Atlas / MCP servers / gybob / AAI Gateway

AAI GatewaySAFE

mcp/gybob/aai-gateway

AAI Gateway — Install MCP servers and skills once, share across all your AI agents. One-time setup, 90% less context overhead. The unified gateway for AI agent tooling.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 2r · 5w · 1d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文 | 日本語 | 한국어

[](https://www.npmjs.com/package/aai-gateway) [](./LICENSE)

What Is It

AAI = Agent App Interface

AAI Gateway is the interaction gateway for Agent Apps.

What is an Agent App? An Agent App is a collection of capabilities that an Agent can use. For example:

  • An MCP Server is an Agent App — it provides a set of tools
  • A Skill package is an Agent App — it provides one or more skills

In AAI Gateway, they are abstracted as Agent Apps under unified management. Import once, and all AI Agents can use them immediately.

What Problems Does It Solve

Context Bloat

Traditional: 10 MCPs × 5 tools = 50 full schemas ≈ 7,500 tokens injected into every conversation.

AAI Gateway: each Agent App needs only fewer than 50 tokens for a summary, with details loaded on demand. 99% token savings.

Finding Tools Is Hard

Traditional: search GitHub → read READMEs → copy JSON configs → debug connections → restart Agent.

AAI Gateway: tell your Agent "use AAI to search for xxx" — auto-searches, installs, ready to use.

"Use AAI to search for a browser automation tool" → Search → finds Playwright MCP → Agent summarizes a one-line Agent App summary → install → ready to use, no restart needed
"Use AAI to search for a PPT creation skill" → Search → finds PPT Skill → uses skill description as Agent App summary → install → ready to use, no restart needed

Duplicate Config

Configure the same thing in Claude Code, Codex, and OpenCode separately? Import once through AAI Gateway, all Agents share instantly.

Quick Start (30 Seconds)

Claude Code:

claude mcp add --scope user --transport stdio aai-g
Read from source at commit b22ee8d511c0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add aai-gateway -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "aai-gateway": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (8)

2 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
disableAppwriteDisable one app for the current agent only. If you do not know the app id, call listAllAaiApps first to find it.
enableAppwriteEnable or re-enable an app for the current agent. When the user asks to enable, start, turn on, or use a specific app by name, call listAllAaiApps first to check if it is already imported before searching for new tools.
getAppConfigwriteGet the full configuration of an imported app plus ready-to-share install snippets. Use this when: (1) the user wants to inspect or check an app\
listAllAaiAppsreadList imported apps (MCP servers and skills) for the current agent. This does not include built-in tools like search:discover, mcp:import, or skill:import — those are always available.
readreadRead the skill documentation
removeAppdestructiveRemove one AAI Gateway managed import from all agents. If you do not know the app id, call listAllAaiApps first to find it.
searchwriteRun a web search using Brave Search.
updateAppConfigwriteUpdate an imported MCP server\
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
removeApp
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/ids.ts:13
const hash = createHash('sha1').update(seed).digest('hex').slice(0, 8);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/background/acp-prewarm-task.ts:10
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/background/acp-prewarm-task.ts:32
const { getAcpExecutor } = await import('../../executors/acp.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/background/acp-prewarm-task.ts:33
const config = app.descriptor.access.config as import('../../types/index.js').AcpAgentConfig;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/background/task-manager.ts:11
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/background/turn-cleanup.ts:8
import { getAcpExecutor } from '../../executors/acp.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, pino, pino-pretty, zod, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:28
AAI Gateway is a unified MCP gateway that manages **Agent Apps** (MCP servers, Skills, ACP agents). It runs as a single MCP server (stdio) and routes tool calls to downstream apps, enabling multiple A
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b22ee8d511c0full audit observations/trust-audit/mcp-server/gybob__aai-gateway.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b22ee8d511c0SAFEB89first audit
06

Questions

What is the AAI Gateway MCP server?

AAI Gateway — Install MCP servers and skills once, share across all your AI agents. One-time setup, 90% less context overhead. The unified gateway for AI agent tooling.

What tools does AAI Gateway expose?

8 in total: 2 read-only, 5 that write, and 1 that can delete or overwrite (removeApp). Every one is listed on this page with its risk.

Is AAI Gateway safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AAI Gateway need?

No credential environment variables were found in its source, so it appears to need none.

How does AAI Gateway run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as aai-gateway at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (b22ee8d511c0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement