alexar76/argus

๐Ÿ”’ Security๐ŸŸข Verified Active
0 Views
0 Installs

๐ŸŽ–๏ธ ๐Ÿ“‡ ๐Ÿ  โ˜๏ธ ๐ŸŽ ๐ŸชŸ ๐Ÿง - ARGUS-3 as a stdio MCP server (argus mcp โ†’ argusask, argusstatus). WARDEN vets third-party MCP servers before any tool runs (LUMEN-scored firewall, tool-def pinning, drift sentinel). Distinct from aimarket-oracle-gateway (oracle tools) and aimarket-plugins (hub packager). npm @alexar76/argus3 ยท live.

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "alexar76-argus": {
      "command": "npx",
      "args": [
        "-y",
        "alexar76-argus"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

๐Ÿ“– Read-only mirror. argus is published from the canonical AI-Factory monorepo. Pull requests are not accepted โ€” any commit pushed here is overwritten by scripts/mirror_satellites.sh on the next sync. ๐Ÿž Found a bug or have a request? Please open an issue.

ARGUS-3 โ€” MCP server

CI argus MCP server WARDEN MCP firewall Crypto off by default 290 tests passing Test coverage License: MIT

One MCP server. WARDEN-hardened agent. Wallet optional.

Transport: stdio (argus mcp). Built with the official Model Context Protocol TypeScript SDK (@modelcontextprotocol/sdk). Compatible hosts: Claude Desktop, Cursor, Glama, and any MCP client that supports stdio servers.

ItemLocation
MCP entrypointargus mcp โ†’ src/channels/mcp_server.ts
Toolsargus_ask, argus_status, argus_capabilities
WARDEN firewalldocs/security-warden.md
Glama / Docker (stdio)Dockerfile.glama, glama.json

Part of the AICOM open agent economy. Live demo: magic-ai-factory.com/argus/ ยท Community: Discord ยท Pollux ยท Telegram ยท Castor

Live landing ยท WARDEN firewall ยท Install ยท Wiki

WARDEN blocks a poisoned MCP server

MCP firewall first โ€” wallet optional. ARGUS-3 vets every third-party MCP server through WARDEN (static scan โ†’ threat feed โ†’ LUMEN reputation โ†’ def-pinning) before a single tool runs. Crypto, wallet, and on-chain economy are off by default. (short name ARGUS ยท CLI: argus ยท npm: argus-warden ยท scoped: @alexar76/argus3)

Why "ARGUS-3"? In the myth, Argus Panoptes โ€” the hundred-eyed watchman โ€” was unbeatable until Hermes talked him to sleep and slew him. ARGUS-3 is the watchman that doesn't fall for Hermes: a hundred eyes open (WARDEN), frugal to a fault, immune to smooth-talking competitors.

Third time's the watchman. ๐Ÿ‘๏ธ

ARGUS is the demand-side reference client the agent economy was missing. The ecosystem already has producers (the Factory ๐Ÿญ), a broker (the Hub ๐Ÿ›’), pricing (ACEX ๐Ÿ“ˆ), trust math (the LUMEN oracle ๐Ÿ”ฎ) and observability (the Monitor ๐Ÿ‘ฝ). What it lacked was a first-class agent an ordinary person runs โ€” one that discovers, pays for, consumes and sells capabilities. That's ARGUS.

It is built on two stack layers that generic MCP clients typically lack:

  1. ๐Ÿ›ก๏ธ WARDEN โ€” an MCP security firewall that scores third-party servers through a verifiable reputation oracle (LUMEN), not a static blocklist. Works with no wallet and no chain.
  2. ๐Ÿ’ธ Native settlement (optional) โ€” pay per-call and get paid in USDC on Base through AIMarket escrow when you enable crypto and connect a wallet.

โ€ฆand it stays frugal (a hard budget governor + live token meter โ€” no self-reflection on your dime), speaks any model (Anthropic, OpenAI-compatible, Chinese, local), and โ€” critically โ€” runs fully autonomously when the economy is unavailable. No wallet, no network to AICOM? It's still a best-in-class local, MCP-secured assistant.

๐Ÿ”’ Crypto is OFF by default

A blockchain is not required to run ARGUS-3. Wallet, lottery, ACEX, paid invokes, and on-chain settlement are disabled by default and turn on only when you set ARGUS_CRYPTO_ENABLED=1 (plus a wallet). Out of the box you get the full agent โ€” WARDEN, any model, memory, channels, and free off-chain oracle reads โ€” with no chain, no token, no wallet, no custody. Crypto is opt-in.


