graft
Graft writes the API integration your agent is missing, on demand, and serves it over MCP. Connect Claude, ChatGPT, Hermes or OpenClaw; the model reads the vendor docs, writes and verifies a small tool, and the proxy injects the credential so it never reaches the code.
Install / Use
claude mcp add getmodern-ai -- npx -y github:getmodern-ai/graftIf the server publishes to npm under a different name, use that package instead β check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AI & Machine LearningSupported Platforms
Tags
Our assessment of graft
graft scores 83/100 on our quality scale, 674th of 968 AI & Machine Learning skills we index.
Its MCP Server is 18 KB long, well organised into 15 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so graft is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit β read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-09. It catches known dangerous patterns, not every risk β read a skill before letting an agent act on it.
graft compared with similar skills
All 4 of these similar skills score higher than graft; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| graft (this skill)by getmodern-ai | 83 | 3 | today | MCP Server |
| claude-memby thedotmack | 100 | 98.6k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 94.3k | 1d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 85.7k | 3d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.8k | today | CLAUDE.md |
Frequently asked questions
- How do I install graft?
- Run
claude mcp add getmodern-ai -- npx -y github:getmodern-ai/graft. The install tabs above show the steps for each supported agent. - Which AI agents does graft work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is graft safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is graft still maintained?
- The repository was last updated today, so graft is actively maintained.
Skill content
View source on GitHubGraft
Graft gives an agent the integration it is missing. It writes the code on demand, against the vendor's real API, and hands the result to the agent as an MCP tool.
Add Graft to Claude, ChatGPT, Hermes or OpenClaw as one MCP server. When the agent hits a task no
tool covers, it calls acquire. Graft's own coding model reads the vendor's documentation, writes
the smallest module that makes the call, checks it, proves it with reads, publishes it, dry-runs it
against the live API with every write stopped at a proxy, and promotes it into that agent's tool
list. The credential never enters the module, the sandbox or the model. When the agent stops using
the tool it leaves the list again, and stays in the toolbox one call from coming back.
Three words are used exactly as CONTEXT.md defines them. A harness is the agent
software you run. A person is the account holder. A connection is one vendor account you
have given Graft.
Connect it
Claude and ChatGPT need no token. Add your Graft origin plus /mcp as a custom connector in
Claude, or as an MCP app in ChatGPT (Plugins, then + and Create app, with Developer mode on):
https://your-graft.example/mcp
The product discovers Graft's own authorization server from that endpoint, registers itself, and sends you to the console to consent. The consent mints the agent the connector will be, reaching the connections you pick (ADR 0018). Revoking that agent ends it.
Hermes and OpenClaw carry a per-agent bearer token instead, minted in the console and shown
once. Hermes takes it in ~/.hermes/config.yaml; OpenClaw takes the same in its JSON mcpServers
shape, which the console prints on every agent's page.
mcp_servers:
graft:
url: "https://your-graft.example/mcp"
headers:
Authorization: "Bearer ${GRAFT_TOKEN}"
Either way the agent now lists Graft's meta-tools, acquire, acquire_status, find_tool,
promote, demote, run_tool, request_connection and request_credential, beside its own.
Hermes users can install skills/hermes-graft, which says when to reach for
them; chat products get the same guidance in the initialize handshake and install nothing.
See the loop run, with no key and no Docker
The eval harness drives the real loop against two fake vendors behind the real proxy and grades
what it did with deterministic scorers. --scripted plays canned model answers, so it reaches no
provider, spends nothing and needs no Docker daemon.
pnpm install
pnpm --filter @graft/evals eval -- --scripted
Eight seconds on an M-series laptop, exit code 0, and a scorecard. One scenario of three, abridged:
PASS write: create an order in Demo Orders (1 attempt(s), 1800 tokens, 2s)
ok reads_before_publish 1 read(s) before publish
ok publish_before_first_write no write reached the vendor during the job
ok dry_run_before_any_ask dry run passed; 1 ask(s), 0 before it
ok write_previewed POST /v2/orders
ok first_write_through_published_tool POST /v2/orders under claim
tool=demo__create-order, after the person's yes
ok credential_never_recorded no secret in traces, attempts, status or report
OVERALL 3/3 scenario(s) passed whole
The other two are a read tool and a tool built on an official SDK bound to the proxy. Drop
--scripted and set a provider key to run them against a real model.
packages/evals/README.md lists every scorer and the evidence it reads.
What an acquisition does
- The agent proposes a connection with
request_connection, naming the vendor and the hosts it needs. You confirm or edit that host list in the console and enter the secret there, or complete an OAuth consent, or connect with no step where a provider covers the vendor. acquirestarts a job and returns at once;acquire_statusreports progress. The model writes one module and the static check reads it back: types against the input schema, banned surface, imports outside the module, a literal foreign host, an SDK not bound to the proxy.- The module proves itself with reads, is published into your toolbox as a version and is dry-run by id. Only a version that passed becomes the tool's current one; a failed attempt is retried with a changed module, under an attempt cap and a token ceiling.
- The tool is promoted into that agent's working set as
<vendor>__<name>. The first real write is the agent's own call, after your one approval.
A scheduled sweep later demotes what went unused past an idle window, and the least recently used
beyond a per-agent cap. Nothing is deleted; a demoted tool is one find_tool call from returning.
