Skip to main content
Glama

๐Ÿ›ก๏ธ SecureMCP

Local English/Korean Masking ยท Subscription Gateway ยท Trusted Restoration

์˜์–ดยทํ•œ๊ตญ์–ดยท์ฝ”๋“œ๋ฅผ ๋กœ์ปฌ์—์„œ ๋งˆ์Šคํ‚นํ•˜๊ณ , ๋„๊ตฌ ์‹คํ–‰๊ณผ ์‚ฌ์šฉ์ž ํ™”๋ฉด์—์„œ ์›๋ฌธ์„ ๋ณต์›ํ•˜๋Š” ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ ๋„๊ตฌ

Version Python Platforms CI MCP License


English ยท ํ•œ๊ตญ์–ด ์•ˆ๋‚ด ยท Supported Versions ยท Quick Start ยท Features ยท Architecture ยท Documentation


English Overview

SecureMCP masks English/Korean text and code locally, with session-based restoration.

Version 0.5 adds an experimental local subscription gateway for Claude Code and Codex. Run secure-mcp gateway install once, then use claude / codex normally. Requests are masked automatically; responses and local tool arguments are restored automatically. Existing CLI subscription OAuth is forwarded to the original subscription service; API keys are refused. No agent hooks are installed. See subscription gateway for setup, automatic startup, tested versions and the exact protection boundary.

Legacy agent hooks remain optional utilities. They cover selected tool text rather than complete requests; local integration documents their limits.

Mask confidential input before sending it to a provider. Restore responses in your trusted local application and show them to the user there. Model-invoked MCP tool arguments are already visible to the provider; adding this server to Claude Desktop or Cursor does not automatically intercept or protect prompts. Restored originals must not be sent back into the model context. This is heuristic masking, not a proof of anonymity, cryptographic zero knowledge, or regulatory compliance.


Related MCP server: ai-security-gateway-mcp

Supported Versions

Component

Supported versions / scope

SecureMCP

0.5.0

Python

3.10 ยท 3.11 ยท 3.12 ยท 3.13 ยท 3.14 in CI; package requires Python โ‰ฅ 3.10

Operating systems

Windows ยท macOS ยท Linux in CI

Claude Code gateway

2.1.287 native fixtures verified; live subscription HTTP 200 verified, model refusal remains

Codex gateway

CLI 0.160.0 native fixture tests and a live ChatGPT subscription request with automatic restoration verified

MCP transport

Local stdio; CLI HTTP/SSE transports are disabled

Natural languages

English ยท ํ•œ๊ตญ์–ด ยท mixed input

Code languages

Python ยท JavaScript ยท TypeScript ยท Go ยท Rust ยท Java ยท C ยท C++ ยท SQL

The CI matrix covers 15 Python/OS combinations. Code-language support describes lexer modes, not compatibility with every language release or compiler. The gateway is experimental. Native fixture tests verify routing/masking/restoration. Codex passed a live subscription smoke test. Claude's attribution masking bug is fixed; live requests now return HTTP 200, but a Sonnet safety-filter refusal prevents successful answer/restoration verification. The earlier 429 was not subscription exhaustion. This does not certify all-traffic privacy.


Quick Start

Automatic subscription integration

uv tool install .
secure-mcp gateway install
secure-mcp gateway status

Restart Claude Code/Codex and use their normal commands. Setup preserves login caches and registers a hidden user-login startup task. It changes user-wide provider settings; no agent hooks are added. Subscription limits still apply. This is text/code inference protection; images, remote attachments and unsupported payloads are blocked. See gateway guide.

Legacy optional agent hooks

uv tool install .
secure-mcp init --agent claude
secure-mcp doctor

Restart Claude Code after installation. Hooks default to the current project; use --global for user-wide registration. See local integration for supported tool fields, installation/removal and limitations.

For Codex:

secure-mcp init --agent codex
secure-mcp doctor --agent codex

Restart Codex and review/trust the installed definitions in /hooks. Project hooks require a trusted project. Codex masks tool results and restores Bash/apply_patch inputs; automatic screen restoration is unavailable. Use secure-mcp restore --agent codex --session-id <id> with masked text on UTF-8 stdin for local display. See Codex integration.

