mcp-safeguard
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_SHIELD_API_KEY | No | API key for authenticating requests to the mcp-safeguard server | |
| MCP_SHIELD_OTLP_ENDPOINT | No | OpenTelemetry endpoint for traces, e.g., 'http://jaeger:4317' | |
| MCP_SHIELD_SSRF_ALLOWLIST | No | JSON array of allowed hosts for SSRF protection, e.g., '["localhost","127.0.0.1"]' | |
| MCP_SHIELD_RATE_LIMIT_WINDOW | No | Rate limit window duration in seconds (default 60) | |
| MCP_SHIELD_PROMETHEUS_ENABLED | No | Set to 'true' to expose Prometheus metrics at /metrics | |
| MCP_SHIELD_RATE_LIMIT_REQUESTS | No | Maximum number of requests per window (default 100) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_mcp_serverA | Run a full security scan of an MCP server. Performs prompt injection detection, credential scanning, endpoint probing, tool poisoning analysis, and blast radius scoring. |
| scan_tool_definitionsA | Analyze MCP tool definitions JSON for prompt injection and poisoning risks. Accepts either a JSON array of tool objects or a single tool object. |
| check_auth_configB | Audit an MCP server configuration for credential exposure and OAuth scope risks. |
| check_endpoint_exposureA | Probe an MCP server for exposed admin panels, debug routes, and dangerous ports. Only scans localhost and explicitly allowlisted hosts (SSRF protection). |
| generate_security_reportB | Retrieve a full security report for a completed scan. |
| get_scan_historyA | List all past scans with their severity scores and targets. Returns: Dict with a list of scan summaries, sorted by recency. |
| compare_scansA | Compare two security scans to identify regressions or improvements. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| security_audit_prompt | Guided prompt for performing a full MCP security audit. |
| remediation_prompt | Step-by-step fix guide for a specific vulnerability type. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| get_rules_resource | All active detection rules across all scanner modules. |
| get_dashboard_resource | Aggregate statistics across all scans. |
TDQS
Scored across 7 tools
Tools are largely distinct: full scan vs. targeted sub-scans (tool definitions, auth, endpoint) have clear boundaries. However, scan_mcp_server subsumes the focus of the other scan/check tools, which could cause an agent to pick the broader tool when a targeted one is needed. Descriptions mitigate this, but there is mild overlap in intent.
All tool names follow a consistent snake_case verb_noun pattern (scan_, check_, generate_, get_, compare_). The verbs and nouns are descriptive and predictable, making the set easy to navigate.
Seven tools is well-scoped for a security scanning server. The full scan, three targeted checks, report retrieval, history listing, and comparison cover the core workflow without bloat or unnecessary duplication.
The tool surface covers the scan–report–history–compare lifecycle effectively. Missing operations like pause/stop or delete are non-critical for this domain, and no obvious dead ends prevent common security auditing workflows. A small gap is the lack of a dedicated 'get single scan detail' besides the report, but history and report retrieval suffice.