SkillAgentSearch skills...

infrabroker

Infrastructure access broker for AI agents — SSH & Kubernetes. Per-operation ephemeral credentials minted by a separate signer; the model never touches one. MCP stdio / HTTP+OIDC.

Install / Use

claude mcp add luisgf -- npx -y github:luisgf/infrabroker

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

84/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of infrabroker

infrabroker scores 84/100 on our quality scale, 78th of 197 Security skills we index (top 40%).

Its MCP Server is 16 KB long, well organised into 21 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.

It has 10 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
4/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 2 days ago, so infrabroker is actively maintained.
  • Our last check on 2026-09-24 found the source still online.
  • It is released under GPL-3.0, a copyleft license: you can use it, but modified versions you distribute must carry the same license.
  • Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

infrabroker compared with similar skills

All 4 of these similar skills score higher than infrabroker; compare them before choosing.

SkillScoreStarsUpdatedFormat
infrabroker (this skill)by luisgf84102d agoMCP Server
Agent-Reachby Panniantong10085.2k9d agoCLAUDE.md
headroomby headroomlabs-ai10073.7ktodayCLAUDE.md
rufloby ruvnet10073.2ktodayCLAUDE.md
CowAgentby zhayujie10047.1ktodayCLAUDE.md

Frequently asked questions

How do I install infrabroker?
Run claude mcp add luisgf -- npx -y github:luisgf/infrabroker. The install tabs above show the steps for each supported agent.
Which AI agents does infrabroker work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is infrabroker safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is GPL-3.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is infrabroker still maintained?
The repository was last updated 2 days ago, so infrabroker is actively maintained.

infrabroker

CI Release Go Report Card License: GPL-3.0 Docs

Infrastructure access broker for AI agents — SSH & Kubernetes. The model never touches a credential. (formerly ssh-broker)

The agent requests an action — run a command on a host, query or change a cluster. infrabroker checks it against policy, executes it with a credential minted for that single operation — an ephemeral, scope-limited SSH certificate from its own CA, or a short-lived bound ServiceAccount token — and returns only the output. Keys, certificates and tokens live in the broker's memory and are discarded after the call: nothing enters the model's context, so a prompt-injected agent has nothing to exfiltrate.

One binary — infrabroker — exposes the same engine (internal/broker) and tool surface (internal/mcpserver) over three transports, chosen by subcommand. (The legacy per-transport binaries broker / mcp-broker / mcp-broker-http remain as thin deprecated wrappers over these subcommands, so existing configs keep working.)

  • MCP stdio (local, recommended for personal use) — infrabroker serve-mcp. Tools: ssh_execute, ssh_session_open / ssh_session_exec / ssh_session_close, ssh_list_servers, ssh_put_file / ssh_get_file; with clusters configured, also k8s_get / k8s_list / k8s_logs / k8s_apply / k8s_delete / k8s_list_clusters. No transport auth — isolation comes from the process being launched by the user (as the MCP spec recommends for stdio).
  • MCP HTTP + OAuth2/OIDC (remote, multi-user) — infrabroker serve-mcp-http, Streamable HTTP. Same tools, but each client authenticates with an OIDC bearer token validated locally against the issuer's JWKS; the user identity (and groups, for per-user RBAC) is propagated to the signer.
  • HTTP + mTLS — infrabroker serve-http, POST /v1/ssh_run (one-shot), for network agents authenticated with a client certificate.