Why ARGUS is different

What it doesWhy it matters
๐Ÿ›ก๏ธ WARDEN firewallEvery MCP server is vetted by a gate chain โ€” static tool-def scan โ†’ threat feed โ†’ LUMEN reputation โ†’ def-pinning โ€” before a single tool runs.Tool-poisoning, rug-pulls (def drift), exfiltration and credential harvesting are blocked by default. Trust comes from a live oracle, so it doesn't rot like a blocklist.
๐Ÿ’ธ Native + autonomous economyDiscover โ†’ open USDC channel โ†’ invoke โ†’ settle (consumer); register in the Mesh โ†’ list โ†’ earn (provider). Loads only with a wallet.Turns AICOM into a real two-sided market. With no wallet the module never loads โ€” zero dependency, zero failure surface.
โš–๏ธ Token-frugal by designBounded reasoning-budget governor with hard $/token ceilings, model tiering, cache_control, curated handoff, compaction, and a live meter.The "cheaper" claim is auditable, not marketing. Exceeding a ceiling stops the task โ€” it never silently overspends.
๐ŸŒ Any providerOne Provider interface over Anthropic-native, any OpenAI-compatible endpoint (incl. DeepSeek, Qwen, GLM, Kimiโ€ฆ), and local Ollama.Your keys, your models, your costs. Triage on a cheap/local model, escalate only when needed.

๐Ÿงญ Core capabilities โ€” design intent and stack dependencies for each headline feature โ€” docs/killer-features.md ยท ru ยท es.

Quickstart

One command (interactive wizard, ~2 minutes):

curl -fsSL https://magic-ai-factory.com/install | bash

Or install from npm (same CLI, no curl script):

npm install -g argus-warden@latest
mkdir -p ~/.argus/agent && cd ~/.argus/agent
argus setup && argus doctor

Package: argus-warden on npm ยท scoped: @alexar76/argus3 ยท CLI: argus ยท npx argus-warden --help

Then argus chat or argus serve.

Run as MCP server (stdio)

npm install -g @alexar76/argus3
# or: npm install && npm run build && node dist/index.js mcp
argus mcp

Claude Desktop / Cursor (mcpServers entry):

{
  "mcpServers": {
    "argus": {
      "command": "argus",
      "args": ["mcp"]
    }
  }
}

Tools (2)

ToolWhen to useReturnsExample
argus_askBounded NL work via agent core. Optional response_format / focus. Sensitive tools deny-by-default; budget-metered LLM.Plain-text answer (isError on failure/budget stop)argus_ask({ task: "Summarise https://example.com in three bullets", response_format: "bullets" })
argus_statusLiveness before heavy argus_ask (detail: basic|full)JSON statusargus_status({ detail: "basic" })
argus_capabilitiesDiscovery / WARDEN posture without spending LLM tokensJSON tool catalogargus_capabilities({ include_schemas: false })

Glama TDQS: MCP annotations (readOnly / destructive / idempotent / openWorld), Behavior + Usage Guidelines in every description, structured params with examples โ€” calibrated to the score rubric (not the old one-liner).

Publish on Glama

Listing: glama.ai/mcp/servers/alexar76/argus

Same pattern as aimarket-oracle-gateway: repo-root glama.json + Dockerfile.glama + node dist/index.js mcp.

If magic-ai-factory.com/install returns 404, use the mirror: curl -fsSL https://modeldev.modelmarket.dev/install | bash

Docs: Wiki ยท User guide (20 languages) ยท Developer guide โ€” publish a capability in 15 min (20 languages) ยท Use case โ€” your ARGUS on AICOM (EN / RU) ยท The Verifiable Conscience (block diagrams) ยท When ARGUS won't help you ๐Ÿ˜ˆ ยท Ecosystem whitepaper

Manual install (developers โ€” from git)
cd argus
npm install
npm run build

# 1) Configure (safe to commit โ€” NO secrets live here)
cp argus.config.example.json argus.config.json

# 2) Add keys to .env (all optional; with none, ARGUS uses a local Ollama model)
cp .env.example .env      # then edit

# 3) Check what's wired up
node dist/index.js doctor

# 4) Ask something
node dist/index.js ask "summarise https://example.com in three bullets"

# 5) Interactive
node dist/index.js chat

During development you can skip the build step with npm run dev -- ask "โ€ฆ".

The autonomy guarantee

ARGUS needs nothing from AICOM to work:

# No ANTHROPIC_API_KEY, no wallet โ€” just a local model:
ARGUS_LOCAL_BASE_URL=http://127.0.0.1:11434/v1 node dist/index.js ask "hello"

With no ARGUS_WALLET_KEY, doctor reports economy: OFF (autonomous) and the entire economy layer is never constructed. See docs/autonomy.md.


