Bernstein runs on your own machine — the client starts it, so there is no endpoint to ping. 17 626 installs a week from pypi. Last commit 17 Sep 2026.
The open-source governance layer for AI agents. Byte-identical run receipts, 40+ adapters, air-gap.
We read the source, 23 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
"chmod 777",
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
detail_hint="/.dockerenv present",
return execSync(`command -v ${cmd}`, { encoding: "utf8", stdio: ["pipe", "pipe", "ignore"] }).trim();
proc = subprocess.Popen(
raw = pickle.loads(path.read_bytes())
def exec(
shell=True, # nosemgrep: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
wt_count = sum(1 for _ in wt_dir.iterdir() if _.is_dir())
r"(?i)(?:ngrok\.io|\.ngrok\.io|burpcollaborator\.net|requestbin\.com|webhook\.site|pipedream\.net)"
r">\s*~/\.ssh/",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Bernstein and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add bernstein -- uvx bernstein
{
"mcpServers": {
"bernstein": {
"args": [
"bernstein"
],
"command": "uvx"
}
}
}
[mcp_servers.bernstein]
command = "uvx"
args = ["bernstein"]
{
"mcpServers": {
"bernstein": {
"args": [
"bernstein"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"bernstein": {
"args": [
"bernstein"
],
"command": "uvx"
}
}
}
The open-source review layer for AI agents. Work done for humans is decided by humans.
Governance layer for agentic AI — signed, verifiable receipts for every agent action.
A local intelligence layer for AI coding agents. Maps your repos, matches the open-source frontier.
Runtime governance enforcement for AI agents. Zero token overhead.
Heartwood Memory — governed AI agent memory; signed provenance. BUSL-1.1; not OSI open source.
Mint tamper-evident receipts for AI agent actions. The notary layer for agent-to-agent transactions.
The open-source talent graph for humans and AI agents. Find developers.
The open retrieval layer for AI agents — index code, docs, data. Search via MCP.
Answers built from our own checks of this server.