← Index

io.github.getaegis/aegis

io.github.getaegis/aegis·v1.0.3·Other

Credential isolation for AI agents. Inject secrets at the network boundary.

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
AEGIS_MASTER_KEY
requiredsecret

Master encryption key for the credential vault

AEGIS_SALT
requiredsecret

Hex-encoded 32-byte salt for key derivation (generated by aegis init)

AEGIS_DATA_DIR

Directory for vault databases and registry (default: .aegis/)

AEGIS_PORT

Gate proxy port (default: 3100)

AEGIS_LOG_LEVEL

Log verbosity: debug, info, warn, error (default: info)

AEGIS_LOG_FORMAT

Log output format: json or pretty (default: json)

AEGIS_VAULT

Named vault to use (default: default)

AEGIS_REQUIRE_AGENT_AUTH

Require agent authentication on every request (true/false, default: false)

AEGIS_POLICY_MODE

Policy enforcement mode: enforce, dry-run, or off (default: enforce)

AEGIS_POLICIES_DIR

Directory containing YAML policy files

AEGIS_METRICS

Enable Prometheus metrics endpoint (true/false, default: true)

MCP quality score · maturity, not trust · methodology
freshness
23
completeness
10
installability
25
documentation
15
stability
10
Alternatives in Other