Documentation

This README is a landing page. The detail lives in focused, single-source docs:

| Document | Contents | |---|---| | QUICKSTART.md | First ssh_execute in under 10 minutes — single-binary local mode, no signer/PKI | | ARCHITECTURE.md | Diagram, request flow, design decisions, sudo elevation, sessions, multi-CA | | THREAT_MODEL.md | Actors, trust boundaries, security controls, and explicit non-goals/gaps | | OPERATIONS.md | Runbook: startup, adding hosts, hot-reload, broker-ctl, PKI rotation, configs | | MESH.md | Running infrabroker over a NetBird / Tailscale mesh — the session layer on top of the overlay path | | HA.md | Why it is single-instance today: state inventory, the blockers, and what degrades under replication | | API.md | HTTP endpoint reference for all services | | USAGE.md | Guide to the MCP tools (SSH + Kubernetes), dry-run, and audit review (for the model / operator) | | SECURITY.md | Vulnerability disclosure policy | | CONTRIBUTING.md · CODING_STYLE.md | Workflow, versioning, Go style |

Why infrabroker

  • Anti-exfiltration (prompt injection): the ephemeral key/cert/token live only in the broker's memory; they never enter the model's context.
  • Kubernetes without kubeconfigs: the signer mints a short-lived bound ServiceAccount token (TokenRequest API) per operation; every cluster is default-deny with per-verb/resource/namespace policy and the same dry-run, approval and audit path as SSH.
  • Anti-reuse: each cert carries a TTL of minutes, source-address (broker or bastion IP), and — for one-shot — a force-command. Useless outside its host/time/IP.
  • Controlled escalation: allow_sudo / allowed_sudo_users live in the signer; a compromised broker cannot escalate where policy forbids it.
  • CA compromise bounded: one CA per host group (ca_keys), each key optionally in Azure Key Vault or ssh-agent (YubiKey PIV / SoftHSM / TPM) — the private key never leaves the HSM.
  • Audit / non-repudiation: append-only, Ed25519-chained log correlated by serial across signer, broker, and sshd.

The full threat model — including what the system deliberately does not defend — is in THREAT_MODEL.md.

How it works

AI model ──tool call──> broker ──mTLS──> [control-plane] ──mTLS──> signer
   (no credential)      (ephemeral key      (approval +          (CA key +
                         in RAM, never        guardrails,          policy + RBAC,
                         on disk)             no CA key)           signs the cert)
                            │
                            └── SSH with the ephemeral cert ──> bastion ──> target host
                                                                 └─ stdout/stderr/exit_code ─> model

The broker sends an intent ({host, role, purpose, command?, sudo?, pty?, pubkey, …}); the signer derives every certificate constraint from policy and returns the signed cert. The ephemeral private key is generated in the broker and never leaves it. See ARCHITECTURE.md for the request flow, the design decisions, and the per-hop ProxyJump certificate diagrams.

Feature overview

| Capability | One-liner | More | |---|---|---| | Ephemeral certificates | Ed25519 pair in RAM per operation; minutes-long, scoped cert. No reusable secret. | ARCHITECTURE | | External signer | A separate cmd/signer holds the CA key and policy; the broker never does. | ARCHITECTURE | | Multi-CA + HSM | One CA key per host group via ca_keys; local PEM, Azure Key Vault, or ssh-agent/HSM. | ARCHITECTURE | | AI-action firewall | Per-host or composable-by-group command policy (allow/deny/require_approval), POSIX-sh AST parsing, dry-run. Authoritative for one-shot. | ARCHITECTURE · USAGE | | Human-in-the-loop approval | Optional control plane gates require_approval commands behind out-of-band approval; the signer enforces it. | ARCHITECTURE · API | | Action budgets (behaviour guardrails) | Budget how much an agent can do: per-CN sign-rate cap plus per-subject rate limit and novelty escalation (a subsequent new host / novel command → approval); observe or enforce. Network tools budget what an agent can reach or spend; this budgets the actions themselves. | OPERATIONS · ARCHITECTURE | | RBAC | Broker-CN groups (mTLS) + per-end-user OIDC groups; fail-closed. | ARCHITECTURE | | sudo / PTY | Policy-gated elevation (sudo -n) and PTY allocation, per host. | ARCHITECTURE | | Kubernetes broker | k8s_* tools with per-operation bound SA tokens, default-deny verb/resource/namespace policy, dry-run. | USAGE §10 | | Session recording | shell/pty sessions to ASCIIcast v2 (.cast), indexed by session_id. | USAGE §8 | | Chained audit | Append-only, Ed25519-signed, SHA-256-chained; correlated by serial. | USAGE §7 · API | | Hot reload | signer.json re-read (and validated) without restart, via POST /v1/reload or SIGHUP. | OPERATIONS §3 |

