Poke GateBLOCK
Expose your machine to your Poke AI assistant via MCP tunnel
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Poke Gate
Let your Poke AI assistant access your machine. A community project — not affiliated with Poke or The Interaction Company.
Run Poke Gate on your Mac, then message Poke from iMessage, Telegram, or SMS to run commands, read files, take screenshots, and more — all on your machine.
Install
Homebrew (recommended)
brew install f/tap/poke-gate
Install via npx
If you have Node.js installed, you can download and install the macOS app with a single command:
npx poke-gate download-macos
This downloads the latest DMG from GitHub Releases, installs the app to /Applications, and clears the quarantine flag automatically.
Don't have Node.js? Install it first:
# Option 1: Homebrew brew install node # Option 2: Download from https://nodejs.org
Manual download
Download the latest Poke.macOS.Gate.dmg from Releases, open it, and drag to Applications. Since the app is not notarized, you may need to run:
xattr -cr /Applications/Poke\ macOS\ Gate.app
CLI only (no macOS app needed)
If you just want to run poke-gate from the terminal without the menu bar app:
n
6354bdbd58caOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add poke-gate --env BEEPER_TOKEN=${BEEPER_TOKEN} --env POKE_GATE_HMAC_SECRET=${POKE_GATE_HMAC_SECRET} -- npx -y [email protected]{
"mcpServers": {
"poke-gate": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BEEPER_TOKEN": "${BEEPER_TOKEN}",
"POKE_GATE_HMAC_SECRET": "${POKE_GATE_HMAC_SECRET}"
}
}
}
}Exposed tools (9)
5 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_directory | read | List files and directories at a given path on the user |
network_speed | write | Run a built-in internet speed test and return download/upload Mbps. |
read_file | read | Read the contents of a file on the user |
read_image | read | Read an image or binary file and return it as base64-encoded data. |
run_agent | write | Run a Poke Gate agent by name. Agents are scheduled scripts in ~/.config/poke-gate/agents/. |
run_command | write | Execute a shell command on the user |
system_info | read | Get system information: OS, hostname, architecture, uptime, memory, and home directory. |
take_screenshot | read | Take a screenshot of the user |
write_file | write | Write content to a file on the user |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
exec(`node "${agent.path}"`, {exec(commandToRun, {/(^|\s)sudo(\s|$)/i,
const withoutSudo = withoutParens.replace(/^sudo\s+/, "");
/launchctl\s+bootout/i,
const response = await fetchImpl(`http://127.0.0.1:${port}/json/version`);const response = await fetchImpl(`http://127.0.0.1:${port}/json/new?${encodeURIComponent(url)}`, {const listResponse = await fetchImpl(`http://127.0.0.1:${port}/json/list`);const response = await fetchImpl(`http://127.0.0.1:${port}/json/list`);.remarkignore
.remarkrc.mjs
.env.beeper
const expectedAccept = createHash('sha1')sudo xcode-select -s "${XCODE_APP}/Contents/Developer"sudo xcode-select -s "${XCODE_APP}/Contents/Developer"assert.equal(evaluateAccessPolicy("run_command", { command: "sudo reboot" }, "full"), null);mermaid, vitepress-plugin-mermaid, vitepress
poke, @eslint/js, eslint, globals, prettier, remark-cli, remark-lint-list-item-indent, remark-parse
assets/logo.png
clients/Poke macOS Gate/Poke macOS Gate/Assets.xcassets/AppIcon.appiconset/[email protected]
conns.json
docs/public/logo.png
system use found in code, not declared in the description
Gates applied: no_behavioural_pass.
6354bdbd58cafull audit observations/trust-audit/mcp-server/f__poke-gate.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6354bdbd58ca | BLOCK | D | 60 | first audit |
Questions
What is the Poke Gate MCP server?
Expose your machine to your Poke AI assistant via MCP tunnel
What tools does Poke Gate expose?
9 in total: 5 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Poke Gate safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Poke Gate need?
It reads BEEPER_TOKEN and POKE_GATE_HMAC_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (6354bdbd58ca), read on 2026-10-07. The repository is watched and re-audited when it changes.