Development installation and demo

uv venv
uv pip install -e ".[dev]"
uv run python -m secure_mcp demo

Trusted local Python API

from secure_mcp import LocalPrivacyClient

# Replace echo with your provider adapter. Only its argument may leave the host.
def provider(masked_payload: str) -> str:
    return masked_payload

with LocalPrivacyClient() as client:
    result = client.request(
        "Patient John Doe received 50mg.", provider,
        sensitive_terms={"John Doe"},
    )
    print(result.unmasked_text)  # Local display only

Features

Feature

Behavior

๐ŸŒ English & Korean

Per-word multilingual handling, conservative Korean particle separation and explicit sensitive terms

๐Ÿงฉ Code-aware masking

Language-specific lexer modes for identifiers, literals, numbers and comments

๐ŸŽญ Four surrogate strategies

Bracket, Unicode, delimited pseudoword and random hash representations

๐Ÿ” Subscription gateway

Automatic request masking, shared prompt/code aliases, local tool-argument restoration and automatic answer display; existing OAuth, no API-key fallback

๐Ÿ”Œ Local agent hooks

Claude Code and Codex tool-text masking and local execution-argument restoration; Claude Code also supports display-only restoration

๐Ÿ” Session management

Stable per-session mappings, operation locks, idle expiry and opt-in encrypted snapshots

๐Ÿ› ๏ธ CLI & Python API

Local masking/restoration, hook diagnostics, statistics and a buffered command wrapper

Masking policies

Mode

Behavior

content_words

Mask content words and detected sensitive spans; keep functional grammar.

entities_only

Mask recognized PII, URLs, secrets, code spans, numbers and capitalized names. Korean and other case-free/non-ASCII words are masked conservatively, including ordinary nouns.

aggressive

Keep a small structural subset of articles/prepositions/conjunctions; mask auxiliaries, adverbs, pronouns and other words.

code_aware

Mask identifiers, numbers, literals and comments using the selected language lexer.

English, Korean and mixed input are handled per word. Unicode names remain atomic. Korean particle splitting uses known stems and conservative rules; unknown ambiguous words stay whole. It is not a full morphological analyzer or universal person-name detector. Supply sensitive_terms for domain names, lowercase names, ambiguous names, and custom secrets. custom_preserve / CLI --preserve deliberately exempts selected words; recognized sensitive spans still take precedence. Unknown secret formats and context-dependent names may evade entities_only; inspect the payload or use broader masking. A high masking ratio does not prove absence of sensitive data.

Surrogate strategies

Strategy

Representation

bracket

[ENT_1]

unicode

โŸฆENT_1โŸง

pseudoword

Explicitly delimited pronounceable words, e.g. โŸชBrivelโ€ฆโŸซ

hash

Random 96-bit nonce, independent of the original

Pseudowords use explicit delimiters to avoid collisions with real words and adjacent tokens. Allocation is stable within a session; random strategies intentionally differ between sessions. Keep all surrogate spelling intact. Altered/unknown placeholder candidates are reported in unmatched_surrogates; strict=True rejects them. Free-form deletion or invention by a model cannot always be detected or reconstructed.

Korean restoration

Exact mask/unmask roundtrips keep written particles. For newly generated Korean responses, opt into normalize_particles=True (CLI --normalize-particles) to choose ์ด/๊ฐ€, ์€/๋Š”, ์„/๋ฅผ, ๊ณผ/์™€ and ์œผ๋กœ/๋กœ from a restored Hangul stem. Pronunciation of foreign names is not guessed.

Code-aware review representations

Code languages: python, javascript, typescript, go, rust, java, c, cpp, sql. Use explicit language in mask_code (CLI --code-language) for ambiguous snippets. Auto detection is best effort. Keywords are language-specific; builtins and shadowed builtin names are masked. Unicode identifiers, SQL comments/doubled quotes, backticks, Python f-strings and escaped newlines, C++/Rust raw strings and numeric suffixes/separators are covered by tests. Code allocations use ASCII names (smcp_ID_n and smcp_LIT_n inside literals) and random native integer constants for numbers (reserved 732846 prefix plus 12 digits), independently of the text strategy, so byte literals remain valid too. Python output is syntax-checked in tests. Output is an opaque review representation: it need not execute, type-check, retain numeric types/values, or preserve f-string/template interpolation behavior. This small lexer is not a complete parser for every version of every supported language.


