← Back to directory
I

IronCurtain

Community
Framework / SDK
A secure runtime for autonomous AI agents, with policy from plain-English constitutions.

This is a framework for building MCP servers or agents, not a server you connect a client to.

Category
Dev Tools #227 of 438
Stars
★ 612 Very popular
Transport
stdio (local process)
Runtime
Node.js 22, 24, or 26 (even- · Docker recommended for Dock
Credentials
Optional API key
License
Apache-2.0
Last commit
52FMRS · D

IronCurtain provides a secure runtime for AI agents by compiling natural-language security policies into deterministic rules. It supports multiple modes and MCP servers, but as a research prototype, users need to carefully review policies and understand the security model.

Strongest · Maintenance 15/20 Weakest · Security and permissions 5/20

Reliability
8/20
Security and permissions
5/20
Maintenance
15/20
Documentation
14/20
Setup experience
10/20
Why each score
Reliability 8/20
The source includes a complete TypeScript project structure, test framework, and CI workflow (.github/workflows/ci.yml), indicating some buildability and test coverage. However, as an MCP server, it lacks a proper 'server' entry point or MCP protocol handshake implementation—it appears to be a full application rather than a dedicated MCP server. Since nothing is executed, startup reliability and tool-list accuracy cannot be verified, and the heavy reliance on external components like Docker and network proxies leaves error handling unknown. Thus reliability is scored low, based only on the optimistic presence of code and tests.
Security and permissions 5/20
The project claims to be a secure runtime but has several red flags: it acts as a MITM proxy, proxying LLM API calls and swapping API keys (fake-to-real key swap), which is a man-in-the-middle attack vector with credential exposure risk. The raw passthrough tunnel allows uninspected traffic, and the README openly lists known limitations including V8 escape possibility and lack of outbound content inspection. On the positive side, it defaults to allow read-only operations and escalates mutations for approval, aligning with least privilege, but the overall security design is complex and dependent on external components, with high risk and incomplete permission/confirmation controls.
Maintenance 15/20
The project is actively developed with continuous CI, npm releases, clear Apache-2.0 license, and indications of issue handling. Despite being a research prototype, maintenance activity is high, with clear versioning and licensing. The downside is reliance on many third-party services (Anthropic, Google, OpenAI) and potential version compatibility fluctuations, but overall maintenance is solid.
Documentation 14/20
Documentation is extensive, covering architecture, quick start, security model, configuration reference, troubleshooting, and various run modes. It details installation, authentication, tool lists, and limitations. However, there are hidden assumptions: the MCP server itself is not a standalone server but part of a larger system, and docs don't clarify how to use it as an MCP server independently. Also, some security details require external links, and there is a lack of detailed tool parameter documentation.
Setup experience 10/20
Installation requires Node.js 22/24/26, Docker, and LLM API keys, with a detailed setup wizard. However, the setup path as an MCP server is unclear—it's a complete application rather than a directly usable MCP server, requiring configuration to connect as one. The installation involves multiple external dependencies (Docker, OAuth, API keys), making it complex, and the docs lack concrete configuration examples for standard MCP clients.

Static review · not runListed 2026-08-07

Read the FMRS scoring method →

Fit and risk

What it can accessReads local filesWrites / deletes local filesRuns commands or codeUses the networkChanges third-party account data

Best for

  • Developers and users who need strict security policies for AI agents
  • Teams that want to define security boundaries in natural language without sacrificing autonomy
  • Security researchers running agents in untrusted environments

Not for

  • Scenarios where no security policy is needed and the agent can run freely
  • Simple tasks requiring minimal permissions or no external dependencies
  • Users who want out-of-the-box functionality without understanding the security model

Required permissions

  • Requires access to filesystem, network, API keys, etc., for file and network operations
  • Requires Docker for Docker agent mode, providing strongest isolation
  • Requires an LLM API key (Anthropic, Google, or OpenAI)

Risks and side effects

  • Research prototype: APIs and configuration formats may change
  • Policy compilation may misinterpret intent; always review compiled rules
  • V8 isolate boundaries are not OS-level; a V8 zero-day could allow escape
  • In Docker mode, approved domains get raw passthrough tunnels without content inspection

Setup

Before you start

Runtime:Node.js 22, 24, or 26 (even- · Docker recommended for Dock

ANTHROPIC_API_KEY requiredsecret Anthropic API key from the Anthropic console; primary LLM provider key, can also be placed in a .env file or ~/.ironcurtain/config..
GOOGLE_GENERATIVE_AI_API_KEY optionalsecret Google Generative AI API key from Google AI Studio; optional alternative LLM provider.
OPENAI_API_KEY optionalsecret OpenAI API key from the OpenAI platform; optional alternative LLM provider.
  1. Install CLI globally: npm install -g @provos/ironcurtain
  2. Set an LLM API key (e.g., ANTHROPIC_API_KEY)
  3. Run ironcurtain setup for the first-start wizard
  4. Use ironcurtain mux for interactive sessions.

Check that it works

Run `ironcurtain setup` to complete the first-start wizard, then run `ironcurtain start "Summarize the files in ./src"`; the install works if the agent responds and every tool call passes through the policy engine and is recorded in the per-session audit.l.

Troubleshooting

  1. Check API key is set correctly, or review `~/.ironcurtain/config.json`
  2. Ensure Docker is installed, and 'bubblewrap' and 'socat' are available for sandboxing
  3. If policy doesn't match intent, review `compiled-policy.json` and run `customize-policy` to refine constitution
  4. Node.js version must be 22, 24, or 26; run `ironcurtain doctor` to check

Things to try

Once connected, you can ask your AI assistant things like:

  • Summarize the files in ./src
  • Fix the tests in my workspace
  • Push my changes to origin
  • Find memory-safety bugs in libical

Use cases

Run autonomous AI agents securely in a sandbox, performing file, git, and API operations
Compile policies from plain-English constitutions into deterministic rules and verify them
Integrate with MCP servers like filesystem, git, GitHub, Google Workspace

Overview

IronCurtain is a secure runtime for autonomous AI agents. It compiles human-readable constitutions into deterministic security policies and enforces them at runtime on every tool call, providing safety without sacrificing autonomy. It supports multiple modes including builtin agent (Code Mode) and Docker agent mode, and includes a policy engine, MCP servers, audit logs, and a web UI.

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision d51a3467cbda Data synced 2026-10-11 Read the FMRS scoring method