Skip to main content
Glama
9hannahnine-jpg

arc-gate-mcp

README.md
[![arc-gate-mcp MCP server](https://glama.ai/mcp/servers/9hannahnine-jpg/arc-gate-mcp/badges/card.svg)](https://glama.ai/mcp/servers/9hannahnine-jpg/arc-gate-mcp)

[![arc-gate-mcp MCP server](https://glama.ai/mcp/servers/9hannahnine-jpg/arc-gate-mcp/badges/score.svg)](https://glama.ai/mcp/servers/9hannahnine-jpg/arc-gate-mcp)

# arc-gate-mcp

Runtime governance proxy for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

## What it does

arc-gate-mcp sits between your MCP client and any MCP server. Every tool result passes through Arc Gate governance before reaching your agent — blocking prompt injection attacks that exploit the MCP trust boundary.

## Installation

```bash
pip install arc-gate-mcp
```

## Usage

```bash
arc-gate-mcp --upstream "uvx mcp-server-fetch" --policy balanced
```

### With Claude Desktop

```json
{
  "mcpServers": {
    "arc-gate": {
      "command": "uvx",
      "args": ["arc-gate-mcp", "--upstream", "uvx mcp-server-fetch", "--policy", "browser_agent"]
    }
  }
}
```

## Policy modes

- `balanced` — general purpose
- `browser_agent` — web browsing agents
- `finance_agent` — financial data agents
- `rag_assistant` — document retrieval agents
- `strict` — maximum enforcement

## Links

- [Bendex Arc Platform](https://bendexgeometry.com)
- [PyPI](https://pypi.org/project/arc-gate-mcp/)

## License

AGPL-3.0

## Used with Heym

arc-gate-mcp is available as a template on [Heym](https://heym.run) — an enterprise agent platform. Try the [Governed Web Research Agent](https://heym.run/templates/governed-web-research-agent-mcp) template to see Arc Gate MCP in action.

TDQS

A4.3/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no possibility of ambiguity.

Naming Consistency5/5

The single tool is named 'fetch', following a clear verb-based naming convention.

Tool Count5/5

One tool is entirely appropriate for a server designed as a secure proxy for the fetch operation.

Completeness5/5

The server fully covers its stated purpose of fetching URLs with security inspection; no additional tools are needed.

Maintenance

ActivityInactive
ResponsivenessNo issues