Fail-closed MCP adapter for untrusted model output over a local Tkach runtime.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
The model proposes. Tkach authorizes.
Put Tkach between model proposals and protected actions. Its Rust Core checks authority and information flow before allowing an action or releasing output. Model output remains untrusted data, even when the model is compromised.
Propusk; model text cannot create one.Sled receipts do not include payloads.These guarantees apply to paths routed through Tkach. It does not make the model trustworthy, detect every prompt injection, or protect a compromised host.
Install from crates.io with Rust 1.85 or newer:
init creates a starter request without overwriting files; check validates
its schema, not permission to execute; run --demo exercises the offline
boundary without a model connection. Use tkach ui for the interactive panel.
Prefer no Rust toolchain? Download a binary below and start with tkach init.
| Channel | What you get | Install / next step |
|---|---|---|
| GitHub Releases | tkach + tkach-mcp; Linux x86_64, macOS x86_64/arm64, Windows x86_64 | Verify downloads |
| crates.io | Seven Rust crates at 0.1.2: Core, Gateway, HTTP, client, MCP, CLI, provider adapter | Package list |
| npm | Thin JavaScript / TypeScript HTTP client | npm install tkach-security-client@0.1.2 |
| PyPI | Thin Python HTTP client | python -m pip install tkach-security-client==0.1.2 |
| Official MCP Registry | io.github.ECD5A/tkach-security@0.1.2, local stdio | Configure MCP |
| GHCR | OCI image for Linux amd64 / arm64 | Digest and deployment |
Binary archives include SHA-256 manifests, keyless Sigstore bundles, and GitHub build attestations. Pin the OCI digest for deployment; verification details live in the distribution guide.
Use the HTTP contract from
your application, the Rust client,
a Python/JS/TS/Go client,
or the stdio adapter from an MCP client.
Clients and MCP require a separately started local tkach serve runtime and
its bearer token; installing a package does not enable background protection.
tkach-core stays provider-, protocol-, and language-independent. Adapters
transport requests; policy and authority stay in Rust. Follow the
integration guide or copy a working examples/
scenario. The Go client is a source module, not a separate registry package.
The supported runtime is loopback-only by default. Public internet serving, TLS termination, Streamable HTTP, a cloud control plane, and a generic executor are not included; see the deployment contract.
From a repository checkout, run the offline Golden Case. It needs no model service or credentials. It performs one create-only write inside a temporary sandbox, then proves that a sibling path and a compromised provider proposal are denied:
Expected result:
The positive path uses trusted host configuration for the exact policy, destination, and executor binding; the provider supplies only an untrusted proposal. Read the architecture for the enforcement path and the release notes for the release checks and remaining limitations.
Keep changes small and explicit about the security boundary. Core changes need a demonstrated security or product defect; adapters must remain thin and must not duplicate Core logic. See CONTRIBUTING.md for required checks, public-claim rules, and files that must remain local.
If Tkach Security is useful to your work, support its continued maintenance:
pointoncurve.ton1ECDSA1b4d5TcZHtqNpcxmY8pBH1GgHntNTUF4vPdB6QkjCvZq18rBL4Qj4dK5ihCN75For inquiries about Tkach Security, integrations, security research, or collaboration:
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/tkach-security)<a href="https://allmcps.com/mcp/tkach-security"><img src="https://allmcps.com/api/badge/tkach-security?style=directory" alt="Tkach Security on AllMCPs" /></a>