Skip to main content

Trentina

Trentina is a secure MCP gateway that inspects everything between your AI agents and the outside world — web content, MCP tool responses and tool definitions, Matrix messages, LLM completions, and monitoring alerts — through a three-layer defense pipeline at every ingress, with per-profile enforcement (annotate, extract, or block) and a full audit trail. Content is never silently modified: what your agent reads is what actually arrived, plus Trentina's verdict. (E2EE Matrix rooms are ciphertext at the gateway and outside what any proxy can defend.) Named after the 1377 quarantine system from Ragusa, where incoming ships had to anchor offshore for thirty days before anyone was allowed into the city. Same idea: keep the commerce flowing without letting something dangerous through.

Capabilities

MCP Gateway

Single chokepoint between your agents and all their MCP backends. One endpoint, one bearer token, one audit log — instead of each agent connecting directly to dozens of MCP servers. Backend tools are namespaced automatically (slack__slack_search_messages, github__list_issues_tool) so there are no collisions.

Per-Agent Profiles

Each consumer — Claude Code, Hermes, OpenClaw, or any MCP client — gets its own profile with independent tool access, defense settings, and authentication. Your human-supervised agent can have full tool access while your autonomous agent gets a locked-down subset, all through the same gateway.

Tool Allowlists & Denylists

Control which tools each agent can even see. Tools not in the allowlist are stripped from tools/list responses before they reach the consumer — they never enter the agent's context window. Supports exact names and glob patterns (delete*, *_gmail_*). Reduces both context cost and attack surface.

Parameter Guards

Per-tool argument validation at the gateway level. Restrict what values an agent can pass, not just which tools it can call. Example: "this agent can send email, but only to user@example.com." The call is rejected before it reaches the backend — no tokens spent, no side effects. Deterministic enforcement that doesn't depend on LLM behavior.

Three-Layer Defense Pipeline

Every piece of untrusted content passes through three independent detection layers. Layer 1 strips structural attacks (hidden HTML, invisible Unicode, encoded payloads, exfiltration URLs). Layer 2 runs a Prompt Guard 2 86M classifier to catch instruction overrides. Layer 3 hands sanitized content to a quarantined LLM (Gemini Flash Lite) for semantic analysis — no tools, no memory, minimal blast radius. Each layer catches what the others miss.

Tool Description Compression

MCP servers ship verbose tool descriptions that waste context tokens. Trentina uses an LLM to compress every tool description as it passes through the gateway, caching results in SQLite so the model is only called once per unique description. Real-world results: 154 tools compressed from 62K to 17K characters (72% reduction), saving ~11K tokens per session. The compressed descriptions are fully functional — agents use them without issue.

Gateway Audit Log

Every tool call through the gateway is recorded in SQLite with profile, backend, tool name, success/failure, duration, and error message. The quarantine_stats tool exposes this data for monitoring — tool call counts, error rates, per-backend breakdowns. Data-driven evidence for tightening allowlists and identifying problems.

Cumulative Detection Memory

When Trentina detects prompt injection in a source, it records the source in a SQLite blocklist. Future requests for that source trigger an immediate warning — the system remembers what it's seen before. Blocklist entries include the source URL or content hash, detection timestamp, and risk level.

Web Content Quarantine Tools

Trentina's original capability: safe web fetching, file reading, and web search with prompt injection defense. safe_fetch fails on injection. quarantine_fetch warns but proceeds, extracting content through the Q-Agent. quarantine_search chains Gemini grounding with the full defense pipeline. quarantine_scan does pre-flight detection without returning content.

LLM Key Proxying

Proxy LLM API calls (Gemini, OpenAI, Anthropic) through the gateway so API keys never leave the trusted boundary. Agents send model requests to Trentina, which forwards them with the real credentials. Adding a new provider is a YAML entry, not code. Streaming and non-streaming responses are forwarded transparently.

Matrix Reverse Proxy

Proxy Matrix Client-Server API traffic through the gateway so agents on the internal network can communicate via Matrix without direct internet access. Agents point MATRIX_HOMESERVER at Trentina instead of matrix.org. Long-poll /sync timeouts are tuned automatically.

Cockpit Plugin

Live web dashboard for the defense pipeline, built as a Cockpit plugin with PatternFly 6. Shows layer status, blocklist entries, and pipeline events in real time through the same web console sysadmins already use to manage RHEL systems. Vanilla JavaScript, no React, no build step.

Quick Start

# PyPI
pip install mcp-trentina-crunchtools

# uvx (zero-install)
uvx mcp-trentina-crunchtools

# Container (includes Prompt Guard 2 86M classifier)
podman run quay.io/crunchtools/mcp-trentina

Minimal Configuration

# Required for Layer 3 (Q-Agent) and description compression
export GEMINI_API_KEY=your-key

# Enable gateway mode
export TRENTINA_GATEWAY_ENABLED=true
export TRENTINA_PROFILES_PATH=/path/to/profiles.yaml

# Per-profile bearer tokens
export TRENTINA_PROFILE_MYAGENT_TOKEN=your-token

Claude Code

{
  "mcpServers": {
    "trentina": {
      "type": "streamable-http",
      "url": "http://localhost:8019/gateway/myprofile/mcp",
      "headers": {
        "Authorization": "Bearer your-token"
      }
    }
  }
}

