com.balmasai/balmas-mcp
Agents read cleaned copies of your files: PII replaced with local consistent tokens. Read-only.
Links
README
From the repo.
balmas-mcp
Your AI agent reads everything. This gateway hands it redacted copies instead.
Why
AI agents are getting file access — and they over-read. Israel's Privacy Protection Authority put it bluntly in its guidance on AI agents: an email-sorting agent can analyze 15 years of correspondence for a 2-year task, infer your health and finances along the way, and leak what it learned. Their recommendation: strict permission minimization — read-only, dedicated folders, minimum necessary data.
balmas-mcp turns that advice into code, and goes one step further: it minimizes not just which files the agent reads, but what's inside them.
How it works
- You allowlist folders. The agent can't reach anything else — enforced with realpath checks, not honor rules.
- Every read is anonymized locally. Names, ID numbers, phones, emails,
companies and amounts become consistent tokens (
PERSON_001,ID_001) before the content is returned. Secrets too: API keys (OpenAI, Anthropic, GitHub, AWS, Stripe, Slack…), JWTs, private-key blocks,password:values and.envcredentials becomeSECRET_001at every level — and are never written back byrestore_text. The same person isPERSON_001in every file, so the agent's reasoning stays coherent. Detection runs in this process — deterministic patterns, lexicons and checksums (Israeli ID included). Hebrew and English. - The answer comes back real.
restore_textmaps the tokens in the agent's final output back to the original values — locally.
Read-only by design: the server exposes no write tools at all.
Quickstart
- Create a free account at balmasai.com/signup (10 documents/month free).
- Create an API key (
bk_...) at balmasai.com/app/team. - Add to your MCP client config (Claude Desktop shown; Cursor and others are the same idea):
{
"mcpServers": {
"balmas": {
"command": "npx",
"args": ["-y", "balmas-mcp", "/Users/me/Documents/work", "--level", "strict"],
"env": { "BALMAS_API_KEY": "bk_..." }
}
}
}
Options: allowed folders as positional args (required, one or more) ·
--level standard|strict|maximum (default strict).
Tools
| Tool | What the agent gets |
|---|---|
list_files | Names, sizes, types inside allowed folders — never contents |
read_clean_file | The file's text after local anonymization |
restore_text | Real values back into its output (session tokens only) |
Supported inputs: txt csv md docx xlsx pptx pdf (text layer).
Privacy model
| Leaves your machine? | |
|---|---|
| File contents | Never |
| File names / paths | Never |
| The replacement map | Never |
| Metering counters (file type + item counts) | Yes — that's all |
Each file read counts as one document against your account's monthly quota (free 10 / PRO 200 / TEAM 1,000). Full processing happens in this local process.
Honest limits
- The gateway helps only when the agent reads files through it — grant it instead of raw filesystem access, not alongside.
- Detection is deterministic: excellent, not clairvoyant. Review output where the stakes demand it.
- Scanned PDFs (no text layer) need the OCR flow at balmasai.com/clean.
Built by BALMAS AI — sensitive data stops here. Docs: balmasai.com/mcp
Config for your environment
Replace {MCP_ENDPOINT_URL} with this MCP’s endpoint URL (from its repo or docs above). No API key — you connect directly.
Tool
OS
Config file: ~/.cursor/mcp.json
{
"mcpServers": {
"mcp-server": {
"url": "{MCP_ENDPOINT_URL}"
}
}
}Paste into mcpServers in the config file. Restart Cursor after saving.
If this MCP is also published on mcpchannel.ai, you can subscribe from Browse and use the gateway config there instead.