koma-gate-mcp
Allows using Google's Gemini models to classify untrusted user input for prompt injection and scope checking.
Allows using locally hosted models via Ollama to classify untrusted user input for prompt injection and scope checking.
Allows using OpenAI's models (e.g., GPT) to classify untrusted user input for prompt injection and scope checking.
Koma Gate MCP
Expose Koma Gate's prompt-injection classification as an MCP tool for AI agents.
npm install koma-gate-mcpWhat it does
Provides a single tool, classify_input, that an AI agent can call to check whether untrusted user text is safe and in-scope before acting on it.
Related MCP server: agent immune
Setup
Set the provider and API key:
# Provider: openai | anthropic | google | deepseek | ollama (default: google)
export KOMA_PROVIDER=google
export GEMINI_API_KEY=sk-...Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"koma-gate": {
"command": "npx",
"args": ["-y", "koma-gate-mcp"]
}
}
}Tool: classify_input
text(required) — the untrusted user input to classifypreset(optional) —general|code|support|reference(default: general)
Returns:
{
"allowed": true,
"in_scope": true,
"reason": "in scope",
"preset": "general",
"model": "gemini-2.5-flash"
}Security Boundary
This is an LLM-based scope classifier, not a cryptographic prompt-injection defense. See koma-gate's README for the full security boundary and BENCHMARKS.md for evaluation results.
Maintenance
Tools
Related MCP Servers
- Alicense-qualityDmaintenanceA lightweight stdio proxy that intercepts and rewrites MCP tool annotations to bypass security approval prompts in AI CLIs like Codex and Claude Code. It transparently passes through all tool operations while marking them as safe to ensure a seamless automation experience.1110MIT
- Alicense-qualityCmaintenanceAdaptive security for AI agents: assess inputs for prompt injection, scan outputs for credential/PII leaks, teach new attack patterns to semantic memory, harden prompts, and monitor metrics. Runs locally via MCP stdio.Apache 2.0

jamjet-policyofficial
AlicenseAqualityBmaintenanceDrop-in stdio interceptor that gates MCP tools/call requests through a YAML policy (block / require_approval / audit / budget cap) before they reach the real server. The same policy file is reused by @jamjet/claude-code-hook and @jamjet/openai-guardrail, so one rule set covers Claude Desktop, Cursor, OpenAI Agents, and custom clients.32Apache 2.0
Blekline MCP Serverofficial
AlicenseAqualityAmaintenanceProvides AI ingress governance by masking prompts, classifying risk, and enforcing tool policies before agent calls reach model providers or sandboxes.61AGPL 3.0
Related MCP Connectors
The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
Deterministic trust gate for AI output: leaked-secret, prompt-injection & PII in one call.
Decision-only prompt routing and firewall checks for local/cloud routing, PII and jailbreak risk.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/swnotmetal/Project-Koma'
If you have feedback or need assistance with the MCP directory API, please join our Discord server