- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Topics declared
- ✓Documented (README)
- !No description
claude mcp add aggrete -- uvx aggrete{
"mcpServers": {
"aggrete": {
"command": "uvx",
"args": ["aggrete"]
}
}
}MCP Servers overview
# Aggrete
[](https://pypi.org/project/aggrete/)
[](https://pypi.org/project/aggrete/)
[](https://github.com/aggrete/aggrete/blob/main/LICENSE)
[](https://glama.ai/mcp/servers/Aggrete/aggrete)
**An MCP proxy that enforces a code-of-conduct document across connectors, with per-user memory that accumulates across calls.**
Four individually-authorized questions can assemble a layoff list — no single one is sensitive, so no guardrail fires. Aggrete is the layer that catches the *combination*: is this call, together with everything this person already pulled today, something the code of conduct forbids?
**[Try it live](https://try.aggrete.com)** — nothing to install · or `uvx aggrete --demo`
## Install
```bash
pip install aggrete # or: uv tool install aggrete
uvx aggrete --demo # the walkthrough — no config, auth, or network
aggrete --config proxy.config.yaml # run it for real
```
## The one example
The `check` tool dry-runs a plan and returns the verdict **before anything is fetched**:
```
Plan check: REFUSED.
1. hr__recent_joiners [hr-personnel] -> allowed
2. finance__budget_roles [finance-comp] -> allowed
3. ops__oncall_draft [ops-rota] -> REFUSED COC-HR-004
Personnel, compensation, and operational rosters may not be combined to
derive the planned departure of identifiable individuals.
```
Each call is fine alone. The third completes a forbidden set across three domains that overlap on the same people, so it's denied **before the upstream call** — the data is never fetched.
## What it does
- **Refuses before fetching**, using a YAML policy and per-user memory across calls and sessions — not single-call authorization.
- **Redacts** emails, SSNs, cards, and tokens from results before they reach the model; **hides** walled tools from users who can't call them.
- **Shields against prompt injection** — any write after a session reads untrusted content is refused — and against **tool poisoning**, flagging hidden instructions in tool descriptions.
- **Holds upstream credentials itself** (confused-deputy safe), with optional per-user on-behalf-of access.
- **Audits tamper-evidently** — every decision is one hash-chained JSON line (`aggrete-audit`), optionally forwarded to a SIEM.
- **Ask before you act** — `check` previews any sequence, `scenarios` lists things to try.
## Learn more
- **[Writing policy](docs/POLICY.md)** — the `coc.yaml` schema, rule types, `arg_match`, and drafting from your handbook with `aggrete-ingest`
- **[Deploying](docs/DEPLOY.md)** — architecture, the deploy matrix, HTTP + OAuth, connecting Claude, and per-user credentials
- **[Building a connector](docs/CONNECTORS.md)** — expose read/write tools and govern any system (Google Drive is the reference)
- **[Roadmap](ROADMAP.md)** — shipped, in progress, and planned
- **[Agent skill](skills/aggrete/SKILL.md)** — teach Claude Code or any MCP client to set up and operate Aggrete: `/plugin marketplace add aggrete/aggrete`, or read `skill://aggrete/SKILL.md` from a running proxy
## Honest limitations
- **Post-call denial redacts, it does not un-fetch** — prefer rules decidable pre-call.
- **stdio identity is advisory** — real enforcement needs streamable HTTP with OAuth and IdP-level blocking of direct connector grants, so the proxy is the only path.
- **Aggregation can only be narrowed, not solved** — a user who spaces requests beyond the window, or paraphrases across systems the proxy doesn't front, gets through. This raises the cost and creates the audit trail; it isn't a ceiling.
- **Not a gateway** — no multi-tenancy, token vault, or HA. For production, embed this engine in agentgateway or IBM ContextForge.
---
<sub>mcp-name: io.github.aggrete/aggrete</sub>
What people ask about aggrete
What is aggrete/aggrete?
+
aggrete/aggrete is mcp servers for the Claude AI ecosystem with 1 GitHub stars.
How do I install aggrete?
+
You can install aggrete by cloning the repository (https://github.com/aggrete/aggrete) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is aggrete/aggrete safe to use?
+
Our security agent has analyzed aggrete/aggrete and assigned a Trust Score of 85/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains aggrete/aggrete?
+
aggrete/aggrete is maintained by aggrete. The last recorded GitHub activity is dated 2026-09-15, with 6 open issues.
Are there alternatives to aggrete?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy aggrete to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/aggrete-aggrete)<a href="https://claudewave.com/repo/aggrete-aggrete"><img src="https://claudewave.com/api/badge/aggrete-aggrete" alt="Featured on ClaudeWave: aggrete/aggrete" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ
The fastest path to AI-powered full stack observability, even for lean teams.