Back to Directory/Security & Auth

Tkach Security

Fail-closed MCP adapter for untrusted model output over a local Tkach runtime.

Security & AuthRustv0.1.2

Русская версия

A fail-closed security boundary for AI agents and compromised model output.

The model proposes. Tkach authorizes.

Put Tkach between model proposals and protected actions. Its Rust Core checks authority and information flow before allowing an action or releasing output. Model output remains untrusted data, even when the model is compromised.

Why Tkach

  • Explicit authority: protected actions need an exact-scope, Core-issued Propusk; model text cannot create one.
  • Controlled data flow: permission to read is not permission to export. Provenance and release checks remain inside the boundary.
  • Fail-closed decisions: invalid, denied, replayed, cancelled, or uncertain states do not silently become permission.
  • Isolated secrets and bounded evidence: broker-held secrets stay outside ordinary model context; Sled receipts do not include payloads.

These guarantees apply to paths routed through Tkach. It does not make the model trustworthy, detect every prompt injection, or protect a compromised host.

Start in minutes

Install from crates.io with Rust 1.85 or newer:

cargo install tkach-cli --version 0.1.2 --locked
tkach init my-agent
tkach check my-agent/.tkach/request.json
tkach run --demo

init creates a starter request without overwriting files; check validates its schema, not permission to execute; run --demo exercises the offline boundary without a model connection. Use tkach ui for the interactive panel.

Prefer no Rust toolchain? Download a binary below and start with tkach init.

Packages and downloads · v0.1.2

ChannelWhat you getInstall / next step
GitHub Releasestkach + tkach-mcp; Linux x86_64, macOS x86_64/arm64, Windows x86_64Verify downloads
crates.ioSeven Rust crates at 0.1.2: Core, Gateway, HTTP, client, MCP, CLI, provider adapterPackage list
npmThin JavaScript / TypeScript HTTP clientnpm install tkach-security-client@0.1.2
PyPIThin Python HTTP clientpython -m pip install tkach-security-client==0.1.2
Official MCP Registryio.github.ECD5A/tkach-security@0.1.2, local stdioConfigure MCP
GHCROCI image for Linux amd64 / arm64Digest and deployment

Binary archives include SHA-256 manifests, keyless Sigstore bundles, and GitHub build attestations. Pin the OCI digest for deployment; verification details live in the distribution guide.

Integrate without moving policy out of Rust

Use the HTTP contract from your application, the Rust client, a Python/JS/TS/Go client, or the stdio adapter from an MCP client. Clients and MCP require a separately started local tkach serve runtime and its bearer token; installing a package does not enable background protection.

tkach-core stays provider-, protocol-, and language-independent. Adapters transport requests; policy and authority stay in Rust. Follow the integration guide or copy a working examples/ scenario. The Go client is a source module, not a separate registry package.

The supported runtime is loopback-only by default. Public internet serving, TLS termination, Streamable HTTP, a cloud control plane, and a generic executor are not included; see the deployment contract.

Show the cross-platform CLI window

See the boundary in action

From a repository checkout, run the offline Golden Case. It needs no model service or credentials. It performs one create-only write inside a temporary sandbox, then proves that a sibling path and a compromised provider proposal are denied:

cargo run -p tkach-gateway --example golden_case --locked

Expected result:

GOLDEN_CASE|safe_output=released|allowed_write=committed|out_of_scope=denied|compromised_action=denied|compromised_executor_calls=0

The positive path uses trusted host configuration for the exact policy, destination, and executor binding; the provider supplies only an untrusted proposal. Read the architecture for the enforcement path and the release notes for the release checks and remaining limitations.

Documentation

Contributing

Keep changes small and explicit about the security boundary. Core changes need a demonstrated security or product defect; adapters must remain thin and must not duplicate Core logic. See CONTRIBUTING.md for required checks, public-claim rules, and files that must remain local.

Support

If Tkach Security is useful to your work, support its continued maintenance:

  • TON: pointoncurve.ton
  • Bitcoin (BTC): 1ECDSA1b4d5TcZHtqNpcxmY8pBH1GgHntN
  • USDT (TRC20): TUF4vPdB6QkjCvZq18rBL4Qj4dK5ihCN75

Contact

For inquiries about Tkach Security, integrations, security research, or collaboration:

 

 

Setup from the maintainer

This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.

Package

tkach-mcpother

Compatible MCP Clients

Tkach Security works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More