Skip to main content
ClaudeWave

Skill router and prompt-injection firewall for AI coding agents: gives Claude Code, Codex and Cursor the few skills, MCP servers and tools each task needs.

MCP ServersRegistry oficial17 estrellas0 forks● PythonNOASSERTIONActualizado today
ClaudeWave Trust Score
80/100
✓ Trusted
Passed
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !Licence file present but not machine-readable
Last scanned: 9/28/2026
Install in Claude Code / Claude Desktop
Method: NPX · skills
Claude Code CLI
claude mcp add lockkeeper -- npx -y skills
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "lockkeeper": {
      "command": "npx",
      "args": ["-y", "skills"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Casos de uso

Resumen de MCP Servers

<div align="center">

<h1>
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/Hannay001/lockkeeper/main/docs/lockkeeper-logo-dark.png">
    <img src="https://raw.githubusercontent.com/Hannay001/lockkeeper/main/docs/lockkeeper-logo.png" alt="Lockkeeper" width="460">
  </picture>
</h1>

### The skill router and prompt-injection firewall for AI coding agents

Give **Claude Code, Codex, Cursor** and other AI agents the few skills, MCP servers and tools that fit each task, instead of all of them.<br>
Smaller context window, better tool choices, and no unvetted skill instructions reaching your agent.

[![PyPI version](https://badge.fury.io/py/lockkeeper.svg)](https://pypi.org/project/lockkeeper/)
[![tests](https://github.com/Hannay001/lockkeeper/actions/workflows/tests.yml/badge.svg)](https://github.com/Hannay001/lockkeeper/actions/workflows/tests.yml)
[![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-blue.svg)](https://www.python.org/downloads/)
![zero dependencies](https://img.shields.io/badge/dependencies-0-brightgreen.svg)
![macOS, Linux, Windows](https://img.shields.io/badge/platform-macOS%20%7C%20Linux%20%7C%20Windows-lightgrey.svg)
[![License: FSL-1.1-ALv2](https://img.shields.io/badge/license-FSL--1.1--ALv2-blue.svg)](https://github.com/Hannay001/lockkeeper/blob/main/LICENSE)

[Quickstart](#quickstart) · [Ways to use it](#four-ways-to-use-lockkeeper) · [Benchmark](#proven-on-a-public-benchmark) · [Firewall](#prompt-injection-firewall-for-skills-and-mcp) · [FAQ](#faq) · [Docs](#documentation)

</div>

---

## What is Lockkeeper?

AI coding agents get better with **skills** (`SKILL.md` files), **MCP servers**, plugins and tools. But every one you install adds to what the agent has to read and choose from. With hundreds installed, your context window fills up before work starts, and the agent often picks the wrong skill or none at all.

**Lockkeeper is a local skill router.** It indexes everything installed across all your agents, and for each task it hands the agent a small, complementary set, up to 10 capabilities by default ([you choose the size](https://github.com/Hannay001/lockkeeper/blob/main/docs/CONFIGURATION.md#bundle-size)), with the exact file to read for each. Before anything reaches your agent, its built-in firewall can check skills and live tool calls for prompt injection.

```console
$ lockkeeper route --runtime claude "migrate the auth module to the new token API"

[primary] skill: api-migration
[context] mcp: context7
[integration] tool: mcp__context7__query_docs
[verification] agent: code-reviewer
[support] skill: python-patterns
context savings: loaded 6 of 7,540 eligible capabilities (7,534 kept out of context)
```

<p align="center">
  <img src="https://raw.githubusercontent.com/Hannay001/lockkeeper/main/docs/demo-route.png" alt="Lockkeeper routing a payment-webhook audit task to two primary skills in the terminal" width="72%">
</p>

## Why developers use Lockkeeper

- **🎯 Better skill choices.** On a public benchmark of real agent tasks, Lockkeeper ranks a correct skill first **65% of the time among 26,000 real skills** (up from 35%) and **55% among 79,000**, no model required. [See the benchmark](#proven-on-a-public-benchmark).
- **📉 A context window that stays small.** With 58,018 capabilities in the library, a routed task still carries a median of about **8,700 tokens** of skills instead of about 77.5 million. Adding skills to the library doesn't grow your prompt.
- **🛡 Safer skills and plugins.** Scan any skill, plugin or MCP config for hidden instructions and data exfiltration before your agent reads it, and block hostile tool calls live.
- **🔌 Works where you already work.** Automatic routing in Claude Code, an MCP server for Codex, Cursor, Windsurf, Cline and other clients, and a CLI for everything else.
- **🔒 Local, private and dependency-free.** Pure Python standard library. No GPU, API key or cloud service needed. Telemetry is off unless you say yes.

