PluginBench
MCP Server
Active
MIT

Koma Gate MCP MCP Server

io.github.swnotmetal/koma-gate-mcp

Classifies prompt injection, jailbreaks, and out-of-scope input before agents act on it.

What is the Koma Gate MCP MCP server?

Koma Gate MCP is a prompt injection firewall that uses LLM-based semantic classification to block jailbreaks, off-topic requests, and instruction overrides before they reach your application model. It supports OpenAI, Anthropic, Google, DeepSeek, and local Ollama models, achieving 98.8% recall and 0% false positives on real attack datasets.

Koma Gate provides application-side input validation by classifying user messages for scope and safety before processing. It's a lightweight, composable security boundary that catches prompt injections and out-of-scope requests at the perimeter, reducing risk without requiring model inspection or proof of understanding. Works standalone or as part of the broader Koma security framework.

How to install Koma Gate MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • KOMA_PROVIDER

    LLM provider: openai, anthropic, google, deepseek, or ollama (default: google)

  • KOMA_MODEL

    Optional model override for the selected provider

  • GEMINI_API_KEY
    secret

    Google Gemini API key (used by the default provider)

  • OPENAI_API_KEY
    secret

    OpenAI API key when KOMA_PROVIDER=openai

  • ANTHROPIC_API_KEY
    secret

    Anthropic API key when KOMA_PROVIDER=anthropic

  • DEEPSEEK_API_KEY
    secret

    DeepSeek API key when KOMA_PROVIDER=deepseek

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "koma-gate-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "koma-gate-mcp"
      ],
      "env": {
        "KOMA_PROVIDER": "<YOUR_KOMA_PROVIDER>",
        "KOMA_MODEL": "<YOUR_KOMA_MODEL>",
        "GEMINI_API_KEY": "<YOUR_GEMINI_API_KEY>",
        "OPENAI_API_KEY": "<YOUR_OPENAI_API_KEY>",
        "ANTHROPIC_API_KEY": "<YOUR_ANTHROPIC_API_KEY>",
        "DEEPSEEK_API_KEY": "<YOUR_DEEPSEEK_API_KEY>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • classify_input — Classifies user input for prompt injection, jailbreaks, and out-of-scope content using LLM-based semantic analysis.

Use cases

  • Block prompt injection attacks and jailbreak attempts before they reach your LLM
  • Reject off-topic or out-of-scope user requests at the API boundary
  • Validate user input in chatbot and agent applications with configurable scope rules
  • Protect multi-tenant applications from cross-user instruction injection
  • Integrate input classification into existing Express or Node.js middleware stacks

Koma Gate MCP MCP server FAQ

What does Koma Gate MCP do?

It classifies incoming user prompts to detect prompt injections, jailbreaks, and out-of-scope requests before they reach your LLM. It uses semantic analysis rather than pattern matching, achieving 98.8% recall on real attack datasets with zero false positives.

Is Koma Gate free?

Yes, Koma Gate is MIT licensed and open source. The core package has no third-party runtime dependencies.

How do I install it in Claude or Cursor?

Add it to your MCP servers configuration: `{"mcpServers": {"koma-gate": {"command": "npx", "args": ["-y", "koma-gate-mcp"]}}}`. Then use the `classify_input` tool to check prompts before processing.

What LLM providers does it support?

Koma Gate supports OpenAI, Anthropic, Google Gemini, DeepSeek, and local Ollama models. You provide your own API key for the classification model.

Does it require authentication?

Yes, you must provide an API key for your chosen LLM provider (e.g., GEMINI_API_KEY for Google, or equivalent for other providers). Local Ollama deployments do not require external authentication.

Can it be used standalone or only as part of Koma?

Koma Gate works completely standalone. The broader Koma framework includes Scout (rate limiting), Core (protected RAG), and Miko (agent skill verification), but Gate functions independently as an input classifier.

README (reference)

Source of truth, from the repository.