System Architecture

flowchart LR
    Input[Trusted local input] --> Mask[Masking engine]
    Mask -->|Masked payload| Provider[AI provider callback]
    Provider -->|Surrogate response| Restore[Local restoration]
    Restore --> Display[User display]
    Vault[Local session mappings] --- Mask
    Vault --- Restore

The subscription gateway masks configured inference requests before forwarding them and restores responses before the CLI consumes them. The callback path masks its provider argument. Legacy agent hooks use a separate, partial tool-text path; they do not intercept all outgoing context. See the architecture and local integration documents.


CLI and Sessions

python -m secure_mcp mask "Alice from Google" --session-id example --session-file example.enc --json-output
python -m secure_mcp unmask "[ENT_1] from [ENT_2]" --session-id example --session-file example.enc --strict
python -m secure_mcp mask "john doe" --mode entities_only --sensitive-term "john doe"

Use the same hidden password, or SECURE_MCP_SESSION_PASSWORD. CLI files use authenticated Fernet encryption, random salt, PBKDF2-HMAC-SHA256 with 600,000 iterations, atomic writes and a lock over the complete CLI read/modify/write operation. A concurrent writer fails clearly. A crash may leave example.enc.lock; remove it only after confirming no writer is running. Files are opt-in; without --session-file, mappings only survive in the current process. Payload schema v2 stores allocations/counters without regenerating mappings. Legacy v1 files remain readable; unknown schema versions fail explicitly. Delete session files after use. Legacy bare pseudoword allocations retain their old ambiguity; start a new session to use the safe delimited representation for every allocation.

Session strategies are immutable; mode records the last-used policy. Creating a duplicate ID fails without changing its TTL or mappings. TTL must be positive and at most one day. The vault sweeps idle expired sessions at most one cleanup interval later (default one second), and checks expiration on access. Clear waits for active operations and invalidates retained references. Library users must use session.operation() for custom mutations; built-in engine operations use the same lock. vault.close() stops cleanup and releases all mapping references. Python cannot promise byte-level memory zeroization. Standalone PrivacySession owners manage lifetime themselves; use SessionVault for scheduled expiry.

masked_ratio counts masked token occurrences divided by non-whitespace/non-punctuation occurrences. Deprecated privacy_entropy_score is an alias, not information entropy. restored_occurrences counts replacements; restored_unique_tokens counts distinct allocations. restored_tokens_count remains a compatibility alias for replacement occurrences.


MCP Tools Reference

python -m secure_mcp serve supports local stdio only. HTTP/SSE transports are disabled in the CLI; directly exposing the Python server over a network requires host-provided authentication and isolation.

MCP tool

Purpose

mask_text

Mask text with a selected policy and session

mask_code

Create a code review representation using a selected language lexer

create_privacy_session

Create an isolated mapping session

get_session_stats

Return counters without original values or mapping entries

clear_privacy_session

Release the session's mapping references

Local Python unmask_text / unmask_code and CLI unmask are not registered as MCP tools, so a model cannot enumerate mappings via restoration. Resources: privacy://policies, privacy://status. Example desktop configurations are utility setups, not privacy proxies.

Migration from 0.1

Version 0.2 changes pseudoword delimiters, code identifier/number representations, mapping keys (mapping_key(original, token_type, code=...)), sentence-initial entity classification, keyword preservation, and the MCP restoration boundary. Direct store readers should use mapping values or mapping_key. Validate explicitly requested strategies; omitted strategies follow the generator.


