systemprompt-demo
AI Governance Infrastructure — open gateway demo. Self-hosted systemprompt.io gateway in a single Rust binary: policy, audit trails, and cost attribution on every AI request, with the Systemprompt Bridge desktop app for Windows and macOS connecting Claude Code and Claude Cowork.
Install / Use
claude mcp add systempromptio -- npx -y github:systempromptio/systemprompt-demoIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AI & Machine LearningSupported Platforms
Our assessment of systemprompt-demo
systemprompt-demo scores 77/100 on our quality scale, 540th of 690 AI & Machine Learning skills we index.
Its MCP Server is 9.4 KB long, split into 6 sections with 3 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 17 days ago, so systemprompt-demo is actively maintained.
- Our last check on 2026-09-12 found the source still online.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-25. Automated pattern scan on 2026-09-25. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
systemprompt-demo compared with similar skills
All 4 of these similar skills score higher than systemprompt-demo; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| systemprompt-demo (this skill)by systempromptio | 77 | 3 | 17d ago | MCP Server |
| claude-memby thedotmack | 100 | 94.7k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 85.5k | 10d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 84.2k | 14d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 73.8k | today | CLAUDE.md |
Frequently asked questions
- How do I install systemprompt-demo?
- Run
claude mcp add systempromptio -- npx -y github:systempromptio/systemprompt-demo. The install tabs above show the steps for each supported agent. - Which AI agents does systemprompt-demo work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is systemprompt-demo safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is systemprompt-demo still maintained?
- The repository was last updated 17 days ago, so systemprompt-demo is actively maintained.
Skill content
View source on GitHubPrivate, managed Claude Cowork. Five minutes from sign-up.
Sign up, get $1 of credit, download the Bridge, and Claude Cowork and Claude Desktop are configured for you automatically. Every request runs through a gateway you can see into: every prompt, every tool call, every cent, one audit trail. Most AI access is a black box someone else operates. This one shows you every row.
systemprompt.io · Documentation · Guides · Discord
<picture> <source media="(prefers-color-scheme: dark)" srcset="demo/recording/svg/output/dark/cap-secrets.svg"> <source media="(prefers-color-scheme: light)" srcset="demo/recording/svg/output/light/cap-secrets.svg"> <img src="demo/recording/svg/output/dark/cap-secrets.svg" alt="An AI agent attempts to exfiltrate a GitHub PAT through a tool call. The secret-detection layer denies the call before the tool process spawns. One row is written to the audit table." width="820"> </picture><sub>Not a diagram. A live capture: an agent tries to pass a GitHub PAT through a tool argument. Denied in under 5 ms, before the tool process spawns. One audit row. The model never saw the key.</sub>
</div>This repository is the source of demo.systemprompt.io, the hosted demo of systemprompt.io: a governed /v1/messages gateway you sign up for, plus the Systemprompt Bridge desktop app that connects Claude Cowork, Claude Desktop, and Claude Code to it. Built on systemprompt-core, published on crates.io as systemprompt.
From landing page to governed Claude in five steps
The hosted demo lives at demo.systemprompt.io (launching soon). This is the exact flow. No sales call, no credit card, no API key of your own: the $1 credit covers your usage.
- Create your account with a passkey. Touch ID, Windows Hello, or a security key. No password to leak.
- Tell us about yourself. A 30-second form.
- Check your email. $1 of credit is waiting on your account.
- Download the Systemprompt Bridge for macOS (Apple Silicon) or Windows.
- Sign in with a one-time code from your setup page. The Bridge writes the MCP configuration for Claude Cowork, Claude Desktop, and Claude Code. You are done.
From that point, everything Claude does runs through your gateway. Prefer configuring a client by hand? The setup page also issues a personal access token, shown once.