Koma

Miko: required Skill checks for Claude Code and Codex

Keep reminding your coding agent to read a required Skill before editing? Miko checks for observable Skill reads before protected edits. When evidence is missing, it pauses the action and tells the agent what to load before retrying. It runs locally, makes no LLM calls, and is free and open source.

The current focus is Claude Code and Codex CLI. Miko is part of Koma; the separate Gate, Scout, and Core packages cover AI application input, request limits, and retrieval. You do not need them to use Miko.

npm install -D koma-miko@alpha
npx koma-miko init --host claude

Edit the generated miko.json to name your project's Skills and protected paths, then start a new Claude Code session. Using Codex? Follow the Codex setup and one-time Hook review. Codex CLI is a Technical Preview; Desktop requires prior CLI activation.

<p align="center"> <img src="logo/logobanner.png" alt="Koma" width="600" /> </p> <p align="center"> <img alt="License" src="https://img.shields.io/badge/license-MIT-green?style=flat-square" /> <img alt="CI" src="https://github.com/swnotmetal/Project-Koma/actions/workflows/ci.yml/badge.svg" /> <a href="https://www.npmjs.com/package/koma-miko"><img alt="koma-miko" src="https://img.shields.io/npm/v/koma-miko/alpha?label=koma-miko%20alpha&color=C25E38&style=flat-square" /></a> <a href="https://www.npmjs.com/package/koma-gate"><img alt="koma-gate" src="https://img.shields.io/npm/v/koma-gate?label=koma-gate&color=3178c6&style=flat-square" /></a> <a href="https://www.npmjs.com/package/koma-scout"><img alt="koma-scout" src="https://img.shields.io/npm/v/koma-scout?label=koma-scout&color=3178c6&style=flat-square" /></a> <a href="https://www.npmjs.com/package/koma-core"><img alt="koma-core" src="https://img.shields.io/npm/v/koma-core?label=koma-core&color=3178c6&style=flat-square" /></a> <br /> <a href="https://koma-demo.swbuilds.workers.dev"><img alt="Miko live demo" src="https://img.shields.io/badge/Miko_demo-10--sec_replay-C25E38?style=flat-square" /></a> <img alt="Gate benchmark" src="https://img.shields.io/badge/Gate_eval-98.8%25_recall_0%25_FPR-6e3abe?style=flat-square" /> <img alt="koma-gate downloads" src="https://img.shields.io/npm/dt/koma-gate?label=gate%20downloads&color=blue&style=flat-square" /> <a href="https://glama.ai/mcp/servers/swnotmetal/Project-Koma"><img alt="MCP server" src="https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg" /></a> </p> <p align="center"> <a href="./README.zh-CN.md">中文版</a> </p> <p align="center"> <strong>▶ <a href="https://koma-demo.swbuilds.workers.dev">Try Miko's guided terminal replay</a></strong> — plus Gate, Scout &amp; Core, no signup. </p>

Miko for Claude Code and Codex

<p align="center"> <img src="packages/koma-miko/assets/miko-lockup.png" alt="Koma Miko" width="420" /> </p>

Coding agents can say they loaded a required Skill or ran a test. Miko does not treat that claim as evidence. At supported local host Hooks, it compares observed Skill loads, reference reads, tool actions, and completion checks with a project-owned miko.json.

If an agent tries to edit before satisfying the spec, Miko can return a denial and a short recovery instruction. It cannot inspect hidden model context, prove that a model understood a Skill, or verify events the host never exposes. In Claude CLI guided mode, a genuine scope exception opens one visible Miko choice: allow that exact retry once, or keep the current boundary.

npx --yes koma-miko@alpha demo       # deterministic; no API key
npx --yes koma-miko@alpha probe --host claude  # isolated adapter check; no model
npx koma-miko init --host claude     # after local installation

Codex CLI is a Technical Preview; Codex Desktop requires prior CLI activation. The CLI requires a one-time /hooks review before project Hooks run. Miko promotes enforce on Codex because the current Hook API cannot open a native REVIEW choice; review therefore degrades to a recoverable pause/deny. Desktop-only onboarding is not a supported alpha path. An offline probe proves adapter logic, not live Hook activation.

