mcp-security-guard
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_SECURITY_API_KEY | No | Opt-in API key for the paid Pro & Team plans (daily threat feed, alerts on changed tool descriptions, history, team policies and dashboards). Everything else runs locally and needs no account. | |
| MCP_SECURITY_AUDIT_LOG | No | Set to `off` to disable the runtime audit log at `~/.claude/mcp-security/audit.jsonl`. | on |
| MCP_SECURITY_SECRET_GUARD | No | Controls the PreToolUse hook on `mcp__*` calls: asks for confirmation when a call's arguments contain a credential. Values: `ask` (default), `deny` or `off`. | ask |
| MCP_SECURITY_SESSION_CHECK | No | Controls the SessionStart hook check that re-verifies only the servers you have pinned. Values: `full` (default) compares launch configs and re-lists tools; `config` compares launch configs only, launch nothing; `off` disables the check. | full |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_mcp_serversA | Lists every MCP server configured for this project (user, local and project scope in Claude Code, plus Claude Desktop) with its transport. Reads config files only; launches nothing. |
| audit_mcp_configA | Static audit of MCP server configuration: plaintext secrets in env/headers/args/URLs, plain-HTTP remote servers, unpinned npx/uvx packages, unpinned or privileged Docker containers, pipe-to-shell launch commands, and duplicate server names across scopes. Read-only; launches nothing. |
| audit_server_toolsA | Connects to the selected MCP servers, lists their tools, and checks every name, description and schema string for tool poisoning (instruction overrides, concealment requests, hidden tags, invisible Unicode, sensitive file paths, exfiltration wording, encoded payloads), cross-server tool shadowing, and changes since the tools were last pinned (rug pulls). Never calls the scanned tools. |
| pin_toolsA | Records a SHA-256 hash of every tool definition of the selected servers in ~/.claude/mcp-security/pins.json, so later audits can detect rug pulls. Pin only after the user has reviewed an audit_server_tools report for these servers. Launches the servers like audit_server_tools. |
| analyze_tool_definitionsA | Runs the tool-poisoning checks on tool definitions you pass in (e.g. the output of tools/list from a server you are developing), without connecting to anything. Useful in CI or before publishing an MCP server. |
| check_supply_chainA | For servers launched with npx/uvx and similar, checks the package on its registry and in the OSV database: known vulnerabilities, known malicious versions, typosquats of popular MCP packages, non-existent names, very new packages or releases, install scripts, deprecation and npm publisher changes. Sends package names and versions to registry.npmjs.org, pypi.org and api.osv.dev; nothing else leaves the machine. |
| adversarial_testA | CALLS every non-destructive tool of one configured server with command-injection payloads (each would only create an empty canary file) and path-traversal payloads, then reports which parameters reach a shell or the file system unchecked. Only for servers the user develops or operates, ideally a test instance in a container. Destructive tools are skipped unless include_destructive is true. |
| security_dashboardA | Opens the interactive mcp-security-guard dashboard: every configured MCP server with its score and grade, findings filterable by severity and server, the OWASP MCP Top 10 breakdown, recommended permission rules, and pin buttons. scan='config' reads files only. scan='full' starts the servers to list their tools, prompts and resources (no tool is called) and needs confirm_launch=true; ask the user first. |
| apply_fixesA | Fixes findings in the project's own files. permissions: adds the recommended permissions.ask rules for tools that execute code, delete data or write files to .claude/settings.json (needs confirm_launch, because the servers are listed to classify their tools). pin-versions: pins unpinned npx/uvx packages in .mcp.json to the registry's current version (needs confirm_network). env-refs: replaces literal secrets in .mcp.json env/headers with ${VAR} references. Without write=true it only shows the planned edits. Every written file is backed up under ~/.claude/mcp-security/backups/ first; ~/.claude.json is never modified. |
| generate_policyA | Returns a .mcp-security.json policy that approves exactly the MCP servers configured now (and their remote hosts) and requires pinned versions. Commit it to the repository so CI, session checks and audits flag any server added later that is not on the list (shadow MCP servers). Read-only: returns the JSON, does not write it. |
| query_audit_logA | Summarises the local audit log written by the plugin's hooks: MCP tool calls per server and tool, and every call where a credential was sent, a credential came back, or the output contained injected instructions. The log stores hashes and sizes only, never arguments or outputs. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| mcp-security-guard dashboard | Interactive security dashboard (MCP App). |
TDQS
Scored across 11 tools
Most tools target clearly different objects: config files (audit_mcp_config), live server tools (audit_server_tools), passed-in definitions (analyze_tool_definitions), packages (check_supply_chain), and active probing (adversarial_test). The mild overlap between audit_server_tools and analyze_tool_definitions (both run poisoning checks) and between security_dashboard and query_audit_log is well clarified by descriptions. An agent can reliably pick the right tool.
Strong verb_noun convention throughout (audit_mcp_config, list_mcp_servers, apply_fixes, generate_policy, pin_tools, check_supply_chain, query_audit_log). A couple of noun-only names (security_dashboard, adversarial_test) break the pattern slightly but remain readable and unambiguous.
11 tools is well within the ideal 3-15 range and each maps to a distinct security function (audit, fix, policy, pin, log, supply chain, adversarial, dashboard). No obvious redundancy or padding.
Covers the full security lifecycle: discovery, static/live auditing, remediation, policy generation, pinning, supply-chain checks, adversarial probing, and reporting. Minor gaps exist (no unpin/remove-server operation and no exportable report artifact), but agents can work around these.