AGY BridgeSAFE
MCP bridge that lets Claude Code delegate heavy tasks to the Antigravity CLI (agy) — purpose-built tools, model routing with fallback, session continuity, and output truncation to save Claude's context and tokens.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/sshahzaiib/agy-bridge/actions/workflows/ci.yml) [](https://www.npmjs.com/package/agy-bridge) [](https://www.npmjs.com/package/agy-bridge) [](https://nodejs.org) [](LICENSE)
[](https://glama.ai/mcp/servers/sshahzaiib/agy-bridge)
[](https://mseep.ai/app/sshahzaiib-agy-bridge)
An MCP bridge that lets Claude Code delegate heavy tasks to the Antigravity CLI (`agy`) — saving Claude's context window and tokens for what matters.
Claude sends a task → the bridge routes it to the best available model via agy → only the answer comes back. Large files, deep git searches, and web lookups never touch Claude's context.
Listed on
[](https://glama.ai/mcp/servers/sshahzaiib/agy-bridge) [](https://mcpmarket.com/server/agy-bridge) [](https://www.pulsemcp.com/servers/sshahzaiib-agy-bridge) [](https://mcp.so/server/agy-bridge/sshahzaiib) [](https://mcpservers.org/servers/sshahzaiib/agy-bridge) [
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
adversarial_review | read | Get an adversarial second opinion from a different model family (Gemini Pro). |
analyze_files | read | Delegate file analysis to the Antigravity CLI (Gemini) instead of reading files yourself. |
deep_search | read | Delegate codebase archaeology to the Antigravity CLI: git log/diff/blame spelunking, |
delegate | read | Raw delegation to the Antigravity CLI for heavy tasks that don |
follow_up | read | Continue a previous Antigravity session by session_id (returned by every other tool). |
web_lookup | read | Delegate a web/documentation lookup to the Antigravity CLI (Gemini with web access): |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
.commitlintrc.json
.prettierignore
.prettierrc.json
@modelcontextprotocol/sdk, zod, @commitlint/cli, @commitlint/config-conventional, @types/node, husky, lint-staged, prettier
Gates applied: no_behavioural_pass.
d2ede38e91b8full audit observations/trust-audit/mcp-server/sshahzaiib__agy-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d2ede38e91b8 | SAFE | B | 89 | first audit |
Questions
What is the AGY Bridge MCP server?
MCP bridge that lets Claude Code delegate heavy tasks to the Antigravity CLI (agy) — purpose-built tools, model routing with fallback, session continuity, and output truncation to save Claude's context and tokens.
What tools does AGY Bridge expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AGY Bridge safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does AGY Bridge need?
No credential environment variables were found in its source, so it appears to need none.
How does AGY Bridge run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as agy-bridge at 0.4.2.
How current is this page?
The grade is for one exact copy of the source (d2ede38e91b8), read on 2026-10-08. The repository is watched and re-audited when it changes.