Skip to main content
Glama

GuardianMCP šŸ›”ļø

Your vigilant security companion that automatically guards your projects against vulnerabilities.

GuardianMCP is an MCP (Model Context Protocol) server that scans project dependencies for known security vulnerabilities using the OSV.dev database. Works with Cursor, VS Code, Claude Desktop, and other MCP-compatible IDEs.

Features

  • Automatic vulnerability scanning for npm and Composer dependencies

  • Real-time alerts for CRITICAL and HIGH severity issues

  • Three scan modes: full, summary, critical-high-only

  • Auto-trigger support via IDE rules (on install, commit, build)

  • Multi-language keyword detection (English, Latvian, French, Spanish, German, Russian, etc.)

  • Docker support for containerized deployment

  • Detailed reports with remediation guidance and CVE links

  • Fast & lightweight using OSV.dev API

  • Secure by design - 0 vulnerabilities, minimal dependencies

Related MCP server: Dependency Checker MCP Server

Security Status

npm audit Node.js Dependencies

Latest security audit: All dependencies scanned, 0 vulnerabilities found Node.js: Latest LTS (22.x) with security updates Regular updates: Weekly dependency checks and monthly security reviews

See SECURITY.md for detailed security policy and audit information.

Quick Start

Choose your preferred method:

npm install -g guardian-mcp

Option 2: From Source

git clone https://github.com/Kalvisan/guardian-mcp.git
cd guardian-mcp
npm install
npm run build

Option 3: Docker

docker pull kalmars/guardian-mcp:latest
# or
docker-compose up -d

IDE Setup Instructions

Click on your IDE to see setup instructions:

Cursor Setup

Cursor has native MCP support. Follow these steps:

1. Install GuardianMCP

npm install -g guardian-mcp
# or use local installation (see Quick Start)

2. Configure Cursor

Open Cursor settings:

  • macOS/Linux: ~/.cursor/config.json or Cursor Settings > Features > MCP Servers

  • Windows: %APPDATA%\Cursor\config.json

Add GuardianMCP configuration:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

Or if installed locally:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "node",
      "args": ["/absolute/path/to/guardian-mcp/dist/index.js"]
    }
  }
}

3. Enable Auto-Scanning (Optional)

Create .cursor/rules.md in your project:

# Security Rules

When working in this project:
- Check for CRITICAL/HIGH vulnerabilities on project start
- Scan after npm install or composer update
- Verify no critical issues before git commits

Use check_vulnerabilities tool with scan_mode="critical-high-only".

4. Restart Cursor

Completely restart Cursor to load GuardianMCP.

5. Test It

Open Cursor's AI chat and type:

Check my project for security vulnerabilities

GuardianMCP will automatically scan your dependencies!

VS Code Setup

VS Code can use MCP servers through extensions or configuration.

Method 1: Using Continue.dev Extension

  1. Install Continue.dev extension

  2. Open Continue settings (.continue/config.json)

  3. Add MCP server configuration:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

Method 2: Direct Configuration

  1. Install GuardianMCP: npm install -g guardian-mcp

  2. Add to VS Code settings (.vscode/settings.json):

{
  "mcp.servers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

3. Enable Auto-Scanning

Create .vscode/rules.md:

Automatically check for vulnerabilities when:
- Opening the project
- After running npm install/composer update
- Before creating commits

4. Restart VS Code

Reload window: Cmd/Ctrl + Shift + P → "Reload Window"

Claude Desktop Setup

Claude Desktop has built-in MCP support.

1. Install GuardianMCP

npm install -g guardian-mcp

2. Configure Claude Desktop

Open configuration file:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json

  • Windows: %APPDATA%\Claude\claude_desktop_config.json

  • Linux: ~/.config/Claude/claude_desktop_config.json

Add GuardianMCP:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

Or for local installation:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "node",
      "args": ["/Users/you/path/to/guardian-mcp/dist/index.js"]
    }
  }
}

3. Configure Auto-Scanning

Add to ~/.claude/rules.md (global) or project's .claude/rules.md:

# GuardianMCP Rules

Automatically scan for vulnerabilities when:
1. User mentions: security, vulnerability, CVE, audit
2. After package installations
3. Before git commits

Use scan_mode="critical-high-only" for auto-scans.

4. Restart Claude Desktop

Completely quit and reopen Claude Desktop.

Windsurf Setup

Windsurf supports MCP servers similar to Cursor.

