- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Topics declared
- ✓Documented (README)
- !No description
claude mcp add aggrete -- uvx aggrete{
"mcpServers": {
"aggrete": {
"command": "uvx",
"args": ["aggrete"]
}
}
}Resumen de MCP Servers
# Aggrete
[](https://pypi.org/project/aggrete/)
[](https://pypi.org/project/aggrete/)
[](https://github.com/aggrete/aggrete/blob/main/LICENSE)
[](https://glama.ai/mcp/servers/Aggrete/aggrete)
**An MCP proxy that enforces a code-of-conduct document across connectors, with per-user memory that accumulates across calls.**
Four individually-authorized questions can assemble a layoff list — no single one is sensitive, so no guardrail fires. Aggrete is the layer that catches the *combination*: is this call, together with everything this person already pulled today, something the code of conduct forbids?
**[Try it live](https://try.aggrete.com)** — nothing to install · or `uvx aggrete --demo`
## Install
```bash
pip install aggrete # or: uv tool install aggrete
uvx aggrete --demo # the walkthrough — no config, auth, or network
aggrete --config proxy.config.yaml # run it for real
```
## The one example
The `check` tool dry-runs a plan and returns the verdict **before anything is fetched**:
```
Plan check: REFUSED.
1. hr__recent_joiners [hr-personnel] -> allowed
2. finance__budget_roles [finance-comp] -> allowed
3. ops__oncall_draft [ops-rota] -> REFUSED COC-HR-004
Personnel, compensation, and operational rosters may not be combined to
derive the planned departure of identifiable individuals.
```
Each call is fine alone. The third completes a forbidden set across three domains that overlap on the same people, so it's denied **before the upstream call** — the data is never fetched.
## What it does
- **Refuses before fetching**, using a YAML policy and per-user memory across calls and sessions — not single-call authorization.
- **Redacts** emails, SSNs, cards, and tokens from results before they reach the model; **hides** walled tools from users who can't call them.
- **Shields against prompt injection** — any write after a session reads untrusted content is refused — and against **tool poisoning**, flagging hidden instructions in tool descriptions.
- **Holds upstream credentials itself** (confused-deputy safe), with optional per-user on-behalf-of access.
- **Audits tamper-evidently** — every decision is one hash-chained JSON line (`aggrete-audit`), optionally forwarded to a SIEM.
- **Ask before you act** — `check` previews any sequence, `scenarios` lists things to try.
## Learn more
- **[Writing policy](docs/POLICY.md)** — the `coc.yaml` schema, rule types, `arg_match`, and drafting from your handbook with `aggrete-ingest`
- **[Deploying](docs/DEPLOY.md)** — architecture, the deploy matrix, HTTP + OAuth, connecting Claude, and per-user credentials
- **[Building a connector](docs/CONNECTORS.md)** — expose read/write tools and govern any system (Google Drive is the reference)
- **[Roadmap](ROADMAP.md)** — shipped, in progress, and planned
- **[Agent skill](skills/aggrete/SKILL.md)** — teach Claude Code or any MCP client to set up and operate Aggrete: `/plugin marketplace add aggrete/aggrete`, or read `skill://aggrete/SKILL.md` from a running proxy
## Honest limitations
- **Post-call denial redacts, it does not un-fetch** — prefer rules decidable pre-call.
- **stdio identity is advisory** — real enforcement needs streamable HTTP with OAuth and IdP-level blocking of direct connector grants, so the proxy is the only path.
- **Aggregation can only be narrowed, not solved** — a user who spaces requests beyond the window, or paraphrases across systems the proxy doesn't front, gets through. This raises the cost and creates the audit trail; it isn't a ceiling.
- **Not a gateway** — no multi-tenancy, token vault, or HA. For production, embed this engine in agentgateway or IBM ContextForge.
---
<sub>mcp-name: io.github.aggrete/aggrete</sub>
Lo que la gente pregunta sobre aggrete
¿Qué es aggrete/aggrete?
+
aggrete/aggrete es mcp servers para el ecosistema de Claude AI con 1 estrellas en GitHub.
¿Cómo se instala aggrete?
+
Puedes instalar aggrete clonando el repositorio (https://github.com/aggrete/aggrete) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar aggrete/aggrete?
+
Nuestro agente de seguridad ha analizado aggrete/aggrete y le ha asignado un Trust Score de 85/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene aggrete/aggrete?
+
aggrete/aggrete es mantenido por aggrete. La última actividad registrada en GitHub es del 2026-09-15, con 6 issues abiertos.
¿Hay alternativas a aggrete?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega aggrete en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/aggrete-aggrete)<a href="https://claudewave.com/repo/aggrete-aggrete"><img src="https://claudewave.com/api/badge/aggrete-aggrete" alt="Featured on ClaudeWave: aggrete/aggrete" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ
The fastest path to AI-powered full stack observability, even for lean teams.