- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Documented (README)
- !No description
git clone https://github.com/YaakovTzedek/balmas-mcp{
"mcpServers": {
"balmas-mcp": {
"command": "node",
"args": ["/path/to/balmas-mcp/dist/index.js"]
}
}
}MCP Servers overview
# balmas-mcp
> **Your AI agent reads everything. This gateway hands it redacted copies instead.**
[](https://www.npmjs.com/package/balmas-mcp)
[](./LICENSE)

## Why
AI agents are getting file access — and they over-read. Israel's Privacy
Protection Authority put it bluntly in its guidance on AI agents: an
email-sorting agent can analyze 15 years of correspondence for a 2-year task,
infer your health and finances along the way, and leak what it learned. Their
recommendation: **strict permission minimization** — read-only, dedicated
folders, minimum necessary data.
balmas-mcp turns that advice into code, and goes one step further: it
minimizes not just *which* files the agent reads, but *what's inside them*.
## How it works
1. **You allowlist folders.** The agent can't reach anything else — enforced
with realpath checks, not honor rules.
2. **Every read is anonymized locally.** Names, ID numbers, phones, emails,
companies and amounts become consistent tokens (`PERSON_001`, `ID_001`)
*before* the content is returned. The same person is `PERSON_001` in every
file, so the agent's reasoning stays coherent. Detection runs in this
process — deterministic patterns, lexicons and checksums (Israeli ID
included). Hebrew and English.
3. **The answer comes back real.** `restore_text` maps the tokens in the
agent's final output back to the original values — locally.
Read-only by design: the server exposes no write tools at all.
## Quickstart
1. Create a free account at [balmasai.com/signup](https://www.balmasai.com/signup) (10 documents/month free).
2. Create an API key (`bk_...`) at [balmasai.com/app/team](https://www.balmasai.com/app/team).
3. Add to your MCP client config (Claude Desktop shown; Cursor and others are the same idea):
```json
{
"mcpServers": {
"balmas": {
"command": "npx",
"args": ["-y", "balmas-mcp", "/Users/me/Documents/work", "--level", "strict"],
"env": { "BALMAS_API_KEY": "bk_..." }
}
}
}
```
**Options:** allowed folders as positional args (required, one or more) ·
`--level standard|strict|maximum` (default `strict`).
## Tools
| Tool | What the agent gets |
|---|---|
| `list_files` | Names, sizes, types inside allowed folders — never contents |
| `read_clean_file` | The file's text after local anonymization |
| `restore_text` | Real values back into its output (session tokens only) |
Supported inputs: `txt` `csv` `md` `docx` `xlsx` `pptx` `pdf` (text layer).
## Privacy model
| | Leaves your machine? |
|---|---|
| File contents | **Never** |
| File names / paths | **Never** |
| The replacement map | **Never** |
| Metering counters (file type + item counts) | Yes — that's all |
Each file read counts as one document against your account's monthly quota
(free 10 / PRO 200 / TEAM 1,000). Full processing happens in this local
process.
## Honest limits
- The gateway helps only when the agent reads files **through it** — grant it
*instead of* raw filesystem access, not alongside.
- Detection is deterministic: excellent, not clairvoyant. Review output where
the stakes demand it.
- Scanned PDFs (no text layer) need the OCR flow at
[balmasai.com/clean](https://www.balmasai.com/clean).
---
Built by [BALMAS AI](https://www.balmasai.com) — sensitive data stops here.
Docs: [balmasai.com/mcp](https://www.balmasai.com/mcp)
What people ask about balmas-mcp
What is YaakovTzedek/balmas-mcp?
+
YaakovTzedek/balmas-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.
How do I install balmas-mcp?
+
You can install balmas-mcp by cloning the repository (https://github.com/YaakovTzedek/balmas-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is YaakovTzedek/balmas-mcp safe to use?
+
Our security agent has analyzed YaakovTzedek/balmas-mcp and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains YaakovTzedek/balmas-mcp?
+
YaakovTzedek/balmas-mcp is maintained by YaakovTzedek. The last recorded GitHub activity is dated 2026-09-02, with 0 open issues.
Are there alternatives to balmas-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy balmas-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/yaakovtzedek-balmas-mcp)<a href="https://claudewave.com/repo/yaakovtzedek-balmas-mcp"><img src="https://claudewave.com/api/badge/yaakovtzedek-balmas-mcp" alt="Featured on ClaudeWave: YaakovTzedek/balmas-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!