agent-guard-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_packageA | Check whether a single package exists and assess slopsquat/typosquat risk BEFORE installing it. Returns OK/SUSPICIOUS/DANGER + risk + flags. Nonexistent names are likely hallucinated; names 1-2 chars from a popular package are likely typosquats. |
| verify_lockfileB | Scan an entire lockfile (direct + transitive deps) for hallucinated / typosquatted / suspicious packages BEFORE running install. Call this instead of trusting an LLM-generated lockfile. |
| score_manifestA | Score a Cursor/Claude skill or MCP/Smithery plugin manifest for poison/backdoor signatures, credential scope over-reach, and drift BEFORE installing a third-party agent extension. Returns risk 0-100 + install recommendation (PROCEED/REVIEW/BLOCK). |
| check_workflowA | Validate a CI workflow (GitHub Actions / GitLab CI YAML) BEFORE merging a PR that touches it. Flags mutable action pins, known-compromised actions, untrusted owners, curl|bash fetch-exec, pull_request_target pwn-requests, and secret exposure. Returns risk 0-100 + merge recommendation (PROCEED/REVIEW/BLOCK). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool targets a distinct security artifact (package, workflow, manifest, lockfile) with no overlap in purpose. An agent can clearly distinguish which tool to call for each verification task.
Tool names follow a verb_noun pattern: 'check_package', 'check_workflow', 'score_manifest', 'verify_lockfile'. While 'check' is used twice, 'score' and 'verify' are different but still descriptive, maintaining a clear and predictable structure.
With 4 tools, the set is concise and focused on common pre-installation and pre-merge security checks. Each tool addresses a specific need without unnecessary bloat, making the surface easy to navigate.
The tool set covers major security vetting areas: package typosquatting, CI workflow integrity, manifest backdoor analysis, and lockfile scanning. Minor gaps like environment or dependency drift checks exist, but the core use cases are well-addressed.