1. Install GuardianMCP

npm install -g guardian-mcp

2. Configure Windsurf

Open Windsurf configuration:

  • Location: ~/.windsurf/config.json

Add MCP server:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

3. Create Project Rules

Add .windsurf/rules.md to your project:

Auto-scan dependencies for vulnerabilities on:
- Project initialization
- npm/composer commands
- Pre-commit checks

4. Restart Windsurf

Reload the editor to activate GuardianMCP.

Zed Setup

Zed is adding MCP support. Check current status:

1. Install GuardianMCP

npm install -g guardian-mcp

2. Configure Zed

Open Zed settings:

  • macOS: ~/.config/zed/settings.json

  • Linux: ~/.config/zed/settings.json

Add configuration:

{
  "assistant": {
    "mcp_servers": {
      "guardian-mcp": {
        "command": "npx",
        "args": ["guardian-mcp"]
      }
    }
  }
}

3. Restart Zed

Reload the editor.

Note: MCP support in Zed may be experimental. Check Zed documentation for latest status.

Docker Setup

Run GuardianMCP in a Docker container and connect from any IDE.

  1. Clone the repository:

git clone https://github.com/Kalvisan/guardian-mcp.git
cd guardian-mcp
  1. Build and run:

docker-compose up -d
  1. Configure your IDE:

In your IDE's MCP configuration, use:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "docker",
      "args": ["exec", "-i", "guardian-mcp", "node", "dist/index.js"]
    }
  }
}

Method 2: Docker Run

  1. Build the image:

docker build -t kalmars/guardian-mcp:latest .
  1. Run the container:

docker run -d --name guardian-mcp \
  -v /path/to/your/projects:/projects:ro \
  kalmars/guardian-mcp:latest
  1. Configure your IDE:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "docker",
      "args": ["exec", "-i", "guardian-mcp", "node", "dist/index.js"]
    }
  }
}

For Cursor with Docker:

Edit ~/.cursor/config.json:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "docker",
      "args": ["exec", "-i", "guardian-mcp", "node", "dist/index.js"]
    }
  }
}

Volume Mounting

To scan projects outside the container:

docker run -d --name guardian-mcp \
  -v /Users/you/projects:/projects:ro \
  -v /Users/you/work:/work:ro \
  guardian-mcp:latest

Then scan with:

Scan /projects/my-app for vulnerabilities

Docker Health Check

docker ps --filter name=guardian-mcp
# Should show "healthy" status

Stopping the Container

docker-compose down
# or
docker stop guardian-mcp && docker rm guardian-mcp

Generic MCP Setup

For any IDE that supports Model Context Protocol:

1. Install GuardianMCP

npm install -g guardian-mcp

2. Find Your IDE's MCP Configuration

Common locations:

  • ~/.config/[IDE_NAME]/config.json

  • ~/.config/[IDE_NAME]/settings.json

  • ~/.[IDE_NAME]/mcp.json

3. Add GuardianMCP

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "npx",
      "args": ["guardian-mcp"]
    }
  }
}

Or with full path:

{
  "mcpServers": {
    "guardian-mcp": {
      "command": "node",
      "args": ["/full/path/to/guardian-mcp/dist/index.js"]
    }
  }
}

4. Verify Setup

Test by asking your IDE's AI assistant:

Use the check_vulnerabilities tool to scan my project

Usage

Once GuardianMCP is installed in your IDE, you can:

Manual Scanning

Simply ask your AI assistant:

Check my project for security vulnerabilities
Scan package.json for critical issues only
Give me a full security audit

Automatic Scanning

Configure rules in your IDE's rules file (.cursor/rules.md, .claude/rules.md, etc.):

# Security Automation

When I mention: security, vulnerability, CVE, audit, or exploit
→ Run check_vulnerabilities with scan_mode="critical-high-only"

After running: npm install, npm update, composer install, composer update
→ Automatically scan for new vulnerabilities

Before creating git commits:
→ Check for CRITICAL vulnerabilities and warn if found

Tool Parameters

GuardianMCP provides the check_vulnerabilities tool with these parameters:

Parameter

Type

Options

Default

Description

project_path

string

any path

current dir

Path to project directory

file_type

string

package.json, composer.json, both

both

Which files to scan

scan_mode

string

full, summary, critical-high-only

full

Output detail level

Examples

Full scan:

Check vulnerabilities with scan_mode="full"

Quick summary:

How many vulnerabilities are in my project? (uses scan_mode="summary")

Auto-scan mode (recommended):

Scan for critical vulnerabilities only (scan_mode="critical-high-only")