Miko README → · Current host support → · 10-second web replay →

Miko replay GIF · Still image — browser simulation, not a live host recording.

Claude Code is the primary alpha workflow. Codex CLI has a verified narrow recovery flow with the activation limits above. Gemini is outside active development; Copilot adapter work is paused pending a real tester. Existing adapters and their dated results remain available in the adapter documentation.

Why use Miko instead of writing a Hook? A small native Hook is enough for a single fixed check. Miko packages project Specs, observed-read tracking, post-compaction reload requirements, recovery messages, and completion evidence so you can maintain those checks together. Neither approach proves the model understood the instructions. See when Miko helps.


Four Boundaries

BoundaryFailure modeWhat Koma checksPackage
Coding agentRequired Skill or completion check skippedHost-observed preparation, action scope, and evidencekoma-miko@alpha
User → LLMPrompt injection / jailbreakSemantic scope before the application modelkoma-gate
Request perimeterAudio abuse / floodingValidation, rate limits, and geo ruleskoma-scout
RetrievalData enumeration / scrapingSplit index from content; token-gate retrievalkoma-core

Different attacks cross different boundaries. Koma provides a small primitive for each one.


What Koma Is — and Isn't

Is: small composable packages · usable independently · explicit failure modes · deterministic checks where the host exposes evidence

Isn't: a model · an agent framework · proof that a model understood its instructions · a replacement for authorization · a complete security boundary by itself


Benchmarks

Miko alpha evaluation

Miko is deterministic, so its useful numbers are verifier cost and end-to-end Hook behavior—not a generic score for model intelligence.

SignalObserved result
Offline host conformanceClaude, Codex, Gemini, and VS Code Copilot each reproduce DENY → observed Skill → ALLOW; ledger fixtures reject prompt/code/tool-response persistence
Local verifier scale1,000 Agent Specs: 1.34 ms p95 per action; 10,001 indexed evidence events: 0.0041 ms p95; restore 1,000 evidence events: 1.52 ms p95
Claude Code live + hand-testOne 100-Skill / ~20k-context run passed. A natural Chinese request drove a three-file rewrite through 3 Agent Specs and 28 observed events. Separate Haiku 4.5 runs verified visible Allow once and Keep current scope policy-exception paths
Codex CLI Technical PreviewFixed live recovery completed DENY → Skill/reference → edit → COMPLETE; an interactive CLI 0.152.0 hand-test visibly rendered Miko active, recovered, and COMPLETE. Desktop also enforced after CLI activation, but onboarding and completion visibility remain unsuitable as a primary path
DeepSeek Harness smoke3/3 narrow packed-artifact recovery runs passed; 19.425 s mean model phase

The scale row is a 2026-08-27 reference run on Node 24.19 / Windows; rerun it with npm run eval:scale -w koma-miko. Context tokens never enter the verifier. The paid samples are deliberately small and do not establish general model, long-context, or editor reliability. See the scale record, Claude record, host-adapter record, and DSH record.

Koma Gate live-model benchmark

I threw 1,769 real prompt-injection attacks at Koma Gate in fail-closed mode, using real providers — not mock adapters.

ProviderRecallPrecisionFalse Positives
DeepSeek (deepseek-chat)98.8%100%0
Google (gemini-2.5-flash)96.2%100%0

Chinese attack set: 100% recall · 100% precision · 0% FPR across 8 categories.