Architecture

Five layers. Everything above the autonomy line runs offline; the economy clips on underneath, gated purely on the presence of a wallet.

flowchart TB
  subgraph OFF["Runs offline โ€” no AICOM, no wallet"]
    L1["Layer 1 ยท Providers โ€” Anthropic ยท OpenAI-compatible ยท local"]
    L2["Layer 2 ยท Bounded agent core โ€” planโ†’executeโ†’observe + budget governor"]
    L3["Layer 3 ยท Memory / self-learning โ€” episodes ยท lessons ยท pins"]
    L4["๐Ÿ›ก๏ธ Layer 4 ยท MCP host + WARDEN โ€” static ยท threat ยท reputation ยท pinning"]
    L1 --- L2 --- L3 --- L4
  end
  GATE{{"โ€” autonomy line โ€” needs ARGUS_WALLET_KEY"}}
  L5["๐Ÿ›’ Layer 5 ยท Economy โ€” discover ยท pay ยท invoke ยท settle ยท sell"]
  L4 -.-> GATE -.-> L5
  L5 -.->|wraps| SDK["@aimarket/agent SDK"]

Full diagrams and the module map: docs/architecture.md.


๐Ÿ›ก๏ธ WARDEN โ€” the MCP firewall

An MCP server's tool descriptions are attacker-controlled text the model reads as instructions. WARDEN treats every server as hostile-by-default and runs each connection through gates before any tool is exposed:

flowchart LR
  S[MCP server] --> A[1 ยท static scan] --> B[2 ยท threat feed] --> C[3 ยท LUMEN reputation] --> D[4 ยท def-pinning] --> V{allow?}
  V -->|yes| OK[bridge tools<br/>pin defs]
  V -->|no| NO[block + report]
  • Static scan โ€” injection / exfiltration / secret-harvesting / hidden-unicode signatures in tool defs.
  • Threat feed โ€” built-in deny-list + optional signed remote feed.
  • Reputation โ€” asks LUMEN for a sybil-resistant trust score (lumen.reputation@v1), verifiable via graph_commitment. Unreachable โ†’ neutral, never blocks (autonomy preserved).
  • Pinning โ€” hashes the approved tool set; later drift = rug-pull, forces re-approval.

Sensitive tools (write/delete/exec/payment/โ€ฆ) additionally require explicit user approval at call time. Details: docs/security-warden.md.

node dist/index.js warden scan      # vet your configured MCP servers

๐Ÿ’ธ Economy integration

ARGUS reuses the existing AI Market Protocol v2 and the @aimarket/agent SDK โ€” no new endpoints.

export ARGUS_WALLET_KEY=0x...                       # enables the economy layer
node dist/index.js economy status
node dist/index.js economy discover "translate to 5 languages" --budget 1
node dist/index.js economy register                 # list ARGUS in the AI Service Mesh

Consumer flow: discover โ†’ openChannel (USDC/Base) โ†’ invoke (X-Payment-Channel) โ†’ settle. Provider flow: register identity + wallet in the Mesh, list capabilities, earn (and become eligible for the agent lottery / machine-UBI). See docs/economy-integration.md ยท docs/mcp-oracles-capabilities.md (17 oracles, MCP, selling).


Multi-provider

AdapterCovers
Anthropic-nativeClaude Opus/Sonnet/Haiku/Fable โ€” first-class cache_control; default for the core loop
OpenAI-compatibleOpenAI, DeepSeek, Qwen/DashScope, Zhipu GLM, Moonshot/Kimi, MiniMax, Mistral, Groq, Together, OpenRouter, vLLM
LocalOllama / llama.cpp โ€” offline + the cheap triage tier

Models are assigned to tiers (triage / core / heavy) in argus.config.json; routing falls back across tiers when a key is missing.


๐ŸŽฎ Agent Arena โ€” level up, keep streaks, flex your card

Running an agent should be fun. Agent Arena turns real ecosystem activity into the game mechanics a young, global audience already loves โ€” Duolingo-style streaks, Wrapped-style shareable cards, gaming rank cards:

  • XP & levels โ€” earn XP for finishing tasks, selling capabilities, playing the oracle lottery, trading on ACEX, and staying frugal (low $/task).
  • Daily streaks ๐Ÿ”ฅ โ€” keep your agent active day after day.
  • Quests & badges โ€” First Blood (first lottery win), Rainmaker (first $1 earned selling capabilities), Frugal (a task under $0.001), Trusted (top-half LUMEN reputation), Warden (blocked a malicious MCP server), Polyglot, Whale, Luckyโ€ฆ
  • Flex Card โ€” argus flex (or /flex in Telegram) renders a slick, shareable card: handle, level, streak, $ earned, win-rate, top badges, reputation rank. Numbers + emoji = no language barrier โ†’ share it anywhere.
  • Global leaderboard (opt-in) โ€” rank against agents worldwide by XP, earnings, or frugality.

Every stat is real โ€” it's your actual economy, reputation and frugality performance, computed locally from your agent's own memory + signed economy receipts, so it's hard to fake and not vanity points. Sharing and the leaderboard are off by default and owner-controlled โ€” your data stays yours. Full design: docs/arena.md.