Scan Modes Explained

full Mode

Best for: Manual security audits, comprehensive reviews

Shows ALL vulnerabilities with complete details:

  • CRITICAL, HIGH, MODERATE, and LOW severity

  • Detailed descriptions and remediation steps

  • Reference links and CVE IDs

  • Update commands for each package

Example output:

## šŸ”“ express@4.17.1
**Vulnerability ID:** GHSA-rv95-896h-c2vc
**Severity:** CRITICAL

### āš ļø CRITICAL RISK!
**Description:** Express.js accepts requests with malformed URL encoding

**IMMEDIATE ACTION REQUIRED:**
1. Update package: npm update express
2. Verify no vulnerable functionality is used
...

summary Mode

Best for: Quick health checks, CI/CD dashboards

Shows only vulnerability counts:

  • Fast overview

  • No detailed descriptions

  • Total counts by severity

Example output:

## šŸ“Š Summary
- šŸ”“ Critical: 2
- 🟠 High: 5
- 🟔 Moderate: 12
- 🟢 Low: 3

**Total: 22 vulnerabilities**
Run with scan_mode="full" for details.

critical-high-only Mode

Best for: Auto-scans, automated monitoring (RECOMMENDED for rules)

Shows detailed info for CRITICAL/HIGH, counts others:

  • Reduces noise

  • Highlights actionable issues

  • Perfect for automatic scans

  • Hides moderate/low details

Example output:

## šŸ”“ lodash@4.17.20
**Severity:** HIGH
**Issue:** Prototype pollution vulnerability
**Recommendation:** npm update lodash

---

## šŸ“Š Summary
- šŸ”“ Critical: 1
- 🟠 High: 2

_Also found 8 moderate/low issues (hidden)._
_Run with scan_mode="full" to see all._

Severity Levels

Level

Icon

Action

Examples

CRITICAL

šŸ”“

Update IMMEDIATELY

RCE, Auth bypass, Privilege escalation

HIGH

🟠

Update ASAP

SQL injection, XSS, CSRF

MODERATE

🟔

Plan update

DoS, Information disclosure

LOW

🟢

Consider updating

Deprecated packages, Minor issues

Example Rules Files

See examples/ for ready-to-use templates:

  • claude-rules.md - Comprehensive template with all scenarios

  • project-rules.md - Project-specific configuration example

  • global-rules.md - User-wide configuration for all projects

Copy these to:

  • Cursor: .cursor/rules.md

  • Claude Desktop: .claude/rules.md

  • VS Code: .vscode/rules.md (with Continue.dev)

Supported Ecosystems

Ecosystem

File

Status

npm (Node.js)

package.json

āœ… Supported

Composer (PHP)

composer.json

āœ… Supported

PyPI (Python)

requirements.txt

šŸ”„ Planned

Go Modules

go.mod

šŸ”„ Planned

Maven (Java)

pom.xml

šŸ”„ Planned

NuGet (.NET)

*.csproj

šŸ”„ Planned

RubyGems

Gemfile

šŸ”„ Planned

Cargo (Rust)

Cargo.toml

šŸ”„ Planned

Troubleshooting

  1. Verify installation:

    npx guardian-mcp --version
    # or
    which guardian-mcp
  2. Check config file path is absolute:

    • āŒ "args": ["dist/index.js"]

    • āœ… "args": ["/Users/you/guardian-mcp/dist/index.js"]

  3. Restart IDE completely (don't just reload window)

  4. Check IDE logs:

    • Cursor: Open DevTools (Help > Toggle Developer Tools)

    • VS Code: Output panel > Extension Host

    • Claude Desktop: View > Developer > Toggle Developer Tools

  5. Test manually:

    node /path/to/guardian-mcp/dist/index.js
    # Should not crash
  1. Verify rules file exists:

    cat .cursor/rules.md
    # or
    cat .claude/rules.md
  2. Check rules mention tool name:

    • Must reference check_vulnerabilities

    • Use scan_mode="critical-high-only" for auto-scans

  3. Test with keywords:

    • Try saying "security" or "vulnerability"

    • Should trigger automatic scan

  4. Check IDE supports rules:

    • Cursor: āœ… Built-in support

    • Claude Desktop: āœ… Built-in support

    • VS Code: Depends on extension

  1. Check logs:

    docker logs guardian-mcp
  2. Verify build succeeded:

    docker build -t kalmars/guardian-mcp:latest .
  3. Test manually:

    docker run -it kalmars/guardian-mcp:latest
  4. Check health:

    docker ps --filter name=guardian-mcp
    # Status should be "healthy"
  1. Check internet connection

  2. Verify API is accessible:

    curl https://api.osv.dev/v1/query
  3. Rate limiting: OSV.dev has rate limits

    • Wait a few minutes

    • Reduce scan frequency

  4. Firewall: Ensure outbound HTTPS is allowed

Contributing

Contributions are welcome! Areas for improvement:

  • Additional ecosystem support (Python, Go, Rust, etc.)

