GuardianShield
GuardianShield
Universal AI security layer — an open-source MCP server for code scanning, PII detection, prompt injection defense, secret detection, dependency auditing, and audit logging.
Zero dependencies · 27 MCP tools · 5 safety profiles · 108+ detection patterns
Features
Code Vulnerability Scanning — SQL injection, XSS, command injection, path traversal with CWE IDs and auto-fix remediation
Cross-line Data Flow Analysis — DeepEngine tracks tainted data from sources to sinks across multiple lines using AST-based taint propagation (Python) and regex (JS/TS)
Dependency Security — Version-aware CVE matching against OSV.dev for PyPI, npm, Go, and Packagist ecosystems
Manifest Parsing — Auto-detects 11 formats (requirements.txt, package.json, yarn.lock, go.mod, composer.json, and more)
Prompt Injection Defense — 9+ detection patterns for instruction override, role hijacking, ChatML injection
PII Detection — Email, SSN, credit card, phone, IP — with automatic redaction in findings
Secret Detection — AWS keys, GitHub tokens, Stripe keys, JWTs, passwords, connection strings
Safety Profiles — 5 built-in profiles (general, education, healthcare, finance, children)
Audit Logging — SQLite-backed scan history with finding retrieval and filtering
Install
pip install guardianshieldQuick Start
# Register with Claude Code
claude mcp add guardianshield -- guardianshield-mcp
# Or run directly
guardianshield-mcpEditor Integration
# Claude Code
claude mcp add guardianshield -- guardianshield-mcp
# VS Code (.vscode/mcp.json)
{"servers": {"guardianshield": {"type": "stdio", "command": "guardianshield-mcp"}}}
# Cursor (.cursor/mcp.json)
{"mcpServers": {"guardianshield": {"command": "guardianshield-mcp"}}}
# Claude Desktop (claude_desktop_config.json)
{"mcpServers": {"guardianshield": {"command": "guardianshield-mcp"}}}MCP Tools
Scanning
Tool | Description |
| Scan source code for vulnerabilities and hardcoded secrets |
| Scan a single file (auto-detects language from extension) |
| Recursively scan a directory with filtering and progress streaming |
| Check user/agent input for prompt injection attempts |
| Check AI output for PII leaks and content violations |
| Detect hardcoded secrets and credentials |
| Scan multiple files in one call |
| Parse unified diff and scan only added lines |
Dependency Security
Tool | Description |
| Check packages for known CVEs via OSV.dev (PyPI, npm, Go, Packagist) |
| Sync the local OSV vulnerability database |
| Parse any supported manifest file (11 formats) into dependency objects |
| Scan a directory for manifest files and check all deps for vulnerabilities |
False Positive Management
Tool | Description |
| Mark a finding as false positive (flags future matches) |
| List active false positive records with optional filter |
| Remove a false positive record by fingerprint |
Engine Management
Tool | Description |
| List available analysis engines with capabilities |
| Set active analysis engines for code scanning |
Three engines ship built-in: regex (line-by-line pattern matching, enabled by default), deep (cross-line taint tracking), and semantic (structure-aware confidence adjustment).
CI & Developer Workflow
Tool | Description |
| Export findings as SARIF 2.1.0 JSON for GitHub Code Scanning and CI |
| Save current findings as a baseline for delta scanning |
| Scan code and report only new findings vs. baseline |
| Evaluate findings against severity thresholds (pass/fail/warn) |
| Scan multiple files in one call |
| Parse unified diff and scan only added lines |
Configuration & Utilities
Tool | Description |
| Get current safety profile configuration |
| Switch safety profile (general, education, healthcare, finance, children) |
| Test a regex pattern against sample code for custom pattern development |
| Query the security audit log |
| Retrieve past findings with filters |
| Get health, configuration, and OSV cache statistics |
Configuration
Set environment variables to customize behavior:
Variable | Description | Default |
| Default safety profile |
|
| Path to SQLite audit database |
|
| Enable debug logging ( | disabled |
Documentation
Full documentation: sparkvibe-io.github.io/GuardianShield
License
Apache 2.0
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/sparkvibe-io/GuardianShield'
If you have feedback or need assistance with the MCP directory API, please join our Discord server