infrabroker
Infrastructure access broker for AI agents — SSH & Kubernetes. Per-operation ephemeral credentials minted by a separate signer; the model never touches one. MCP stdio / HTTP+OIDC.
Install / Use
claude mcp add luisgf -- npx -y github:luisgf/infrabrokerIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of infrabroker
infrabroker scores 84/100 on our quality scale, 78th of 197 Security skills we index (top 40%).
Its MCP Server is 16 KB long, well organised into 21 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 2 days ago, so infrabroker is actively maintained.
- Our last check on 2026-09-24 found the source still online.
- It is released under GPL-3.0, a copyleft license: you can use it, but modified versions you distribute must carry the same license.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
infrabroker compared with similar skills
All 4 of these similar skills score higher than infrabroker; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| infrabroker (this skill)by luisgf | 84 | 10 | 2d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 85.2k | 9d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 73.7k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.2k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.1k | today | CLAUDE.md |
Frequently asked questions
- How do I install infrabroker?
- Run
claude mcp add luisgf -- npx -y github:luisgf/infrabroker. The install tabs above show the steps for each supported agent. - Which AI agents does infrabroker work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is infrabroker safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is GPL-3.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is infrabroker still maintained?
- The repository was last updated 2 days ago, so infrabroker is actively maintained.
Skill content
View source on GitHubinfrabroker
Infrastructure access broker for AI agents — SSH & Kubernetes. The model
never touches a credential. (formerly ssh-broker)
The agent requests an action — run a command on a host, query or change a cluster. infrabroker checks it against policy, executes it with a credential minted for that single operation — an ephemeral, scope-limited SSH certificate from its own CA, or a short-lived bound ServiceAccount token — and returns only the output. Keys, certificates and tokens live in the broker's memory and are discarded after the call: nothing enters the model's context, so a prompt-injected agent has nothing to exfiltrate.
One binary — infrabroker — exposes the same engine (internal/broker) and tool
surface (internal/mcpserver) over three transports, chosen by subcommand. (The
legacy per-transport binaries broker / mcp-broker / mcp-broker-http remain as
thin deprecated wrappers over these subcommands, so existing configs keep
working.)
- MCP stdio (local, recommended for personal use) —
infrabroker serve-mcp. Tools:ssh_execute,ssh_session_open/ssh_session_exec/ssh_session_close,ssh_list_servers,ssh_put_file/ssh_get_file; with clusters configured, alsok8s_get/k8s_list/k8s_logs/k8s_apply/k8s_delete/k8s_list_clusters. No transport auth — isolation comes from the process being launched by the user (as the MCP spec recommends for stdio). - MCP HTTP + OAuth2/OIDC (remote, multi-user) —
infrabroker serve-mcp-http, Streamable HTTP. Same tools, but each client authenticates with an OIDC bearer token validated locally against the issuer's JWKS; the user identity (and groups, for per-user RBAC) is propagated to the signer. - HTTP + mTLS —
infrabroker serve-http,POST /v1/ssh_run(one-shot), for network agents authenticated with a client certificate.
Documentation
This README is a landing page. The detail lives in focused, single-source docs:
| Document | Contents |
|---|---|
| QUICKSTART.md | First ssh_execute in under 10 minutes — single-binary local mode, no signer/PKI |
| ARCHITECTURE.md | Diagram, request flow, design decisions, sudo elevation, sessions, multi-CA |
| THREAT_MODEL.md | Actors, trust boundaries, security controls, and explicit non-goals/gaps |
| OPERATIONS.md | Runbook: startup, adding hosts, hot-reload, broker-ctl, PKI rotation, configs |
| MESH.md | Running infrabroker over a NetBird / Tailscale mesh — the session layer on top of the overlay path |
| HA.md | Why it is single-instance today: state inventory, the blockers, and what degrades under replication |
| API.md | HTTP endpoint reference for all services |
| USAGE.md | Guide to the MCP tools (SSH + Kubernetes), dry-run, and audit review (for the model / operator) |
| SECURITY.md | Vulnerability disclosure policy |
| CONTRIBUTING.md · CODING_STYLE.md | Workflow, versioning, Go style |
Why infrabroker
- Anti-exfiltration (prompt injection): the ephemeral key/cert/token live only in the broker's memory; they never enter the model's context.
- Kubernetes without kubeconfigs: the signer mints a short-lived bound ServiceAccount token (TokenRequest API) per operation; every cluster is default-deny with per-verb/resource/namespace policy and the same dry-run, approval and audit path as SSH.
- Anti-reuse: each cert carries a TTL of minutes,
source-address(broker or bastion IP), and — for one-shot — aforce-command. Useless outside its host/time/IP. - Controlled escalation:
allow_sudo/allowed_sudo_userslive in the signer; a compromised broker cannot escalate where policy forbids it. - CA compromise bounded: one CA per host group (
ca_keys), each key optionally in Azure Key Vault or ssh-agent (YubiKey PIV / SoftHSM / TPM) — the private key never leaves the HSM. - Audit / non-repudiation: append-only, Ed25519-chained log correlated by
serialacross signer, broker, andsshd.
The full threat model — including what the system deliberately does not defend — is in THREAT_MODEL.md.
How it works
AI model ──tool call──> broker ──mTLS──> [control-plane] ──mTLS──> signer
(no credential) (ephemeral key (approval + (CA key +
in RAM, never guardrails, policy + RBAC,
on disk) no CA key) signs the cert)
│
└── SSH with the ephemeral cert ──> bastion ──> target host
└─ stdout/stderr/exit_code ─> model
The broker sends an intent ({host, role, purpose, command?, sudo?, pty?, pubkey, …}); the signer derives every certificate constraint from policy and
returns the signed cert. The ephemeral private key is generated in the broker
and never leaves it. See ARCHITECTURE.md for the request flow,
the design decisions, and the per-hop ProxyJump certificate diagrams.