ํ•œ๊ตญ์–ด ์•ˆ๋‚ด (Korean Overview)

0.5์—์„œ๋Š” Claude CodeยทCodex์˜ ๊ธฐ์กด ๊ตฌ๋… ๋กœ๊ทธ์ธ์„ ์œ ์ง€ํ•˜๋Š” ๋กœ์ปฌ ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. uv tool install . ์„ค์น˜ ํ›„ secure-mcp gateway install์„ ํ•œ ๋ฒˆ ์‹คํ–‰ํ•˜๊ณ  ๋‘ CLI๋ฅผ ์žฌ์‹œ์ž‘ํ•˜์„ธ์š”. ๊ทธ ๋’ค์—๋Š” ํ‰์†Œ์ฒ˜๋Ÿผ claude / codex๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. ์ง์ ‘ ์ž…๋ ฅยทํ…์ŠคํŠธ ์ฝ”๋“œยท๋„๊ตฌ ๊ฒฐ๊ณผ๋ฅผ ์ž๋™์œผ๋กœ ๋งˆ์Šคํ‚นํ•˜๊ณ , ๋‹ต๋ณ€๊ณผ ๋กœ์ปฌ ์‹คํ–‰ ์ธ์ž๋Š” ์ž๋™ ๋ณต์›ํ•ฉ๋‹ˆ๋‹ค. ํ•จ์ˆ˜๋ช…ยท๋ณ€์ˆ˜๋ช…ยท๋ฌธ์ž์—ดยท์ˆซ์žยท์ฃผ์„์„ ๋ณด์กดํ•˜๋Š” ์˜ˆ์™ธ๋Š” ์ถ”๊ฐ€ํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์ž…๋ ฅ์—์„œ ์ง€์นญํ•œ ํ•จ์ˆ˜์™€ ์ฝ”๋“œ์˜ ํ•จ์ˆ˜๋Š” ๊ฐ™์€ ์น˜ํ™˜ํ‘œ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ์กด ๋กœ๊ทธ์ธ ํŒŒ์ผ์€ ์ฝ๊ฑฐ๋‚˜ ๋ณต์‚ฌํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. CLI๊ฐ€ ๊ด€๋ฆฌํ•˜๋Š” OAuth ํ—ค๋”์™€ ๊ฐฑ์‹  ํ๋ฆ„์„ ์‚ฌ์šฉํ•˜๊ณ , API ํ‚ค ์š”์ฒญ์€ ๊ฑฐ๋ถ€ํ•˜๋ฏ€๋กœ ์œ ๋ฃŒ API๋กœ ์ž๋™ ์ „ํ™˜ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ƒˆ Hook์„ ๋“ฑ๋กํ•˜์ง€ ์•Š์œผ๋ฉฐ, ์šด์˜์ฒด์ œ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ์‹œ ๋ฐฑ๊ทธ๋ผ์šด๋“œ๋กœ ์ž๋™ ์‹œ์ž‘ํ•˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ์กด Hook ๋ฐฉ์‹์€ ์„ ํƒ ๊ธฐ๋Šฅ์œผ๋กœ ๋‚จ๊ฒจ ๋‘์—ˆ์Šต๋‹ˆ๋‹ค. ์„ค์น˜ยทํ•ด์ œ ๋ฐ ๋ณดํ˜ธ ๋ฒ”์œ„๋ฅผ ํ™•์ธํ•˜์„ธ์š”.