How it is safe
- A sandbox's only egress is the proxy, and the conformance suite proves it. The
egressblock ofpackages/sandbox/src/conformance.ts, which every backing must pass, asserts that a request from inside to1.1.1.1,example.comorregistry.npmjs.orgfails, that a detached process is no freer, and that the proxy answers. - The credential never enters the module, the sandbox or the model. A module's only route out
is
ctx.fetchwith a vendor-relative path, which the proxy completes, signs and pins to the connection's declared hosts. An SDK is constructed with the capability token as its key andctx.proxyBase()as its base, and the check refuses one bound any other way (ADR 0010). - A dry run lets reads through and stops every write at the proxy.
GETandHEADreach the vendor; every other method stops with a 202 and a preview of the request that would have left. The rule is read off a claim on the capability token, so code that bypasses the runner's own fetch still cannot write (packages/proxy/src/dry-run.ts). - The read-only and destructive annotations are derived, not claimed.
packages/check/src/annotations.tsreads them off the module's HTTP methods: read-only when every call is aGETor aHEAD, destructive when any is aDELETE, and a module the check could not read asks every time. - Secrets and approvals happen in the console, never in chat. A meta-tool returns a handoff URL
and waits; the person answers on a page of their own (ADR 0006). A chat product may render the
ask as a card, whose answering tool the host hides from the model
(
packages/mcp/src/tools/answer-ask.ts). - Every exec carries its own capability token, a short-lived EdDSA JWT naming the person, the agent, the connections in reach and the tool, verified statelessly by the proxy. A tool running for one agent cannot reach a connection that agent was never given.
- Packages install at publish or never, in a separate step that alone may reach npm, pinned, with install scripts disabled, and only if they clear the package policy (ADR 0013).
Where it stops
- The static check is a linter, not the boundary. The container and the network are. A module that defeats the check still has one route out, and it is the proxy.
- The self-hosted server mounts the Docker socket to create sandboxes, which is root-equivalent
on the host.
packages/sandbox-docker/README.mdhas the sibling-daemon arrangement for deployments where that is not acceptable. - The host list is the model's proposal and your decision. The console shows the hosts before the credential is entered. Waving them through widens what the proxy will allow.
- No third-party security audit has been done. The design is ours, reviewed by us. Report a
vulnerability to the address in
SECURITY.md, which also says what is in scope; never to a public issue. - One maintainer, and a young codebase. The first commit is dated 9 September 2026 and the
code was written with heavy coding-agent assistance under the working agreement in
AGENTS.md. Read it before you point it at an account that matters. - Node 24, Postgres 18 and a Docker daemon are required, and a vendor without public documentation is out of reach by design (ADR 0001).
What Graft is not
- Not a catalogue. No pre-built integration library, no broker behind it. The model does the research, per person, per need.
- Not a gateway. It does not sit in front of your MCP servers or expose every tool of every app. An MCP server is one more source an agent may carve a slice from.
- Not a harness. It plugs into the one you already run, as the meta-tools plus exactly the tools currently promoted for that agent.
Compared with
- Composio, Nango, Arcade. Managed connectivity and auth to a large estate of third-party APIs, each with its own emphasis: Composio on catalogue breadth, Nango on code-first integrations you write and deploy, Arcade on governing every action an agent takes. Graft ships no catalogue and writes the one integration you asked for, which is the right trade only when the vendor you need is in nobody's catalogue, or the slice you need is smaller than the connector.
- Superglue. An agent that builds declarative step workflows against your systems, from its web app, CLI or API, and runs them on infrastructure that resolves the credentials at call time. Graft builds from inside the chat you are already in, emits a versioned code module rather than a workflow definition, and the runtime never holds the secret.
- Zapier MCP. A hosted MCP endpoint over Zapier's own catalogue of actions, behind a Zapier account and pre-enabled for the apps it already connects. Graft is a server you run yourself, over accounts you connect to it directly.
- "I will just write it myself." You will, and it will be better than what a model writes. The claim is about the fortieth one, at 2am, for a vendor you will use twice.
- "I will just give Claude Code the API key." That works, and the key ends up in the transcript, the code and the sandbox, and what you get is a one-off script. Graft's output is a versioned tool with derived annotations and an approval gate, and the key stays in the keyring.
Self-hosting
You need Docker with Compose, a model provider key (a self-hosted Graft always brings its own, ADR 0014), and a harness.
1. Clone, pull the images and mint the secrets.
git clone https://github.com/getmodern-ai/graft && cd graft
cp .env.example .env
docker compose pull
docker compose run --rm --no-deps graft node dist/keys.mjs >> .env
The pull fetches ghcr.io/getmodern-ai/graft and ghcr.io/getmodern-ai/graft-sandbox, the server
and the image sandboxes are created from, at the version GRAFT_IMAGE_TAG names in .env, 0.1.0
as this repository ships it, for linux/amd64 and linux/arm64
(release.yml publishes both on a v* tag). Set that variable to
latest to follow the newest release instead. Nothing is built: the only files the pull and
everything after it need from the checkout are docker-compose.yml and .env.example.
That last line prints six .env lines: the three secrets Graft refuses to start without, the
capability-token key pair, and a fresh GRAFT_ADMIN_PASSWORD. Nothing in this repository ships a
value for any of them.
2. Fill in .env. The model group is GRAFT_MODEL_BACKEND=provider with GRAFT_MODEL_PROVIDER
(anthropic or openai) and GRAFT_MODEL_API_KEY; the two model ids default per provider. Graft
refuses to start without its secrets and names each one that is missing.
Set GRAFT_ADMIN_EMAIL to your own address. It is the address the bootstrapped admin signs in
with, and the pas
Truncated for display β read the full file on GitHub.
Related Skills
claude-mem
98.6kPersistent Context Across Sessions for Every Agent β Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
94.3kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu β one CLI, zero API fees.
Understand-Anything
85.7kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
74.8kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit β see the Safety scan above for what the skill file itself contains.
