AAI GatewaySAFE
AAI Gateway — Install MCP servers and skills once, share across all your AI agents. One-time setup, 90% less context overhead. The unified gateway for AI agent tooling.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 简体中文 | 日本語 | 한국어
[](https://www.npmjs.com/package/aai-gateway) [](./LICENSE)
What Is It
AAI = Agent App Interface
AAI Gateway is the interaction gateway for Agent Apps.
What is an Agent App? An Agent App is a collection of capabilities that an Agent can use. For example:
- An MCP Server is an Agent App — it provides a set of tools
- A Skill package is an Agent App — it provides one or more skills
In AAI Gateway, they are abstracted as Agent Apps under unified management. Import once, and all AI Agents can use them immediately.
What Problems Does It Solve
Context Bloat
Traditional: 10 MCPs × 5 tools = 50 full schemas ≈ 7,500 tokens injected into every conversation.
AAI Gateway: each Agent App needs only fewer than 50 tokens for a summary, with details loaded on demand. 99% token savings.
Finding Tools Is Hard
Traditional: search GitHub → read READMEs → copy JSON configs → debug connections → restart Agent.
AAI Gateway: tell your Agent "use AAI to search for xxx" — auto-searches, installs, ready to use.
"Use AAI to search for a browser automation tool" → Search → finds Playwright MCP → Agent summarizes a one-line Agent App summary → install → ready to use, no restart needed
"Use AAI to search for a PPT creation skill" → Search → finds PPT Skill → uses skill description as Agent App summary → install → ready to use, no restart needed
Duplicate Config
Configure the same thing in Claude Code, Codex, and OpenCode separately? Import once through AAI Gateway, all Agents share instantly.
Quick Start (30 Seconds)
Claude Code:
claude mcp add --scope user --transport stdio aai-g
b22ee8d511c0OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add aai-gateway -- npx -y [email protected]
{
"mcpServers": {
"aai-gateway": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (8)
2 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
disableApp | write | Disable one app for the current agent only. If you do not know the app id, call listAllAaiApps first to find it. |
enableApp | write | Enable or re-enable an app for the current agent. When the user asks to enable, start, turn on, or use a specific app by name, call listAllAaiApps first to check if it is already imported before searching for new tools. |
getAppConfig | write | Get the full configuration of an imported app plus ready-to-share install snippets. Use this when: (1) the user wants to inspect or check an app\ |
listAllAaiApps | read | List imported apps (MCP servers and skills) for the current agent. This does not include built-in tools like search:discover, mcp:import, or skill:import — those are always available. |
read | read | Read the skill documentation |
removeApp | destructive | Remove one AAI Gateway managed import from all agents. If you do not know the app id, call listAllAaiApps first to find it. |
search | write | Run a web search using Brave Search. |
updateAppConfig | write | Update an imported MCP server\ |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
removeApp
const hash = createHash('sha1').update(seed).digest('hex').slice(0, 8);import { logger } from '../../utils/logger.js';const { getAcpExecutor } = await import('../../executors/acp.js');const config = app.descriptor.access.config as import('../../types/index.js').AcpAgentConfig;import { logger } from '../../utils/logger.js';import { getAcpExecutor } from '../../executors/acp.js';@modelcontextprotocol/sdk, pino, pino-pretty, zod, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8
AAI Gateway is a unified MCP gateway that manages **Agent Apps** (MCP servers, Skills, ACP agents). It runs as a single MCP server (stdio) and routes tool calls to downstream apps, enabling multiple A
Gates applied: no_behavioural_pass.
b22ee8d511c0full audit observations/trust-audit/mcp-server/gybob__aai-gateway.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b22ee8d511c0 | SAFE | B | 89 | first audit |
Questions
What is the AAI Gateway MCP server?
AAI Gateway — Install MCP servers and skills once, share across all your AI agents. One-time setup, 90% less context overhead. The unified gateway for AI agent tooling.
What tools does AAI Gateway expose?
8 in total: 2 read-only, 5 that write, and 1 that can delete or overwrite (removeApp). Every one is listed on this page with its risk.
Is AAI Gateway safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does AAI Gateway need?
No credential environment variables were found in its source, so it appears to need none.
How does AAI Gateway run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as aai-gateway at 1.2.0.
How current is this page?
The grade is for one exact copy of the source (b22ee8d511c0), read on 2026-10-07. The repository is watched and re-audited when it changes.