repo-guardian
repo-guardian
リポジトリの健全性をチェックするツールを公開し、あらゆるエージェントがリポジトリを保護できるMCPサーバーです。依存関係の固定(pinned)/未固定(unpinned)、ライセンスコンプライアンス上の問題、ハードコードされたシークレット、デッドコードを検出します。
機能
audit_dependencies —
pyproject.toml、requirements*.txt、setup.pyを解析し、セキュリティパッチの適用を取り逃す可能性のある完全固定(exact pin)や、バージョン制約が指定されていない依存関係を警告します。check_licenses — 宣言された依存関係のライセンスをスキャンし、コンプライアンス上の問題(GPL/AGPLのコピーレフト、不明なライセンス、プロジェクトのライセンスとの非互換性)を検出します。
scan_for_secrets — AWSキー、GitHubトークン、Google APIキー、Stripeキー、秘密鍵ブロック、パスワードの代入、ベアラートークン、高エントロピー文字列を検索します。
find_dead_code — 未使用のPythonインポート、未使用の関数、孤立したファイルを検出します。
すべてのスキャナーは外部依存がなく(標準ライブラリのみ)、MCPセッションをクラッシュさせることはありません。エラーはツールの結果として返されます。
Related MCP server: sdlc-integrity-mcp
インストール
pip install repo-guardian開発用:
git clone https://github.com/prem-the-dev/repo-guardian.git
cd repo-guardian
pip install -e ".[dev]"クイックスタート(Claude Desktop / Cursor / Windsurf)
MCPクライアント設定に以下を追加してください:
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Cursor (.cursor/mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Windsurf (.codeium/windsurf/mcp.json)
Cursor の場合と同じ設定です。
Gemini CLI (gemini/.gemini/.mcp.json)
{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}Hermes Agent
同梱の mcp.json を Hermes プロファイルにコピーするか、既存の MCP サーバー設定にマージしてください:
cp mcp.json ~/.hermes/profiles/mcp-specialist/mcp.json
hermes profile reload{
"mcpServers": {
"repo-guardian": {
"command": "python",
"args": ["-m", "repo_guardian"]
}
}
}使用例
設定が完了すると、どのエージェントでもツールを呼び出せます:
依存関係の監査
audit_dependencies(path="/path/to/my-project")戻り値:
{
"status": "ok",
"scanned_files": ["pyproject.toml", "requirements.txt"],
"total_dependencies": 4,
"pinned_dependencies": [
{"name": "Django", "version_spec": "==4.2.7", "classification": "pinned"}
],
"potential_issues": [
{"type": "pinned_exact", "dependency": "Django", "message": "..."}
]
}ライセンスの検査
check_licenses(path="/path/to/my-project")戻り値:
{
"status": "ok",
"project_license": "MIT",
"restricted_licenses": [],
"unknown_licenses": [...],
"potential_issues": []
}シークレットのスキャン
scan_for_secrets(path="/path/to/my-project", max_file_size_mb=5)戻り値:
{
"status": "ok",
"total_findings": 3,
"findings": [
{"type": "aws_access_key", "file": ".env", "line": 2, "confidence": "high"},
{"type": "github_token", "file": "config.py", "line": 5, "confidence": "high"}
]
}デッドコードの検出
find_dead_code(path="/path/to/my-project")戻り値:
{
"status": "ok",
"unused_imports": [
{"type": "unused_import", "file": "main.py", "line": 3, "name": "unused_module"}
],
"unused_functions": [
{"type": "unused_function", "file": "main.py", "line": 12, "name": "unused_function"}
],
"orphaned_files": [...]
}テストの実行
python -m pytest tests/ -vアーキテクチャ
graph TD
A[MCP Client<br/>Claude/Cursor/Windsurf/Hermes] -->|stdio JSON-RPC| B[MCP Server<br/>repo_guardian]
B --> C[Tool Registry<br/>tools/list + tools/call]
C --> D[audit_dependencies]
C --> E[check_licenses]
C --> F[scan_for_secrets]
C --> G[find_dead_code]
D --> D1[pyproject.toml parser]
D --> D2[requirements.txt parser]
D --> D3[setup.py parser]
E --> E1[SPDX license DB<br/>offline lookup]
E --> E2[Project license<br/>detect]
F --> F1[Pattern matchers<br/>AWS/GH/Slack/etc]
F --> F2[Shannon entropy<br/>high-entropy scan]
G --> G1[AST parser<br/>imports + defs]
G --> G2[Cross-file<br/>usage tracker]ライセンス
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables hybrid code audits using MCP tools across 12 domains, producing structured, scored, and actionable code quality reports.61MIT
- AlicenseAqualityAmaintenanceMCP server that provides audit and safety-check tools for enterprise SDLC code integrity, enabling AI agents to scan workspaces for lifecycle gaps, mock-theater tests, DRY violations, and language-specific issues in shell, JavaScript/HTML, and Python.4376MIT
- AlicenseAqualityCmaintenanceEnables policy-first defensive security operations for MCP, providing repository and web-security analysis with controlled authorization, scoped execution, and auditability.9MIT
- AlicenseAqualityCmaintenanceMCP server providing diagnostic tools to analyze software architecture, security, REST API compliance, and dependencies for multiple programming languages. Enables AI agents to run scans and audits on codebases.7MIT
Related MCP Connectors
Remote MCP for tool license checks, vendor policy review, alternatives, and license receipts.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/prem-the-dev/repo-guardian'
If you have feedback or need assistance with the MCP directory API, please join our Discord server