Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_SECURITY_API_KEYNoOpt-in API key for the paid Pro & Team plans (daily threat feed, alerts on changed tool descriptions, history, team policies and dashboards). Everything else runs locally and needs no account.
MCP_SECURITY_AUDIT_LOGNoSet to `off` to disable the runtime audit log at `~/.claude/mcp-security/audit.jsonl`.on
MCP_SECURITY_SECRET_GUARDNoControls the PreToolUse hook on `mcp__*` calls: asks for confirmation when a call's arguments contain a credential. Values: `ask` (default), `deny` or `off`.ask
MCP_SECURITY_SESSION_CHECKNoControls the SessionStart hook check that re-verifies only the servers you have pinned. Values: `full` (default) compares launch configs and re-lists tools; `config` compares launch configs only, launch nothing; `off` disables the check.full

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
list_mcp_serversA

Lists every MCP server configured for this project (user, local and project scope in Claude Code, plus Claude Desktop) with its transport. Reads config files only; launches nothing.

audit_mcp_configA

Static audit of MCP server configuration: plaintext secrets in env/headers/args/URLs, plain-HTTP remote servers, unpinned npx/uvx packages, unpinned or privileged Docker containers, pipe-to-shell launch commands, and duplicate server names across scopes. Read-only; launches nothing.

audit_server_toolsA

Connects to the selected MCP servers, lists their tools, and checks every name, description and schema string for tool poisoning (instruction overrides, concealment requests, hidden tags, invisible Unicode, sensitive file paths, exfiltration wording, encoded payloads), cross-server tool shadowing, and changes since the tools were last pinned (rug pulls). Never calls the scanned tools.

pin_toolsA

Records a SHA-256 hash of every tool definition of the selected servers in ~/.claude/mcp-security/pins.json, so later audits can detect rug pulls. Pin only after the user has reviewed an audit_server_tools report for these servers. Launches the servers like audit_server_tools.

analyze_tool_definitionsA

Runs the tool-poisoning checks on tool definitions you pass in (e.g. the output of tools/list from a server you are developing), without connecting to anything. Useful in CI or before publishing an MCP server.

check_supply_chainA

For servers launched with npx/uvx and similar, checks the package on its registry and in the OSV database: known vulnerabilities, known malicious versions, typosquats of popular MCP packages, non-existent names, very new packages or releases, install scripts, deprecation and npm publisher changes. Sends package names and versions to registry.npmjs.org, pypi.org and api.osv.dev; nothing else leaves the machine.

adversarial_testA

CALLS every non-destructive tool of one configured server with command-injection payloads (each would only create an empty canary file) and path-traversal payloads, then reports which parameters reach a shell or the file system unchecked. Only for servers the user develops or operates, ideally a test instance in a container. Destructive tools are skipped unless include_destructive is true.

security_dashboardA

Opens the interactive mcp-security-guard dashboard: every configured MCP server with its score and grade, findings filterable by severity and server, the OWASP MCP Top 10 breakdown, recommended permission rules, and pin buttons. scan='config' reads files only. scan='full' starts the servers to list their tools, prompts and resources (no tool is called) and needs confirm_launch=true; ask the user first.

apply_fixesA

Fixes findings in the project's own files. permissions: adds the recommended permissions.ask rules for tools that execute code, delete data or write files to .claude/settings.json (needs confirm_launch, because the servers are listed to classify their tools). pin-versions: pins unpinned npx/uvx packages in .mcp.json to the registry's current version (needs confirm_network). env-refs: replaces literal secrets in .mcp.json env/headers with ${VAR} references. Without write=true it only shows the planned edits. Every written file is backed up under ~/.claude/mcp-security/backups/ first; ~/.claude.json is never modified.

generate_policyA

Returns a .mcp-security.json policy that approves exactly the MCP servers configured now (and their remote hosts) and requires pinned versions. Commit it to the repository so CI, session checks and audits flag any server added later that is not on the list (shadow MCP servers). Read-only: returns the JSON, does not write it.

query_audit_logA

Summarises the local audit log written by the plugin's hooks: MCP tool calls per server and tool, and every call where a credential was sent, a credential came back, or the output contained injected instructions. The log stores hashes and sizes only, never arguments or outputs.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
mcp-security-guard dashboardInteractive security dashboard (MCP App).

TDQS

A4/5.0

Scored across 11 tools

Disambiguation4/5

Most tools target clearly different objects: config files (audit_mcp_config), live server tools (audit_server_tools), passed-in definitions (analyze_tool_definitions), packages (check_supply_chain), and active probing (adversarial_test). The mild overlap between audit_server_tools and analyze_tool_definitions (both run poisoning checks) and between security_dashboard and query_audit_log is well clarified by descriptions. An agent can reliably pick the right tool.

Naming Consistency4/5

Strong verb_noun convention throughout (audit_mcp_config, list_mcp_servers, apply_fixes, generate_policy, pin_tools, check_supply_chain, query_audit_log). A couple of noun-only names (security_dashboard, adversarial_test) break the pattern slightly but remain readable and unambiguous.

Tool Count5/5

11 tools is well within the ideal 3-15 range and each maps to a distinct security function (audit, fix, policy, pin, log, supply chain, adversarial, dashboard). No obvious redundancy or padding.

Completeness4/5

Covers the full security lifecycle: discovery, static/live auditing, remediation, policy generation, pinning, supply-chain checks, adversarial probing, and reporting. Minor gaps exist (no unpin/remove-server operation and no exportable report artifact), but agents can work around these.

Maintenance

ActivityMaintained
ResponsivenessNo issues