Back to Browse

Agent Infra MCP Server

Developer ToolsUse Caution0.5MCP RegistryLocal
Free

Server data from the Official MCP Registry

18 tools: agent memory, API drift detection, and HMAC-signed trust receipts

About

18 tools: agent memory, API drift detection, and HMAC-signed trust receipts

Security Report

0.5
Use Caution0.5Critical Risk

Critical security issue: The MCP server requires three separate API keys (AGENT_MEMORY_API_KEY, AGENT_DRIFT_API_KEY, TRUST_RECEIPT_API_KEY) but the provided code is incomplete—only README, package.json, and a massive TypeScript library dump are present. No actual server implementation code was provided for analysis. The incomplete submission, combined with the requirement for external API authentication and the 18-tool surface area, presents substantial risk. Without reviewing the actual implementation (src/index.ts, tool handlers, API communication logic), safe assessment is impossible. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

4 files analyzed · 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

API key for Agent Memory serviceOptional

Environment variable: AGENT_MEMORY_API_KEY

API key for Agent Drift Detection serviceOptional

Environment variable: AGENT_DRIFT_API_KEY

API key for Trust Receipt serviceOptional

Environment variable: TRUST_RECEIPT_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-lulzasaur9192-agent-infra-mcp": {
      "env": {
        "AGENT_DRIFT_API_KEY": "your-agent-drift-api-key-here",
        "AGENT_MEMORY_API_KEY": "your-agent-memory-api-key-here",
        "TRUST_RECEIPT_API_KEY": "your-trust-receipt-api-key-here"
      },
      "args": [
        "-y",
        "@lulzasaur9192/agent-infra-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@lulzasaur9192/agent-infra-mcp

MCP server with 18 tools for AI agent infrastructure — persistent memory, API drift detection, and HMAC-signed trust receipts.

Installation

npx @lulzasaur9192/agent-infra-mcp

Claude Desktop / Cursor

{
  "mcpServers": {
    "agent-infra": {
      "command": "npx",
      "args": ["-y", "@lulzasaur9192/agent-infra-mcp"],
      "env": {
        "AGENT_MEMORY_API_KEY": "your-key",
        "AGENT_DRIFT_API_KEY": "your-key",
        "TRUST_RECEIPT_API_KEY": "your-key"
      }
    }
  }
}

Tools (18)

Memory (8 tools)

Persistent key-value store with namespaces, metadata, TTL, and FTS5 full-text search.

  • memory_store — Store a memory (namespace + key + value)
  • memory_store_batch — Batch store up to 100 memories
  • memory_list — List memories in a namespace
  • memory_get — Get a specific memory
  • memory_update — Update value, metadata, or TTL
  • memory_delete — Delete a memory or entire namespace
  • memory_search — Full-text search with metadata filtering
  • memory_stats — Usage statistics

Drift Detection (7 tools)

Monitor API endpoints for unexpected changes with golden test cases and cron scheduling.

  • drift_create_test — Register a golden test (exact/subset/contains/status match)
  • drift_list_tests — List all tests
  • drift_run_test — Execute a test manually
  • drift_test_history — View run history and diffs
  • drift_update_test — Update test configuration
  • drift_delete_test — Remove a test
  • drift_dashboard — Overview with drift rate and response times

Trust Receipts (3 tools)

HMAC-SHA256 signed, tamper-proof records of agent actions for audit trails.

  • receipt_issue — Issue a signed receipt for an agent action
  • receipt_verify — Verify receipt integrity (online or offline)
  • receipt_list — List receipts with filters

API Keys

Each service uses its own API key:

ServiceEnv VarAPI
MemoryAGENT_MEMORY_API_KEYagent-memory-api
DriftAGENT_DRIFT_API_KEYagent-drift-api
ReceiptsTRUST_RECEIPT_API_KEYtrust-receipt-api

License

MIT

Reviews

No reviews yet

Be the first to review this server!