ShadowRun
ShadowRun
MCP 서버를 위한 로컬 우선 stdio 프록시입니다. AI 에이전트(Claude Code, Cursor 등)와 실제 MCP 서버 사이에 위치하여, 실행 전에 파괴적인 도구 호출(쓰기, 삭제, SQL 변이 등)을 가로채고, 로컬 대시보드에서 커밋하거나 폐기할 때까지 메모리에 보관합니다.
'가짜 성공' 인터셉터와 달리 ShadowRun은 가로챈 호출이 해결될 때까지 에이전트에 응답하지 않습니다. 응답을 위조하면(예: INSERT ... RETURNING id의 경우) 에이전트가 아직 존재하지 않는 데이터를 기반으로 행동하게 되어 현실과의 믿음 상태가 달라지기 때문입니다. 따라서 가로챈 호출은 대신 (타임아웃과 함께) 대기합니다.
범위 (v0.1)
이는 의도적으로 좁게 설정되었습니다: Claude Code / Cursor와 함께 사용되는 로컬 MCP 서버(Postgres, 파일시스템 등)를 위한 단일 개발자 CLI입니다. 팀 정책 시행 게이트웨이가 아니며, 인증 기능이 없고, 재시작 시에도 지속성이 없습니다. 자신의 머신 외부에서 사용하기 전에 아래 제한 사항을 참조하세요.
Related MCP server: Agentrim MCP
설치 및 실행
npm install
npm run build에이전트 설정을 실제 서버 대신 프록시로 지정하세요:
{
"mcpServers": {
"postgres": {
"command": "node",
"args": [
"/path/to/shadowrun-mcp/dist/index.js",
"npx", "-y", "@modelcontextprotocol/server-postgres",
"postgresql://localhost:5432/devdb"
]
}
}
}http://127.0.0.1:4040을 열어 보류 중인 변이를 확인하고, 각각을 커밋하거나 폐기하세요. 읽기 전용 호출(get*, list*, search* 등)은 즉시 통과하며 대시보드에 표시되지 않습니다.
분류 방식
src/interceptor.ts — DEFAULT_CONFIG를 참조하세요. 도구 호출은 이름이 변이 동사 패턴(write, delete, create 등)과 일치하고 먼저 안전한 읽기 패턴과 일치하지 않거나, 문자열 인수에 SQL 변이 키워드(insert into, drop table 등)가 포함된 경우 가로챕니다. 이는 휴리스틱이며 보장이 아닙니다 — 제한 사항을 참조하세요.
제한 사항
휴리스틱 분류기. 도구 이름과 인수 텍스트에 대한 정규식은 교묘하게 명명된 변이 도구를 놓치고 이상하게 명명된 읽기 도구를 과도하게 가로챌 수 있습니다. 이를 보안 경계가 아닌 과속 방지턱으로 취급하세요.
대시보드에 인증 없음.
127.0.0.1에만 바인딩되지만, 해당 포트에 도달할 수 있는 모든 로컬 프로세스(또는 이론상 DNS 리바인딩을 수행하는 악성 페이지)는 커밋/폐기할 수 있습니다. 공유 또는 신뢰할 수 없는 머신에서 실행하지 마세요.메모리 전용. 프록시를 재시작하면 모든 보류 중인 변이가 사라집니다 — 에이전트의 원래 호출은 단순히 시간 초과됩니다.
단일 개발자, 로컬 사용. 공유 감사 로그나 팀 전체 정책 시행 기능이 없습니다. 이것이 필요하다면 호스팅된 MCP 게이트웨이를 대신 사용하세요.
라이선스
AGPL-3.0
This server cannot be deployed
Maintenance
Related MCP Connectors
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
MCP server for progressive tool usage at any scale (see https://klavis.ai)
Nifty's MCP server — exposes tasks, projects, messages, and files as tools for AI agents.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceZero-dependency local proxy that wraps any MCP server to redact secrets, strip hidden-Unicode prompt injection, and block writes to protected paths like ~/.ssh and .env.4MIT
- AlicenseNot gradedqualityBmaintenanceA least-privilege enforcement proxy for MCP servers. It sits between MCP clients and upstream servers, enforcing tool policies, hiding denied tools, requiring human approval for risky actions, and providing a structured audit trail.MIT
- AlicenseNot gradedqualityDmaintenanceA zero-infrastructure, local proxy that wraps any stdio MCP server to add audit logging, policy enforcement with regex guards, and per-session/per-day budgets.MIT
- AlicenseNot gradedqualityAmaintenanceAn MCP proxy that records every tool call, restores prior state on undo, and blocks irreversible actions until a human approves them.1,238 npm2MIT