Runtime Security • Model Context Protocol (MCP)

Isolated Tool Runtime for Autonomous Agents

Magumi intercepts raw agent tool calls between Claude and host systems, executing commands inside disposable micro-sandboxes with automated diff verification and zero host credential leakage.

Runtime Topology Protocol: MCP 1.0 Compliant
Tier 1: Planning
Claude Opus 5.5

Adaptive Thinking engine ingests repository graphs via 1M context to formulate validated tool execution plans.

Tier 2: Proxy
Magumi Daemon

Intercepts JSON-RPC tool requests, audits argument safety, and maintains prompt cache alignments.

Tier 3: Execution
Micro-Sandbox

Isolated ephemeral containers execute file changes, builds, and commands without host disk mutations.

Tier 4: Verification
Diff Gate

Generates cryptographic unified diffs and executes test assertions before committing changes to git.

Engineered for Production Agent Safety

Deterministic boundaries for long-horizon autonomous coding and tool orchestration.

01

Zero-Leakage MCP Proxy

Acts as a security barrier between Claude and host MCP servers. Environment tokens, private SSH keys, and restricted directories are masked from subagent inspection.

02

Ephemeral Tool Sandboxes

Subagent tool commands run inside isolated micro-containers with strict CPU, memory, and timeout caps, preventing runaway terminal loops and destructive file operations.

03

Prompt Cache Optimization

Maintains structured tool definition blocks to guarantee continuous 90 percent cache hit rates across Claude 5.5 model families, eliminating redundant inference costs.

04

Parallel Subagent Fan-Out

Dispatches concurrent validation tasks to Claude Haiku 5.5 for high-frequency linting and syntax passes, feeding errors back to the lead worker for automatic repair.

05

Cryptographic Diff Validation

All file writes and code changes are isolated as unified diffs. The runtime rejects unverified commits until test suites pass assertion thresholds.

06

Local-First Architecture

Runs on developer hardware or private cloud nodes. No telemetry, no third-party relay servers, and zero external codebase exposure.

magumi-daemon: mcp-session.log
$ magumi daemon start --config ./magumi.json
[2026-10-09 15:42:01] Starting Magumi runtime v0.4.1 (protocol: MCP v1.0)...
[2026-10-09 15:42:01] Connected upstream: claude-opus-5-5 (adaptive thinking: enabled)
[2026-10-09 15:42:02] Prompt cache verified: 48,220 tokens cached (read multiplier: 0.10x)
[2026-10-09 15:42:04] Intercepted tool call: fs_write_file ("./src/auth/session.go")
[2026-10-09 15:42:04] Routing execution to ephemeral sandbox (id: box_91a0c8)...
[2026-10-09 15:42:05] Running test assertion gate: go test ./src/auth/...
[2026-10-09 15:42:06] Test suite passed (4 tests, 0 failures)
[2026-10-09 15:42:06] Host diff verified. Applied 1 file change cleanly to working tree.

Runtime Specifications

Verified compatibility across the Claude 5.5 model family and MCP servers.

Specification Details
Supported Models Claude Opus 5.5 (Planning), Claude Sonnet 5.5 (Execution), Claude Haiku 5.5 (Verification)
Protocol Standard Model Context Protocol (MCP) JSON-RPC 2.0 (Linux Foundation / Agentic AI Foundation)
Context Management Native 5-minute Ephemeral Prompt Caching on 1M Context Windows
Sandbox Isolation Rootless micro-containers with memory bounds and network outbound filtering
Distribution Private CLI Binary (Early Alpha: Token Access Only)

Private Alpha Access

Magumi is currently deployed in closed alpha with select engineering teams. Request an evaluation token or submit inquiries to the core team.

contact@magumi.download