Claude Code 2.1.287ยทCodex 0.160.0์˜ ์‹ค์ œ CLI๋ฅผ ๋ชจ์˜ OAuth/๋กœ์ปฌ ์„œ๋ฒ„๋กœ ๊ฒ€์ฆํ–ˆ์Šต๋‹ˆ๋‹ค. Codex๋Š” ์‹ค์ œ ๊ตฌ๋… ์š”์ฒญยท์ž๋™ ๋ณต์›๊นŒ์ง€ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค. Claude๋Š” ์‹๋ณ„ ๋ธ”๋ก ์ฒ˜๋ฆฌ ์˜ค๋ฅ˜๋ฅผ ์ˆ˜์ •ํ•ด ์‹ค์ œ ๊ตฌ๋… HTTP 200์„ ํ™•์ธํ–ˆ์ง€๋งŒ, Sonnet ์•ˆ์ „ ํ•„ํ„ฐ ๊ฑฐ์ ˆ๋กœ ์ •์ƒ ๋‹ต๋ณ€ยท๋ณต์› ๊ฒ€์ฆ์ด ๋‚จ์•˜์Šต๋‹ˆ๋‹ค. ๊ธฐ์กด 429๋Š” ๊ตฌ๋… ํ•œ๋„ ์†Œ์ง„์ด ์•„๋‹ˆ์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฏธ์ง€ยท์›๊ฒฉ ์ฒจ๋ถ€ยท๋ฏธ์ง€์› ์š”์ฒญ์€ ์ฐจ๋‹จํ•˜๊ณ , ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ–์˜ ๋„๊ตฌ ๋„คํŠธ์›Œํฌยทํ…”๋ ˆ๋ฉ”ํŠธ๋ฆฌ๊นŒ์ง€ ๋ณดํ˜ธํ•œ๋‹ค๊ณ  ์ฃผ์žฅํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

SecureMCP๋Š” ์˜์–ดยทํ•œ๊ตญ์–ดยทํ˜ผํ•ฉ ๋ฌธ์žฅ์„ ๋กœ์ปฌ์—์„œ ๋งˆ์Šคํ‚นํ•˜๊ณ  ๋ณต์›ํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ์— ์š”์ฒญํ•˜๊ธฐ ์ „์— LocalPrivacyClient ๋˜๋Š” ๋กœ์ปฌ API/CLI๋กœ ์›๋ฌธ์„ ๊ฐ€๋ฆฌ๊ณ , ์‘๋‹ต์€ ๋กœ์ปฌ์—์„œ๋งŒ ๋ณต์›ํ•˜์„ธ์š”. ๋ชจ๋ธ์ด ํ˜ธ์ถœํ•˜๋Š” MCP ๋„๊ตฌ์˜ ์ธ์ž๋Š” ์ด๋ฏธ ์ œ๊ณต์ž์—๊ฒŒ ์ „๋‹ฌ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ, Claude Desktop/Cursor์— ์„œ๋ฒ„๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ๋งŒ์œผ๋กœ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ๋ณดํ˜ธ๋˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค. ๋ณต์›ํ•œ ์›๋ฌธ์„ ๋ชจ๋ธ ์ปจํ…์ŠคํŠธ์— ๋‹ค์‹œ ๋„ฃ์œผ๋ฉด ์•ˆ ๋ฉ๋‹ˆ๋‹ค. MCP ๋ณต์› ๋„๊ตฌ๋Š” ์ œ๊ฑฐํ–ˆ์œผ๋ฉฐ, ๊ธฐ๋ณธ CLI ์„œ๋ฒ„๋Š” ๋กœ์ปฌ stdio๋งŒ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

์˜์–ด ๋Œ€๋ฌธ์ž ์ด๋ฆ„๊ณผ Unicode ์ด๋ฆ„์„ ํ•˜๋‚˜์˜ ํ† ํฐ์œผ๋กœ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ํ•œ๊ตญ์–ด ์ด๋ฆ„๊ณผ ์ผ๋ฐ˜ ๋ช…์‚ฌ๊ฐ€ ๊ตฌ๋ถ„๋˜์ง€ ์•Š๋Š” entities_only์—์„œ๋Š” ๋น„๊ธฐ๋Šฅ์–ด๋ฅผ ๋ณด์ˆ˜์ ์œผ๋กœ ๊ฐ€๋ฆฝ๋‹ˆ๋‹ค. ์กฐ์‚ฌ ๋ถ„๋ฆฌ๋Š” ์•Œ๋ ค์ง„ ์–ด๊ฐ„๊ณผ ๋ณด์ˆ˜์ ์ธ ๊ทœ์น™์„ ์‚ฌ์šฉํ•˜๋ฉฐ, ๋ชจํ˜ธํ•œ ๋ฏธ๋“ฑ๋ก ๋‹จ์–ด๋Š” ํ†ต์งธ๋กœ ๊ฐ€๋ฆฝ๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ณ ์œ ๋ช…์‚ฌยท๋น„๋ฐ€๊ฐ’ ๋˜๋Š” ํ•œ๊ตญ์–ด ํ˜•ํƒœ์†Œ๋ฅผ ์™„๋ฒฝํžˆ ์ธ์‹ํ•˜๋Š” ๋„๊ตฌ๋Š” ์•„๋‹™๋‹ˆ๋‹ค. sensitive_terms / --sensitive-term์œผ๋กœ ํŠน์ • ์šฉ์–ด๋ฅผ ์ง€์ •ํ•˜๊ณ , ์•Œ ์ˆ˜ ์—†๋Š” ๋ฏผ๊ฐ์ •๋ณด์—๋Š” ๋” ๋„“์€ ๋งˆ์Šคํ‚น ์ •์ฑ…์„ ์‚ฌ์šฉํ•˜์„ธ์š”.