Comparison with existing solutions

Several tools address SSH access control or AI-agent credential security, but none cover the full combination that infrabroker targets in a lightweight, self-hosted package.

| Feature | infrabroker | Teleport | Vault + SSH engine | StrongDM | ssh-mcp | |---|---|---|---|---|---| | Ephemeral cert in memory (no disk) | ✅ | ✅ | ✅ | ❌ | ❌ | | Separate broker / signing service | ✅ | ✅ | Partial | ❌ | ❌ | | MCP-native (AI agents) | ✅ | ✅ (2025) | ✅ (2025) | ❌ | ✅ | | OAuth2/OIDC on MCP transport | ✅ | ✅ | ✅ | ❌ | ❌ | | Per-command policy + dry-run (AI-action firewall) | ✅ | ❌ | ❌ | ❌ | ❌ | | Human-in-the-loop approval for AI commands | ✅ | ❌ | ❌ | ❌ | ❌ | | Per-agent behavioral guardrails (anomaly/rate) | ✅ | ❌ | ❌ | ❌ | ❌ | | Session recording (ASCIIcast v2, stdin+stdout+stderr) | ✅ | ✅ | ❌ | Partial | ❌ | | Cryptographically chained audit log | ✅ | ❌ | ❌ | Partial | ❌ | | Single-binary / simple self-hosted | ✅ | ❌ | ❌ | ❌ | ✅ | | HSM/KMS for CA key | ✅ (AKV) | ✅ | ✅ | — | — |

Teleport is the closest commercial equivalent — short-lived SSH certs, RBAC, and since 2025 Secure MCP; its Jan-2026 Agentic Identity Framework targets the same threat model. The difference is operational weight: Teleport needs a dedicated control-plane cluster, recording proxy, and web UI — orders of magnitude heavier than a Go binary + signer.

HashiCorp Vault SSH secrets engine is an SSH CA with full HSM/KMS support and (2025) its own MCP server, but it provides only the signing piece — you still build the execution layer (engine.go, session.go, the MCP tools) yourself.

StrongDM hides credentials but stores long-lived secrets rather than generating ephemeral certs in memory, making it weaker against exfiltration. Smallstep SSH CA is a lightweight OIDC-integrated SSH CA (close to cmd/signer) with no execution broker or MCP layer. ssh-mcp exposes SSH to LLMs over MCP but uses a static SSH key — the exact vulnerability this broker prevents. CyberArk PAM offers comparable JIT cert access but is a closed enterprise platform for human operators, not AI workloads.

Where it fits: MCP-native AI-agent access + in-memory ephemeral certs + separate signer + ASCIIcast recording + chained audit, as a small set of Go binaries without a cluster. Enterprise features (web UI, multi-region HA) are on the roadmap (see HANDOFF.md).

Install

  • Prebuilt binaries — each release ships infrabroker_<ver>_{linux,darwin}_{amd64,arm64}.tar.gz with all binaries, plus the installer tarball (infrabroker-v<ver>.tar.gz) that deploy/install.sh consumes for the systemd production path.
  • go install — go install github.com/luisgf/infrabroker/cmd/infrabroker@latest (pure Go, no CGO; same for the other cmd/ binaries).
  • Container — ghcr.io/luisgf/infrabroker (docker or podman, multi-arch; entrypoint is the stdio MCP frontend). See CONTAINERS.md, including a compose demo that runs the full stack against a toy host: cd examples/compose && docker compose up --build -d (or make demo).
  • From source — the Quickstart below.

Register with Claude Code in one line — native binary or container:

claud

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars10
CategorySecurity
Updated2d ago
Forks0

Languages

Go

Trust signals

97/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info