Documentation

Document Description
MCP Gateway Architecture, routing, namespacing
Per-Agent Profiles Authentication, profile schema, multi-agent setup
Tool Filtering Allowlists, denylists, glob patterns
Parameter Guards Per-tool argument validation
Defense Pipeline L1/L2/L3 layers, coverage matrix
Description Compression LLM-powered context reduction
Audit Log Call recording, stats, monitoring
Blocklist Cumulative detection memory
Quarantine Tools Web fetch, read, search, scan
LLM Key Proxying API key isolation via reverse proxy
Matrix Reverse Proxy Agent communication via Matrix
Cockpit Plugin Live defense pipeline dashboard
Internal: Gateway Design Original design document for contributors

Environment Variables

Trentina reads its gateway, profile and backend configuration from a YAML file; these variables control the process itself. Profile tokens (TRENTINA_PROFILE_<NAME>_TOKEN) and provider API keys are covered in Per-Agent Profiles and LLM Key Proxying.

Variable Default Description
TRENTINA_LOG_LEVEL INFO Application log level, sent to stderr. Any standard Python level name.
TRENTINA_GATEWAY_ENABLED unset (disabled) Turns on the MCP gateway (profiles, auth, allowlists, audit). See MCP Gateway.
TRENTINA_PROFILES_PATH /etc/trentina/profiles.yaml Path to the gateway's profile YAML file. See Per-Agent Profiles.
TRENTINA_LEGACY_MCP unset (disabled) Restores the pre-gateway unguarded /mcp endpoint. Bypasses auth, allowlists and audit — migration aid only. See MCP Gateway.
TRENTINA_MODEL_PROVIDER gemini Global LLM provider for L3 Q-Agent and tool-description compression, overridable per-profile. See Per-Agent Profiles.
TRENTINA_PROVIDER_FALLBACK unset (none) Comma-separated provider names to fall back to if TRENTINA_MODEL_PROVIDER is unavailable.
OLLAMA_BASE_URL http://localhost:11434 Base URL for the Ollama provider.
OLLAMA_MODEL qwen2.5:0.5b Model used when the Ollama provider is selected. See LLM Key Proxying.
QUARANTINE_MODEL gemini-2.5-flash-lite Model used for quarantine agent (L3) extraction/detection calls.
QUARANTINE_SEARCH_MODEL gemini-2.5-flash Model used for grounded L0 search.
QUARANTINE_FALLBACK layer1 Behavior when the LLM provider is unavailable during quarantine processing.
QUARANTINE_MAX_CONTENT 100000 Max characters of content sent to the quarantine LLM per call. See Token Routing.
CLASSIFIER_THRESHOLD 0.5 Malicious-score threshold above which the L2 classifier flags content.
CLASSIFIER_MODEL_PATH /models/prompt-guard-2-86m Filesystem path to the ONNX classifier model. Set to /models/prompt-guard-2-86m by the container image.
CLASSIFIER_MAX_TOKENS 32768 Max tokens the L2 classifier will scan before truncating.
CLASSIFIER_THREADS 4 ONNX Runtime intra-op thread count for the L2 classifier.
QUARANTINE_DB ~/.local/share/mcp-trentina/trentina.db (container: /data/quarantine.db) Path to the main SQLite database (blocklist, audit log). See Audit Log and Blocklist.
TRENTINA_PERIMETER_DB <QUARANTINE_DB's directory>/perimeter.db Path to the perimeter verdict-cache database, deliberately separate from QUARANTINE_DB.
QUARANTINE_TRUST_CONFIG ~/.config/mcp-env/mcp-trentina-trust.json Path to the trust-level configuration JSON. See Quarantine Tools.

Development

uv sync --all-extras
uv run ruff check src tests
uv run mypy src
uv run pytest -v

The container image is built by the GHA pipeline (container.yml), never locally. The model-export stage needs a gated HuggingFace credential that only CI holds, and building outside the pipeline causes drift. Push the branch and let the pipeline verify the image.

License

AGPL-3.0-or-later

Release files for mcp-trentina-crunchtools 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mcp-trentina-crunchtools 0.8.0
File Size Uploaded
mcp_trentina_crunchtools-0.8.0.tar.gz 621.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mcp-trentina-crunchtools 0.8.0
File Interpreter ABI Platform
mcp_trentina_crunchtools-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 838.6 kB

Release files / mcp_trentina_crunchtools-0.8.0.tar.gz

Download URL mcp_trentina_crunchtools-0.8.0.tar.gz
Size 621.9 kB
Tags Source
SHA-256 checksum
How to use checksums
ad791c06c94e0c22e2cc246cee707b0e90340e7d9b62ce2c5742966c228b9502
BLAKE2b-256 checksum
How to use checksums
5550c886ba870ead8b54b039a357fc376f95f08e1c3f53ff4ee57d9f622ce891
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / mcp_trentina_crunchtools-0.8.0-py3-none-any.whl

Download URL mcp_trentina_crunchtools-0.8.0-py3-none-any.whl
Size 216.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
88abcf124bb877bbe7088352a1d02ee9271ac06eda262fd2ee8a3f1b5f2de32e
BLAKE2b-256 checksum
How to use checksums
7909640e837fc9950a06e7516795e2d1ddfa54f8a882bc3c97cfcc644653b559
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

0.35.0

2 release files

0.20.1

2 release files

0.19.1

2 release files

0.19.0

2 release files

0.12.0

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.3

2 release files

0.8.2

2 release files

0.8.1

2 release files

This release

0.8.0 This release

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page