์ •ํ™•ํ•œ ์™•๋ณต ๋ณต์›์—์„œ๋Š” ์ž…๋ ฅ ์กฐ์‚ฌ๋ฅผ ๊ทธ๋Œ€๋กœ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋ธ์ด ์ƒˆ๋กœ ๋งŒ๋“  ๋ฌธ์žฅ์—๋Š” normalize_particles=True / --normalize-particles๋ฅผ ์„ ํƒํ•˜์—ฌ ๋ฐ›์นจ์— ๋งž๋Š” ์กฐ์‚ฌ๋ฅผ ๋ณด์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜์–ด ์ด๋ฆ„ยท์•ฝ์–ด์˜ ๋ฐœ์Œ์€ ์ถ”์ธกํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. --strict๋Š” ํƒ์ง€ํ•œ ๋ณ€ํ˜•ยท๋ฏธ๋“ฑ๋ก ํ”Œ๋ ˆ์ด์Šคํ™€๋”์˜ ๋ณต์›์„ ๊ฑฐ๋ถ€ํ•˜์ง€๋งŒ, ๋ชจ๋ธ์ด ์™„์ „ํžˆ ์‚ญ์ œํ•œ ๋‚ด์šฉ์„ ์žฌ๊ตฌ์„ฑํ•˜์ง€๋Š” ๋ชปํ•ฉ๋‹ˆ๋‹ค.

์„ธ์…˜ ์ „๋žต์€ ์ƒ์„ฑ ํ›„ ๊ณ ์ •๋˜๋ฉฐ, ์ค‘๋ณต ID ์ƒ์„ฑ์€ ์˜ค๋ฅ˜์ž…๋‹ˆ๋‹ค. ๋งŒ๋ฃŒ ์„ธ์…˜์€ ์ฃผ๊ธฐ์ ์œผ๋กœ ์ •๋ฆฌํ•˜๊ณ , ์‚ญ์ œ์™€ ์ง„ํ–‰ ์ค‘ ์ž‘์—…์„ ์ž ๊ธˆ์œผ๋กœ ์กฐ์œจํ•ฉ๋‹ˆ๋‹ค. ๋ณ„๋„ CLI ํ”„๋กœ์„ธ์Šค ๊ฐ„ ๋ณต์›์—๋Š” ๋™์ผํ•œ ์•”ํ˜ธํ™” --session-file์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋งˆ์Šคํ‚น ๋น„์œจ์€ ํ†ต๊ณ„์ด๋ฉฐ ๊ธฐ๋ฐ€์„ฑยท์ต๋ช…์„ฑยท๊ทœ์ œ ์ค€์ˆ˜์˜ ์ฆ๋ช…์ด ์•„๋‹™๋‹ˆ๋‹ค.


Development

python -m ruff check src tests examples
python -m mypy src
python -m pytest -W error --cov=secure_mcp --cov-report=term-missing --cov-fail-under=85

Documentation

License

Licensed under Apache License 2.0. See LICENSE for details.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables anonymization and deanonymization of sensitive data in text using Microsoft Presidio. Supports session-based storage to reversibly replace sensitive information like passwords and secrets with placeholder tokens.
    -
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI assistants to mask sensitive personal data and project directories before sending to AI, then unmask responses to restore original values using configurable swap sessions.
    7
    MIT