kryos-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@kryos-mcprun my Kryos script with net and io capabilities granted"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
kryos-mcp
Governed code execution for AI agents, backed by the Kryos compiler's capability system. An MCP server that lets any client type-check, run, and capability-verify Kryos code — so an agent can only run code whose reach (network, filesystem, process, crypto, …) is declared and checked at compile time.
Why
Most "run this code" tools give an agent an unconstrained interpreter. kryos-mcp runs code through Kryos, where every function declares its capabilities (@capabilities(net, io)) and the compiler rejects anything that reaches further. verify_capabilities turns that into a governance verdict: ALLOW only if the code type-checks, every declared capability is inside the grant, and every function is annotated. Because Kryos enforcement is opt-in per function, unannotated functions are reported as UNCONSTRAINED rather than waved through.
Related MCP server: Code Executor MCP Server
Tools
Tool | What it does |
| Type-check without producing artifacts; surfaces type + capability errors. |
| Compile and run with a hard timeout; captures stdout/stderr/exit code. |
| Per-function capability manifest (JSON). |
| ALLOW/DENY against a capability grant; reports unconstrained functions. |
| Full audit: capability usage, extern/FFI surface, secret-pattern scan. |
files is an optional map of sibling .kry module files (name → content) so use <mod> resolves.
Install
Requires the Kryos toolchain on PATH (or set KRYOS_BIN).
npm install
claude mcp add kryos --scope user -- node /abs/path/to/kryos-mcp/server.mjsVerify
node smoke-test.mjs # spawns the server, exercises every tool incl. a DENY and an ALLOW verdictCapabilities reference
Valid grants (case-insensitive): net, io, ffi, compute, crypto, process, env, term, db, time, all. Notable gotchas the manifest reflects: env_get/exit require process; time_now requires time; network builtins require net.
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Build, validate, and deploy multi-agent AI solutions from any AI environment.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to launch and manage system processes with strict security controls through executable allowlists, resource monitoring, and output capture capabilities.36 npm1MIT
- AlicenseNot gradedqualityAmaintenanceProvides sandboxed code execution for AI agents with support for Python, JavaScript, and shell commands. Includes comprehensive safety features like destructive pattern blocking, timeout protection, and restricted file access for secure production use.9 npm113 PyPIMIT
- AlicenseNot gradedqualityCmaintenanceProvides isolated sandbox environments for AI agents to execute code securely, generating signed receipts for every execution to ensure auditability and trust.61 npm4MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to safely execute Python, JavaScript, and Bash code in an isolated Docker sandbox with strict security constraints.1-