ACPSAFE
A bridge server that connects Agent Communication Protocol (ACP) agents with Model Context Protocol (MCP) clients, enabling seamless integration between ACP-based AI agents and MCP-compatible tools like Claude Desktop.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/py/acp-mcp-server) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT)
A bridge server that connects Agent Communication Protocol (ACP) agents with Model Context Protocol (MCP) clients, enabling seamless integration between ACP-based AI agents and MCP-compatible tools like Claude Desktop.
✨ Features
- 🔄 Protocol Bridge: Seamlessly connects ACP agents with MCP clients
- 🚀 Multiple Transports: Supports STDIO, SSE, and Streamable HTTP
- 🤖 Agent Discovery: Automatic discovery and registration of ACP agents
- 🧠 Smart Routing: Intelligent routing of requests to appropriate agents
- 🔄 Async Support: Full support for synchronous and asynchronous operations
- 💬 Interactive Sessions: Support for multi-turn agent interactions
- 🌐 Multi-Modal: Handle text, images, and other content types
🚀 Quick Start
Installation
# Install from PyPI pip install acp-mcp-server # Or use uvx for isolated execution uvx acp-mcp-server
Basic Usage
# Run with STDIO (default, for Claude Desktop) acp-mcp-server # Run with SSE transport acp-mcp-server --transport sse --port 8000 # Run with HTTP transport acp-mcp-server --transport streamable-http --host 0.0.0.0 --port 9000 # Connect to different ACP server acp-mcp-server --acp-url http://localhost:8001
Using with Claude Desktop
Add to your Claude Desktop configuration:
{
"mcpServers": {
"acp-bridge": {
"command": "uvx",
"args": ["acp-mcp-server"]
}
}
}📋 Requirements
- Python 3.11+
- Running ACP server with agents
- FastMCP for protocol implementation
🔧 Configuration
Environment Variables
- `ACPBASE
30c5fb2c317cOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add acp-mcp-server -- uvx acp-mcp-server
{
"mcpServers": {
"acp-mcp-server": {
"command": "uvx",
"args": [
"acp-mcp-server"
]
}
}
}Exposed tools (16)
12 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_routing_rule | write | Add a new routing rule to a strategy |
analyze_message_content | read | Analyze the content types and structure of an ACP message |
cancel_interaction | read | Cancel a pending interactive agent |
convert_acp_message | read | Convert ACP message format to MCP-compatible format |
discover_acp_agents | read | Discover all available ACP agents and register them as resources |
get_agent_info | read | Get detailed information about a specific ACP agent |
get_async_run_result | write | Get the result of an asynchronous run |
get_server_info | read | Get information about the ACP-MCP bridge server |
list_active_runs | read | List all active runs |
list_pending_interactions | read | List all pending interactive agents waiting for input |
list_routing_strategies | read | List all available routing strategies and their rules |
provide_user_input | read | Provide user input to resume a waiting interactive agent |
run_acp_agent | write | Execute an ACP agent with specified mode |
smart_route_request | read | Intelligently route a request to the best ACP agent |
start_interactive_agent | write | Start an interactive ACP agent that may require user input |
test_routing | read | Test routing without executing - shows which agent would be selected |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
sse,streamable-http
fastmcp, acp-sdk, uvicorn, asyncio, aiohttp, pydantic, python-multipart
Gates applied: no_behavioural_pass.
30c5fb2c317cfull audit observations/trust-audit/mcp-server/gongrzhe__acp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 30c5fb2c317c | SAFE | B | 89 | first audit |
Questions
What is the ACP MCP server?
A bridge server that connects Agent Communication Protocol (ACP) agents with Model Context Protocol (MCP) clients, enabling seamless integration between ACP-based AI agents and MCP-compatible tools like Claude Desktop.
What tools does ACP expose?
16 in total: 12 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ACP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does ACP need?
No credential environment variables were found in its source, so it appears to need none.
How does ACP run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as acp-mcp-server.
How current is this page?
The grade is for one exact copy of the source (30c5fb2c317c), read on 2026-10-09. The repository is watched and re-audited when it changes.