Mnki MCP server
MCP proxy that checks every tools/call against Agent Trust policy, with evidence, before it runs.
B82/100grade B
Adoption
Growing
0 stars491 downloads/wk
Reviews
Write oneNobody has reviewed Mnki yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Mnki tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- Code scan19 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 2 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Overall 82/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Grade history
- 2026-09-19downgradeA → Bscore 82
- 2026-09-18restoreC → Ascore 85
Install directly
Runs npx -y mnki-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mnki-mcp -- npx -y mnki-mcp
Mnki: common questions
- Is Mnki MCP server safe?
- Mostly: it is graded B (82/100). Read the Mnki safety report
- How do I install Mnki?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Mnki need an API key?
- Yes. The registry entry asks for
MNKI_API_KEY. - Is Mnki maintained?
- The last commit was 2 days ago (2026-09-17). The latest release is v0.1.6.
- What can I use instead of Mnki?
- Servers from other publishers that do the same job: IWE MCP server, Protect MCP server and MCP Server. Compare all Mnki alternatives.
Alternatives to Mnki
Same job from other publishers: the closest match first, then the best rated.
- IWEMarkdown knowledge base as agent memory. Runs against the notes directory it is started in.not reviewedEstablishedA
- ProtectFail-closed Cedar policy gate + Ed25519 signed receipts for agent tool calls. Denies on any error.not reviewedGrowingC
- MCP ServerDeterministic intent preflight before your agent builds: six gates, keyless, no model call.not reviewedGrowingB
- X402 TrustTrust & reliability data for x402 endpoints before your agent pays them.not reviewedGrowingB
- MCPAuthorize consequential AI agent actions before executionnot reviewedEstablishedA