repo-guardian
repo-guardian
MCP-Server, der Repo-Health-Tools bereitstellt, sodass jeder Agent Repositories absichern kann — er erkennt gepinnte/nicht gepinnte Abhängigkeiten, Lizenzkonformitätsprobleme, hartkodierte Geheimnisse und toten Code.
Funktionen
audit_dependencies — Parst
pyproject.toml,requirements*.txtundsetup.py; kennzeichnet exakte Pins, die unter Umständen Sicherheits-Patches verpassen, sowie Abhängigkeiten ohne Versionsbeschränkungen.check_licenses — Scannt deklarierte Abhängigkeitslizenzen auf Konformitätsprobleme (GPL/AGPL-Copyleft, unbekannte Lizenzen, Lizenzinkompatibilitäten mit der Projektlizenz).
scan_for_secrets — Sucht nach AWS-Keys, GitHub-Tokens, Slack-Tokens, Google-API-Keys, Stripe-Keys, Private-Key-Blöcken, Passwort-Zuweisungen, Bearer-Tokens und Zeichenfolgen mit hoher Entropie.
find_dead_code — Erkennt ungenutzte Python-Importe, ungenutzte Funktionen und verwaiste Dateien.
Alle Scanner arbeiten ohne externe Abhängigkeiten (nur stdlib) und lassen die MCP-Sitzung nie abstürzen — Fehler werden als Tool-Ergebnisse zurückgegeben.
Related MCP server: sdlc-integrity-mcp
Installation
pip install repo-guardianFür die Entwicklung:
git clone https://github.com/prem-the-dev/repo-guardian.git
cd repo-guardian
pip install -e ".[dev]"Schnellstart (Claude Desktop / Cursor / Windsurf)
Fügen Sie Folgendes zu Ihrer MCP-Client-Konfiguration hinzu:
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Cursor (.cursor/mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Windsurf (.codeium/windsurf/mcp.json)
Gleiche Konfiguration wie oben bei Cursor.
Gemini CLI (gemini/.gemini/.mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Hermes Agent
Kopieren Sie das mitgelieferte agentjson`name in Ihr Hermes-Profil oder führen Sie es mit Ihrer bestehenden MCP-Server-Konfiguration zusammen:
cp mcp.json ~/.hermes/profiles/mcp-specialist/mcp.json
hermes profile reload{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Anwendungsbeispiele
Nach der Konfiguration kann jeder Agent die Tools aufrufen:
Lizenzen prüfen
audit_dependencies(path="/path/to/my-project")Ergebnis:
{
"status": "ok",
"scanned_files": ["pyproject.toml", "requirements.txt"],
"total_dependencies": 4,
"pinned_dependencies": [
{"name": "Django", "version_spec": "==4.2.7", "classification": "pinned"}
],
"potential_issues": [
{"type": "pinned_exact", "dependency": "Django", "message": "..."}
]
}Lizenzen prüfen
check_licenses(path="/path/to/my-project")Ergebnis:
{
"status": "ok",
"project_license": "MIT",
"restricted_licenses": [],
"unknown_licenses": [...],
"potential_issues": []
}Geheimnisse scannen
scan_for_secrets(path="/path/to/my-project", max_file_size_mb=5)Ergebnis:
{
"status": "ok",
"total_findings": 3,
"findings": [
{"type": "aws_access_key", "file": ".env", "line": 2, "confidence": "high"},
{"type": "github_token", "file": "config.py", "line": 5, "confidence": "high"}
]
}Toten Code finden
find_dead_code(path="/path/to/my-project")Ergebnis:
{
"status": "ok",
"unused_imports": [
{"type": "unused_import", "file": "main.py", "line": 3, "name": "unused_module"}
],
"unused_functions": [
{"type": "unused_function", "file": "main.py", "line": 12, "name": "unused_function"}
],
"orphaned_files": [...]
}Tests ausführen
python -m pytest tests/ -vArchitektur
graph TD
A[MCP Client<br/>Claude/Cursor/Windsurf/Hermes] -->|stdio JSON-RPC| B[MCP Server<br/>repo_guardian]
B --> C[Tool Registry<br/>tools/list + tools/call]
C --> D[audit_dependencies]
C --> E[check_licenses]
C --> F[scan_for_secrets]
C --> G[find_dead_code]
D --> D1[pyproject.toml parser]
D --> D2[requirements.txt parser]
D --> D3[setup.py parser]
E --> E1[SPDX license DB<br/>offline lookup]
E --> E2[Project license<br/>detect]
F --> F1[Pattern matchers<br/>AWS/GH/Slack/etc]
F --> F2[Shannon entropy<br/>high-entropy scan]
G --> G1[AST parser<br/>imports + defs]
G --> G2[Cross-file<br/>usage tracker]Lizenz
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables hybrid code audits using MCP tools across 12 domains, producing structured, scored, and actionable code quality reports.61MIT
- AlicenseAqualityAmaintenanceMCP server that provides audit and safety-check tools for enterprise SDLC code integrity, enabling AI agents to scan workspaces for lifecycle gaps, mock-theater tests, DRY violations, and language-specific issues in shell, JavaScript/HTML, and Python.4376MIT
- AlicenseAqualityCmaintenanceEnables policy-first defensive security operations for MCP, providing repository and web-security analysis with controlled authorization, scoped execution, and auditability.9MIT
- AlicenseAqualityCmaintenanceMCP server providing diagnostic tools to analyze software architecture, security, REST API compliance, and dependencies for multiple programming languages. Enables AI agents to run scans and audits on codebases.7MIT
Related MCP Connectors
Remote MCP for tool license checks, vendor policy review, alternatives, and license receipts.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/prem-the-dev/repo-guardian'
If you have feedback or need assistance with the MCP directory API, please join our Discord server