Can you break it? Open an issue with an attack Koma misses. → Full methodology


Application-side quick start: Gate

import { createGeneralKnowledgeGuard } from 'koma-gate';

const guard = createGeneralKnowledgeGuard({
  llm: { apiKey: process.env.GEMINI_API_KEY },
});

app.post('/api/chat', guard.middleware(), async (req, res) => {
  // Only in-scope requests reach your model
  res.json({ reply: await chat(req.body.message) });
});
git clone https://github.com/swnotmetal/Project-Koma
cd Project-Koma && node demo/server.js
curl http://localhost:8080/self-test

Application-Side Packages

koma-gate — Prompt injection firewall. LLM-based scope classifier that blocks jailbreaks, off-topic requests, and instruction overrides. Supports OpenAI, Anthropic, Google, DeepSeek, and local Ollama models. README →

Try Gate in the browser demo →

<img src="show-koma.gif" alt="Koma Gate blocking a prompt injection in real time" width="100%" />

koma-scout — Perimeter protection. Rate limiting, audio upload validation, geo allowlisting. Cheap checks before expensive AI work. README →

<img src="logo/scout-diagram.svg" alt="Koma Scout perimeter checks" width="480" />

koma-core — Protected RAG storage. Public search index, private content, opaque HKDF-derived tokens. Discovery is not authorization. README →

<img src="logo/core-diagram.svg" alt="Koma Core split-store" width="480" />

Each package works standalone. A typical application checks cheap request limits with Scout before Gate classification, then uses Core where protected retrieval is needed. See the architecture map.

Application-side MCP servers — these belong to Gate and Core, not Miko:

  • koma-gate-mcp — classify_input tool for prompt-injection checks. README →
  • koma-core-mcp — search_docs + retrieve_doc for protected RAG retrieval. README →
{
  "mcpServers": {
    "koma-gate": { "command": "npx", "args": ["-y", "koma-gate-mcp"] },
    "koma-core": { "command": "npx", "args": ["-y", "koma-core-mcp"] }
  }
}

Using an agent to set up Miko?

Tell it:

"Read the Miko README, then help me configure koma-miko for my existing Skills and protected paths. Use the setup for my host and explain any activation step I must complete."

For a coding-agent repository, install Miko and run npx koma-miko init --host claude or follow the Codex setup. Edit the generated miko.json to name the Skills, paths, and completion evidence that matter to the project. Miko does not install the Skills themselves.

See llms.txt for documentation entry points. Miko uses host Hooks; it does not require an MCP server.


Trust & Safety

  • Minimal dependency surface. Miko, Gate, and Core have no third-party runtime dependencies; Scout declares Express as a peer.
  • No model-output execution. Miko observes host events; Gate, Scout, and Core classify, rate-limit, or store. None executes generated code.
  • Package-specific failure behavior. Gate defaults to fail-open and can use failOpen: false. Miko follows each Agent Spec's mode; an enforce-mode missing-evidence check denies the applicable action.
  • CodeQL on every push. Targets OWASP LLM01.
  • MIT licensed.

→ Security policy · Known limitations · Contributing


Koma comes from Komainu ("狛犬"), the stone guardian lions of Japanese Shinto shrines. Three deployed defense layers, each standalone, plus the Miko alpha agent-contract boundary. Patterns distilled from production, not papers.

License

Related MCP servers

Protected RAG storage with public metadata discovery and token-gated content retrieval for AI agents.

10
TypeScript
MIT
View repository →

158,000+ K-12 education standards across 300 curriculum systems, cross-referenced via NLP.

5
Python
MIT
View repository →

Convert, resize, crop, filter & composite images via the imgcli CLI (lightweight, no deps)

0
C
MIT
View repository →

Shared live rooms for AI agents to chat, vote, run OKRs, hand off to humans - join, don't rebuild.

0
TypeScript
Apache-2.0
View repository →
RORoastPilot logo

RoastPilot controls coffee roasting sessions through local stdio MCP tools and exports logs.

0
Python
Apache-2.0
View repository →

Zero-config MCP server bundling 50+ utility tools: converters, OCR, scraping, and formatters.

0
TypeScript
View repository →