
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
aggrete
Advanced tools
An MCP proxy that enforces your code of conduct across connectors. Permission is not need-to-know.
An MCP proxy that enforces a code-of-conduct document across connectors, with per-user memory that accumulates across calls.
Four individually-authorized questions can assemble a layoff list — no single one is sensitive, so no guardrail fires. Aggrete is the layer that catches the combination: is this call, together with everything this person already pulled today, something the code of conduct forbids?
Try it live — nothing to install · or uvx aggrete --demo
pip install aggrete # or: uv tool install aggrete
uvx aggrete --demo # the walkthrough — no config, auth, or network
aggrete --config proxy.config.yaml # run it for real
The check tool dry-runs a plan and returns the verdict before anything is fetched:
Plan check: REFUSED.
1. hr__recent_joiners [hr-personnel] -> allowed
2. finance__budget_roles [finance-comp] -> allowed
3. ops__oncall_draft [ops-rota] -> REFUSED COC-HR-004
Personnel, compensation, and operational rosters may not be combined to
derive the planned departure of identifiable individuals.
Each call is fine alone. The third completes a forbidden set across three domains that overlap on the same people, so it's denied before the upstream call — the data is never fetched.
aggrete-audit), forwarded to a SIEM or an OpenTelemetry collector, with Prometheus metrics and health endpoints for operations.check previews any sequence, scenarios lists things to try.action: approve pauses a call until the clause owner approves it, from Slack, the terminal, or the console; the approval is a time-limited, audited grant.coc.yaml schema, rule types, arg_match, and drafting from your handbook with aggrete-ingestaggrete extmcp), Docker MCP Gateway, IBM ContextForge or any AuthZEN-speaking gatewayaggrete conformance runs sixteen checks against the real components and maps them onto the OWASP MCP Top 10, OWASP Agentic Top 10, CoSAI and AIUC-1; --url runs the same scenarios black-box against any gateway (latest report)/plugin marketplace add aggrete/aggrete, or read skill://aggrete/SKILL.md from a running proxymcp-name: io.github.aggrete/aggrete
FAQs
An MCP proxy that enforces your code of conduct across connectors. Permission is not need-to-know.
The pypi package aggrete receives a total of 615 weekly downloads. As such, aggrete popularity was classified as not popular.
We found that aggrete demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.