  • Better version range parsing

  • Caching to reduce API calls

  • IDE-specific optimizations

  • Test coverage

  • Documentation improvements

License

MIT - See LICENSE file

Resources

Security Note

GuardianMCP helps identify known vulnerabilities but is not a substitute for:

  • Comprehensive security audits

  • Penetration testing

  • Secure coding practices

  • Regular dependency updates

  • Security training

Always review and test dependency updates before deploying to production.


Available Tools

1 tool
check_vulnerabilitiesA

Scans project dependencies (package.json, composer.json) for known security vulnerabilities using the OSV.dev database. Supports multiple scan modes: 'full' for detailed reports, 'summary' for quick overview, 'critical-high-only' for auto-scans showing only actionable issues. Use this tool when: user asks about security/vulnerabilities, after package installations (npm install, composer update), before commits/builds, or when starting work in a new project with dependency files.

ParametersJSON Schema
NameRequiredDescriptionDefault
project_pathNoPath to project directory (default: current directory)
file_typeNoWhich file(s) to check (default: both)
scan_modeNoOutput detail level: 'full' shows all vulnerabilities with details, 'summary' shows only counts, 'critical-high-only' shows detailed info for CRITICAL/HIGH only (default: full)

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes the tool's behavior by explaining the different scan modes ('full', 'summary', 'critical-high-only') and their outputs, and mentions it uses the OSV.dev database. However, it lacks details on potential side effects, error handling, or performance characteristics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured and front-loaded with the core purpose, followed by usage guidelines. It is appropriately sized, but could be slightly more concise by integrating the usage scenarios more tightly with the initial explanation.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (3 parameters, no output schema, no annotations), the description does a good job covering purpose, usage, and behavior. However, it lacks information on output format or error handling, which would be helpful for an AI agent to understand what to expect from the tool's execution.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema description coverage is 100%, so the schema already documents all parameters thoroughly. The description adds some context by mentioning 'project dependencies' and 'multiple scan modes', but does not provide additional semantic details beyond what the schema specifies. This meets the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose with specific verbs ('scans project dependencies') and resources ('package.json, composer.json'), and distinguishes its function by mentioning the OSV.dev database. It explicitly lists what it does without being tautological or vague.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit guidance on when to use the tool, listing specific scenarios such as 'user asks about security/vulnerabilities', 'after package installations', 'before commits/builds', and 'when starting work in a new project with dependency files'. This gives clear context for usage without alternatives needed since no sibling tools exist.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A4.1/5.0
Disambiguation5/5

With only one tool, there is no possibility of ambiguity or overlap between tools. The single tool 'check_vulnerabilities' has a clear, distinct purpose focused on security vulnerability scanning.

Naming Consistency5/5

The tool name 'check_vulnerabilities' follows a consistent verb_noun pattern, and since there is only one tool, there is no inconsistency to evaluate. The naming is clear and appropriate for its function.

Tool Count2/5

A single tool for a security vulnerability scanning server is too limited in scope. While the tool is well-described, a server with only one tool often feels thin and lacks the breadth needed for comprehensive security operations, such as managing scans, updating databases, or handling different file types beyond the mentioned ones.

Completeness2/5

The tool surface is severely incomplete for a security vulnerability domain. It only covers scanning for vulnerabilities in specific dependency files, missing essential operations like configuring scan settings, retrieving historical scan results, updating vulnerability databases, or integrating with other security tools. This creates significant gaps that could lead to agent failures in broader security workflows.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    C
    maintenance
    Enables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.
    3
    22
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables users to scan software packages for data exfiltration and security threats directly within their IDE across npm, PyPI, Cargo, and Maven ecosystems. This tool helps ensure the safety of project dependencies by identifying potential risks before they are integrated.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Visual CVE audit dashboard for npm, Python, Go, and Rust projects. Scans your project manifests (package-lock.json, requirements.txt, go.sum, Cargo.lock) against OSV.dev live data, opens a browser dashboard for human review, then applies fixes only after explicit confirmation. Supports multi-service monorepos in one command.
    4
    12
    4
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Kalvisan/guardian-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server