Docker commands under governance.
Integrates with GitHub CLI (gh) to execute GitHub commands under policy, approval, and tracing.
Supports exporting traces to Jaeger via OTLP for distributed tracing.
Allows LangChain agents to be governed by the sidecar proxy, with policy enforcement and tracing.
Allows governing calls to Ollama tools through policy rules, enabling control over local model access.
Exports traces in OTLP format to any OTLP-compatible backend (file, stdout, or HTTP).
Allows governing calls to SearXNG search engine tools through policy rules.
Imports OpenAPI/Swagger specs to expose REST APIs as governed tools, with policy and tracing.
Wraps Terraform CLI commands with policy, human approval, and tracing, enabling governed infrastructure management.
┌┬┐┌─┐┌─┐┬ ┬┌─┐
│││├┤ └─┐├─┤ │ agents ──▶ mesh7 ──▶ tools
┴ ┴└─┘└─┘┴ ┴ ┴ policy · approval · traceflux7-mesh
A governance proxy between AI agents and their tools. Policy, human approval and signed traces on every tool call, without changing agent code.
One Go binary, one YAML file, fail closed. Works with Claude Code, Cursor, Anthropic Managed Agents, the Agent SDK, LangChain, or anything that calls tools over MCP, HTTP or a CLI.
Full documentation: docs.flux7.art/mesh7
What it does
Policy | Allow, deny or ask, per agent and per tool: globs, conditions on arguments, per-agent files, hot reload. Writing policies |
Human approval | A call that needs a human waits in a queue (terminal, CLI, HTTP, console); time-boxed grants act as |
Emergency stop | Stop every call of one agent, one session or everything at once; pending approvals are denied, grants revoked and put back on resume. CLI, HTTP and console. Emergency stop |
Traces | Every call and decision, grouped by session, HMAC hash-chained and verifiable, exported over OTLP. Trace integrity · Observability |
Tool catalogue | Each tool classified (named or generic, read or write) from what it declares; a draft policy from |
Identity | JWT from your IdP, including the human an agent acts for. JWT authentication |
Delegation | Past decisions auto-approve through flux7-memory; an L1 supervisor resolves the rest through flux7-supervisor. Memory integration |
Provenance | Every call to an MCP upstream carries its trace in |
Related MCP server: agent-sudo-mcp
How it sits
flowchart LR
A["Agents<br/>Claude Code · Cursor · Agent SDK<br/>LangChain · Managed Agents"]
M["mesh7<br/>identity → rate limit → policy<br/>→ approval → forward → trace"]
T["Tools<br/>MCP servers · REST APIs (OpenAPI)<br/>CLI binaries"]
O["Traces<br/>JSONL · OTLP"]
A -- "MCP stdio / HTTP · HTTP" --> M --> T
M --> OAgents see an ordinary tool surface. The operator sees every decision.
Install
curl -fsSL https://raw.githubusercontent.com/KTCrisis/flux7-mesh/main/install.sh | shInstalls mesh7 (the proxy) and mesh (the approval CLI) in ~/.local/bin. Add -s -- --service to also run mesh7 as a systemd user service, or --system where the user manager is unavailable (some WSL setups). By hand:
curl -L https://github.com/KTCrisis/flux7-mesh/releases/latest/download/mesh7_linux_amd64.tar.gz | tar xz
sudo mv mesh7 mesh /usr/local/bin/Other targets: mesh7_darwin_arm64.tar.gz, mesh7_linux_arm64.tar.gz, mesh7_windows_amd64.zip… (releases). From source (Go 1.24+): make install. Python SDK and the Claude Code harness hook: pip install flux7-mesh (Python SDK).
Quick start
# config.yaml
mcp_servers:
- name: filesystem
transport: stdio
command: npx
args: ["-y", "@modelcontextprotocol/server-filesystem", "/home/me/projects"]
policies:
- name: claude
agent: "claude"
rules:
- tools: ["filesystem.read_*", "filesystem.list_*"]
action: allow
- tools: ["filesystem.write_file", "filesystem.edit_file"]
action: human_approval
- name: default
agent: "*"
rules:
- tools: ["*"]
action: denymesh7 discover --config config.yaml --generate-policy # or start from a commented draft
claude mcp add mesh7 -- mesh7 --mcp --config config.yamlRestart Claude Code: the tools are there, the rules apply, every call is traced. When a call needs approval, the agent relays an id: run mesh approve <id> (or use the console), and its retry of the same call goes through. For a long-running daemon, OpenAPI and CLI sources, and every YAML key, see Getting started and Configuration.
Documentation
Reference: commands, flags, HTTP API, project layout, tests
Next
Policy on the delegation: rules on the pair this agent, for this user, from the identity the token already carries.
Conditions v2: AND/OR, claims from the token, parsed arguments instead of text matching.
Policy on content: a local classifier annotates arguments and results (indirect injection first); the condition engine decides.
Shipped features are listed per version in the releases.
Why a mesh
Envoy sits between services and adds identity, policy and telemetry without changing their code. mesh7 does the same between agents and their tools: invisible to the agent, visible to the operator.
License
Apache 2.0
This server cannot be deployed
Maintenance
Related MCP Connectors
Fail-closed policy guardrails for AI agents running kubectl, terraform, helm, and argocd.
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Related MCP Servers
- AlicenseAqualityBmaintenanceSecurity, cost, and health governance proxy for MCP infrastructure. Enforces YAML-configurable security policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features OAuth 2.1/OIDC with RBAC, web dashboard, payload normalization, semantic shell AST analysis, mTLS, and a formal STRIDE threat model.476 npm3MIT
- AlicenseAqualityBmaintenanceLocal zero-trust permission gateway for AI agents. Enforces policy-based tool authorization, human approvals, scoped permissions, and cryptographically verifiable audit logs.439 PyPI5Apache 2.0

aperion-shieldofficial
FlicenseAqualityAmaintenanceLocal guardrail proxy for AI coding agents. Wraps any MCP server (stdio or HTTP/SSE) and blocks destructive tool calls before they execute, with TOFU catalog pinning against rug pulls and tool-poisoning/result-injection scanning. Single Rust binary, Apache-2.0.1411-- AlicenseNot gradedqualityAmaintenanceA minimal guardrails framework for AI agents, acting as an MCP proxy to enforce policies, approvals, and audit logging on tool calls.1MIT