## Quickstart

**1. Install** from [PyPI](https://pypi.org/project/lockkeeper/) (Python 3.11+, macOS, Linux and Windows):

```sh
pipx install lockkeeper     # or: pip install lockkeeper  ·  uv tool install lockkeeper
lockkeeper init             # finds every AI agent on this machine and connects it
```

<sub>Only want the router skill? `npx skills add Hannay001/lockkeeper` installs it for any agent (it needs the `lockkeeper` command too). Prefer not to use a terminal? Paste the prompt in [PROMPT.md](https://github.com/Hannay001/lockkeeper/blob/main/PROMPT.md) into the AI agent you already use; it installs and configures Lockkeeper for you. Working from source? `git clone https://github.com/Hannay001/lockkeeper.git && cd lockkeeper && ./install.sh`</sub>

**2. Index what you have installed:**

```sh
lockkeeper rebuild    # indexes every skill, agent, command, MCP server and plugin it finds
lockkeeper doctor     # shows each agent found and how many skills it has
```

**3. Route a task:**

```sh
lockkeeper route "write unit tests for a python data pipeline"
```

Then pick how your agent should use it, below.

## Four ways to use Lockkeeper

### 1. Route every prompt automatically (Claude Code)

Install the Claude Code plugin (after `pipx install lockkeeper`). Inside Claude Code:

```text
/plugin marketplace add Hannay001/lockkeeper
/plugin install lockkeeper@lockkeeper
```

It adds the routing hook, the MCP server and the router skill in one step. Prefer settings files? `lockkeeper hooks install claude` adds just the hook (use one or the other, not both).

Every prompt you send now reaches Claude Code with a short note naming the installed skills that fit it and the exact files to read. Slash commands and short replies like "thanks" pass through untouched, and the hook never blocks a prompt. Undo with `lockkeeper hooks remove claude`.

Then shrink the list Claude Code loads into every session:

```sh
lockkeeper library move            # shows the plan: which skills move, how many tokens it saves
lockkeeper library move --apply    # moves them to ~/.agents/library; the hook still finds them
lockkeeper library restore --apply # puts them all back
```

Claude Code puts the name and description of every skill in `~/.claude/skills` into each session. Library mode moves them to a folder Lockkeeper indexes but Claude Code doesn't load, so only the skills a prompt needs reach the context. Keep favorites where they are with `--keep NAME`.

### 2. As an MCP server (Codex, Cursor, Windsurf, Cline and any MCP client)

`lockkeeper mcp` gives your agent three tools, `route`, `search` and `audit`, and keeps the index loaded between calls so answers are fast.

```sh
claude mcp add lockkeeper -- lockkeeper mcp          # Claude Code
```

```toml
# Codex: ~/.codex/config.toml
[mcp_servers.lockkeeper]
command = "lockkeeper"
args = ["mcp", "--runtime", "codex"]
```

```json
{ "mcpServers": { "lockkeeper": { "command": "lockkeeper", "args": ["mcp"] } } }
```

<sub>The JSON form works for Cursor (`~/.cursor/mcp.json`), Windsurf, Cline and most other clients. Lockkeeper is also listed in the official MCP Registry (MCP Registry name: `mcp-name: io.github.Hannay001/lockkeeper`).</sub>

### 3. From the command line and scripts

```sh
lockkeeper route --runtime codex "add rate limiting to a REST endpoint"
lockkeeper search "pdf tables"
lockkeeper route --json --stdin < task.txt      # whole prompts, machine-readable output
```

### 4. As a firewall for skills and plugins

```sh
lockkeeper audit ~/Downloads/some-skill --recursive --strict   # exit 2 = hostile
lockkeeper hooks install claude --firewall                      # block hostile tool calls live
```