What you get inside Claude
Enable the Bridge and every signed-in user gets the systemprompt MCP server: a documentation hub with four read-only tools (list_topics, get_topic, search_docs, governance_stats) over seven topics — plus fetch_remote_docs, which policy refuses on purpose — and four marketplace skills that show the platform explaining and enforcing itself.
Try these prompts in Claude Cowork or Claude Desktop:
- "What is systemprompt?" The agent lists the topics and reads the answer from the hub.
- "How does governance work here?" It pulls the governance-pipeline topic, then demonstrates a live policy denial.
- Run the
demonstrate_tool_rejectionskill. It reaches for an egress tool the blocklist refuses, and the call is stopped before any connection is made. That refusal is the product working. - Run the
analyse_governance_statsskill. It reads back what the session just cost and how every call was judged.
Why "private" is not a slogan here
Every inference request and every MCP tool call passes a synchronous four-stage pipeline before anything executes: scope check, secret scan (35+ credential patterns), blocklist, rate limit. Allow or deny, the decision lands in an audit row in PostgreSQL, linked from identity to agent to tool to cost.
- Your keys cannot enter the model's context. Credentials are decrypted from an encrypted store and injected into the tool subprocess environment only. The process that owns the LLM context never writes the value, and the secret scan denies any tool call that tries to smuggle one through arguments. The recording above is that denial happening.
- Your usage is a query, not a mystery.
systemprompt infra logs request listshows every gateway request with model, tokens, cost, and latency.systemprompt infra logs audit <id> --fullreconstructs one request end to end. - Your $1 is enforced at the gateway. Cost is metered per request in microdollars. When the credit is gone, the gateway returns a clean 403 instead of a surprise bill.
Claude (Cowork / Desktop / Code)
│
▼
Governance pipeline (in-process, synchronous, <5 ms p99)
│
├─ 1. Identity & scope check
├─ 2. Secret detection (35+ patterns: API keys, PATs, PEM, AWS)
├─ 3. Blocklist (destructive operation categories)
└─ 4. Rate limiting (per session, role multipliers)
│
▼
ALLOW or DENY → audit row, always
│
▼ (ALLOW)
spawn tool process credentials injected here, never in the LLM context
The gateway speaks the Anthropic wire format at POST /v1/messages, so any Anthropic-SDK client works unmodified. Model routing and provider configuration: docs/gateway-routes.md.
Or host the whole funnel yourself
This repository is the source of demo.systemprompt.io. You can run the entire funnel, from splash page to credit exhaustion, on your own machine. One difference from the hosted demo: locally there is no funded gateway behind you, so setup-local asks for your own AI provider key and inference is billed to it. The $1 credit mechanics still work, they just meter spend against your key.
git clone https://github.com/systempromptio/systemprompt-demo
cd systemprompt-demo
just setup-local # prompts for a provider key, starts Docker Postgres
just build # compiles the workspace, runs migrations
just start # gateway + agents + MCP server on :8080
just publish # prerenders the public pages
Open http://localhost:8080 and walk the five steps above against your own binary. The scripted governance and analytics demos live in demo/, and the Bridge source is in bridge/.
setup-local grants no credit, so the gateway refuses inference until a grant exists — that is the exhaustion path, reached from the other side:
INSERT INTO credit_grants (id, user_id, microdollars, reason)
VALUES (gen_random_uuid(), '<user-id>', 1000000, 'local_dev');
You will need Docker, Rust 1.75+, just, and at least one AI provider key. systemprompt --help covers the rest.
License
This template is MIT. Fork it, modify it, use it however you like.
systemprompt-core is BSL-1.1: free for evaluation, testing, and non-production use. Production use requires a commercial license. Each version converts to Apache 2.0 four years after publication. Licensing enquiries: ed@systemprompt.io.
<div align="center">
<sub>Sign up. Spend the $1. Read your own audit trail. Then decide who should operate your AI layer.</sub>
</div>Related Skills
claude-mem
94.7kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
85.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Understand-Anything
84.2kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
73.8kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