Feature overview
| Capability | One-liner | More |
|---|---|---|
| Ephemeral certificates | Ed25519 pair in RAM per operation; minutes-long, scoped cert. No reusable secret. | ARCHITECTURE |
| External signer | A separate cmd/signer holds the CA key and policy; the broker never does. | ARCHITECTURE |
| Multi-CA + HSM | One CA key per host group via ca_keys; local PEM, Azure Key Vault, or ssh-agent/HSM. | ARCHITECTURE |
| AI-action firewall | Per-host or composable-by-group command policy (allow/deny/require_approval), POSIX-sh AST parsing, dry-run. Authoritative for one-shot. | ARCHITECTURE · USAGE |
| Human-in-the-loop approval | Optional control plane gates require_approval commands behind out-of-band approval; the signer enforces it. | ARCHITECTURE · API |
| Action budgets (behaviour guardrails) | Budget how much an agent can do: per-CN sign-rate cap plus per-subject rate limit and novelty escalation (a subsequent new host / novel command → approval); observe or enforce. Network tools budget what an agent can reach or spend; this budgets the actions themselves. | OPERATIONS · ARCHITECTURE |
| RBAC | Broker-CN groups (mTLS) + per-end-user OIDC groups; fail-closed. | ARCHITECTURE |
| sudo / PTY | Policy-gated elevation (sudo -n) and PTY allocation, per host. | ARCHITECTURE |
| Kubernetes broker | k8s_* tools with per-operation bound SA tokens, default-deny verb/resource/namespace policy, dry-run. | USAGE §10 |
| Session recording | shell/pty sessions to ASCIIcast v2 (.cast), indexed by session_id. | USAGE §8 |
| Chained audit | Append-only, Ed25519-signed, SHA-256-chained; correlated by serial. | USAGE §7 · API |
| Hot reload | signer.json re-read (and validated) without restart, via POST /v1/reload or SIGHUP. | OPERATIONS §3 |
Comparison with existing solutions
Several tools address SSH access control or AI-agent credential security, but none cover the full combination that infrabroker targets in a lightweight, self-hosted package.
| Feature | infrabroker | Teleport | Vault + SSH engine | StrongDM | ssh-mcp | |---|---|---|---|---|---| | Ephemeral cert in memory (no disk) | ✅ | ✅ | ✅ | ❌ | ❌ | | Separate broker / signing service | ✅ | ✅ | Partial | ❌ | ❌ | | MCP-native (AI agents) | ✅ | ✅ (2025) | ✅ (2025) | ❌ | ✅ | | OAuth2/OIDC on MCP transport | ✅ | ✅ | ✅ | ❌ | ❌ | | Per-command policy + dry-run (AI-action firewall) | ✅ | ❌ | ❌ | ❌ | ❌ | | Human-in-the-loop approval for AI commands | ✅ | ❌ | ❌ | ❌ | ❌ | | Per-agent behavioral guardrails (anomaly/rate) | ✅ | ❌ | ❌ | ❌ | ❌ | | Session recording (ASCIIcast v2, stdin+stdout+stderr) | ✅ | ✅ | ❌ | Partial | ❌ | | Cryptographically chained audit log | ✅ | ❌ | ❌ | Partial | ❌ | | Single-binary / simple self-hosted | ✅ | ❌ | ❌ | ❌ | ✅ | | HSM/KMS for CA key | ✅ (AKV) | ✅ | ✅ | — | — |
Teleport is the closest commercial equivalent — short-lived SSH certs, RBAC, and since 2025 Secure MCP; its Jan-2026 Agentic Identity Framework targets the same threat model. The difference is operational weight: Teleport needs a dedicated control-plane cluster, recording proxy, and web UI — orders of magnitude heavier than a Go binary + signer.
HashiCorp Vault SSH secrets engine
is an SSH CA with full HSM/KMS support and (2025) its own MCP server, but it
provides only the signing piece — you still build the execution layer
(engine.go, session.go, the MCP tools) yourself.
StrongDM hides credentials but stores
long-lived secrets rather than generating ephemeral certs in memory, making it
weaker against exfiltration. Smallstep SSH CA is a
lightweight OIDC-integrated SSH CA (close to cmd/signer) with no execution
broker or MCP layer. ssh-mcp exposes
SSH to LLMs over MCP but uses a static SSH key — the exact vulnerability this
broker prevents. CyberArk PAM offers
comparable JIT cert access but is a closed enterprise platform for human
operators, not AI workloads.
Where it fits: MCP-native AI-agent access + in-memory ephemeral certs + separate signer + ASCIIcast recording + chained audit, as a small set of Go binaries without a cluster. Enterprise features (web UI, multi-region HA) are on the roadmap (see HANDOFF.md).
Install
- Prebuilt binaries — each release
ships
infrabroker_<ver>_{linux,darwin}_{amd64,arm64}.tar.gzwith all binaries, plus the installer tarball (infrabroker-v<ver>.tar.gz) thatdeploy/install.shconsumes for the systemd production path. - go install —
go install github.com/luisgf/infrabroker/cmd/infrabroker@latest(pure Go, no CGO; same for the othercmd/binaries). - Container —
ghcr.io/luisgf/infrabroker(docker or podman, multi-arch; entrypoint is the stdio MCP frontend). See CONTAINERS.md, including a compose demo that runs the full stack against a toy host:cd examples/compose && docker compose up --build -d(ormake demo). - From source — the Quickstart below.
Register with Claude Code in one line — native binary or container:
claud
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
85.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
73.7kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.2k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.1kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