## Supported agents

| Agent | Skills and tools indexed | How the agent gets its routes |
|---|:-:|---|
| Claude Code | ✓ | Automatically on every prompt (`hooks install claude`), or MCP |
| OpenAI Codex CLI | ✓ | MCP (`lockkeeper mcp`) or CLI |
| Cursor, Windsurf, Cline | ✓ | MCP |
| GitHub Copilot, Gemini CLI, OpenCode | ✓ | MCP |
| Jcode, Hermes | ✓ | MCP or CLI |

Lockkeeper reads the formats you already use: `SKILL.md` Agent Skills, agents and commands in Markdown, plugin manifests, and MCP server configs. The installer also detects agent tools it doesn't know by name.

## Proven on a public benchmark

Routing claims should be measurable. Lockkeeper is tested against **SkillRouter Eval Core**, the public benchmark from the SkillRouter paper ([arXiv:2603.22455](https://arxiv.org/abs/2603.22455)): 75 real agent tasks with known correct skills, hidden among real `SKILL.md` files from public repositories, including 780 deliberately misleading look-alikes.

| | Before this release | **Lockkeeper today** |
|---|--:|--:|
| Correct skill ranked first, 26,000 skills | 34.7% | **65.3%** |
| Correct skill ranked first, 79,141 skills | 25.3% | **54.7%** |
| Needed skills included in the routed set (79k) | 20.6% | **52.1%** |
| Time to route a ~180-word task, 26k skills | 6.5 s | **0.7 s** |

On the full pool, Lockkeeper's standard-library ranker scores between the paper's general-purpose embedding models (Qwen3-Embedding-0.6B at 53.3%, Gemini embedding at 56.0%) and roughly double its BM25 keyword baseline (28.0%), without loading a model. Methods, per-change results and caveats: **[docs/BENCHMARK.md](https://github.com/Hannay001/lockkeeper/blob/main/docs/BENCHMARK.md)**.

Reproduce it yourself (downloads the ~400 MB dataset once):

```sh
python3 scripts/bench_routing.py prepare --home /tmp/lk-bench --size 26000
python3 scripts/bench_routing.py run --home /tmp/lk-bench
```

**Your prompt stays flat as your library grows.** On the 79,141-skill benchmark pool (about 157M tokens of skill text), six everyday tasks each routed to 10 capabilities: a median of about 16,000 tokens even if the agent reads every one, over 99.98% kept out of context. The 26,000-skill pool gave about the same (17,600). Reproduce with `python3 scripts/bench_context_savings.py`
agent-skillagent-skillsai-agentsclaude-codeclaude-code-pluginclicodexcontext-windowcursordeveloper-toolsllm-securitymcpmcp-serverprompt-injectionpythonsecurityskill-routerskillsskills-sh

Lo que la gente pregunta sobre lockkeeper

¿Qué es Hannay001/lockkeeper?

+

Hannay001/lockkeeper es mcp servers para el ecosistema de Claude AI. Skill router and prompt-injection firewall for AI coding agents: gives Claude Code, Codex and Cursor the few skills, MCP servers and tools each task needs. Tiene 17 estrellas en GitHub y su última actualización registrada es del 2026-09-27.

¿Cómo se instala lockkeeper?

+

Puedes instalar lockkeeper clonando el repositorio (https://github.com/Hannay001/lockkeeper) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar Hannay001/lockkeeper?

+

Nuestro agente de seguridad ha analizado Hannay001/lockkeeper y le ha asignado un Trust Score de 80/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene Hannay001/lockkeeper?

+

Hannay001/lockkeeper es mantenido por Hannay001. La última actividad registrada en GitHub es del 2026-09-27, con 0 issues abiertos.

¿Hay alternativas a lockkeeper?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega lockkeeper en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: Hannay001/lockkeeper
[![Featured on ClaudeWave](https://claudewave.com/api/badge/hannay001-lockkeeper)](https://claudewave.com/repo/hannay001-lockkeeper)
<a href="https://claudewave.com/repo/hannay001-lockkeeper"><img src="https://claudewave.com/api/badge/hannay001-lockkeeper" alt="Featured on ClaudeWave: Hannay001/lockkeeper" width="320" height="64" /></a>

Más MCP Servers

Alternativas a lockkeeper