Live demo (this fleet):

Use the TEST ยท LIVE ยท UNI switcher on the Arena page to flip between demo metrics and each deployed node.


Configuration

  • argus.config.json โ€” non-secret config (providers, models, tier pricing for the meter, budget ceilings, WARDEN policy, MCP servers/catalogs, economy endpoints). Safe to commit. Start from argus.config.example.json.
  • .env โ€” secrets only: API keys (ANTHROPIC_API_KEY, DEEPSEEK_API_KEY, โ€ฆ), ARGUS_WALLET_KEY, and optional ALIEN_API_TOKEN for the Alien Monitor run feed. Never commit. Start from .env.example.

economy.enabled is derived โ€” it is true iff ARGUS_WALLET_KEY is set.


Where it sits in the ecosystem

aicom Factory builds agents โ†’ listed & invoked through AIMarket (Hub + protocol) โ†’ Oracles (LUMEN trust, randomness, VDF, consensus) price and secure them โ†’ financed on ACEX โ†’ visualised by Alien Monitor.

ARGUS is the demand side: the agent that spends in this market, sells into it, and defends the user against the MCP supply chain โ€” using LUMEN as its safety oracle.


Channels

One bounded agent core, many channels โ€” each with the auth model natural to it. Full matrix + design: docs/channels.md.

ChannelRunAuth
CLIargus ask / argus chatlocal (interactive approval)
Telegramargus telegramowner-locked (first /start claims)
HTTP APIargus serve/health open ยท POST /ask Bearer ARGUS_HTTP_TOKEN
MCP-serverargus mcplocal stdio โ€” exposes argus_ask / argus_status / argus_capabilities

argus serve runs Telegram + the HTTP server together (this is what the container runs). GET /health is also the hook that lets ARGUS appear as a live node in Alien Monitor. Set ALIEN_MONITOR_URL + ALIEN_API_TOKEN to push each completed run to the node's verifiable-run panel (oracle calls, WARDEN blocks, hires, sealed receipt). Discord, Slack, Email, Matrix, WhatsApp and voice are ready-to-add adapters (see the doc).

Deployment (Docker)

ARGUS launches untrusted MCP servers as child processes, so the container is also a security boundary around them โ€” not just packaging.

cp argus.config.example.json argus.config.json   # edit
cp .env.example .env                              # add secrets
docker compose up -d --build                      # serve: Telegram + HTTP /health

Secrets come from .env (never baked into the image); argus.config.json is mounted read-only; state persists in the argus-state volume; a HEALTHCHECK probes /health. Economy is OFF by default in the container (autonomous).

Development

npm run typecheck     # tsc --noEmit (strict)
npm test              # vitest (budget governor, WARDEN gates, provider mapping)
npm run build         # emit dist/

Status

v0.1 โ€” bounded agent loop, multi-provider routing, WARDEN gate chain (static + threat + reputation + pinning), memory/lessons, MCP host, economy consumer/provider wrappers, and four channels (CLI, Telegram, HTTP, MCP-server) + Docker โ€” all implemented and tested. OS-level MCP sandboxing (seccomp/Landlock/sandbox-exec), the signed threat-feed publisher, and the remaining channel adapters are the v2 track โ€” see the docs.

Demo

Related repos

RepoRole
aicomAI-Factory โ€” ships capabilities ARGUS consumes
aimarket-hubFederation hub โ€” discover, invoke, settle
oraclesLUMEN reputation + verifiable math
alien-monitorARGUS appears as a live graph node
dioscuriTwin community agents โ€” MNEMOSYNE Q&A

Community

The DIOSCURI twins answer questions from synced GitHub docs.

ChannelTwinBest for
DiscordPolluxHelp, ideas, show-and-tell
TelegramCastorReleases, digests, quick news

Ecosystem map: Alien Monitor ยท AICOM

License

MIT โ€” your keys, your infra, your data. Part of the AICOM open agent-economy.

Related MCP Servers

13bm/GhidraMCP

๐Ÿ โ˜• ๐Ÿ  - MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.

๐Ÿ”’ Security1 views
123Ergo/unphurl-mcp

๐Ÿ“‡ โ˜๏ธ - URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

๐Ÿ”’ Security0 views
82ch/MCP-Dandan

๐Ÿ ๐Ÿ“‡ ๐Ÿ  ๐ŸŽ ๐ŸชŸ ๐Ÿง - Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

๐Ÿ”’ Security0 views
9hannahnine-jpg/arc-gate-mcp

๐Ÿ - Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

๐Ÿ”’ Security0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Active

Recent health check succeeded.

Last checked: 7/28/2026, 10:45:20 AM

Unclaimed listing (imported or pending owner verification). Claim it โ†’
โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.