workflow-guard-mcp
Provides OpenAI Codex with a shared policy decision point for proposed shell, file write, git, and network actions, returning allow, deny, or ask verdicts.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@workflow-guard-mcpCheck if this action is allowed: git push --force"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
workflow-guard-mcp
Portable guardrails for agentic coding clients that speak the Model Context Protocol (MCP).
The project is intended to reduce the blast radius of fast, highly autonomous coding workflows by giving clients a shared policy decision point. The MCP server does not execute the proposed action itself.
Status
This repository is an early scaffold. The current guard_check tool demonstrates a stable policy-decision contract; it is not yet a complete port of opencode-workflow-guard policies.
Most importantly, connecting an MCP server does not make it an interceptor for every native tool a coding client can execute. Hard enforcement depends on integration support in the host. See Compatibility and Plan.
Related MCP server: Vaikora Guard MCP
Tools
guard_check: evaluates a proposedshell,file_write,git, ornetworkaction and returnsallow,deny, oraskwith a machine-readable policy ID.guard_status: reports the server's current enforcement mode. It explicitly identifies this scaffold as host-dependent policy advice.
Development
Requires Node.js 20 or newer.
npm install
npm test
npm run typecheck
npm run buildThe initial transport is stdio because both Claude Code and Codex support local stdio MCP servers. Streamable HTTP can be added without changing the policy API.
Design Principle
The public promise is deliberately narrower than "this MCP sandboxes your coding agent." It centralizes policy. Client adapters enforce that policy wherever the client exposes a trustworthy interception mechanism; otherwise the result remains advisory and should be combined with the client's native sandbox and approval controls.
Sources
The compatibility design was checked against current official documentation and source on 2026-08-27:
Anthropic Claude Code MCP: https://docs.claude.com/en/docs/claude-code/mcp
Anthropic Claude Code hooks: https://github.com/anthropics/claude-code/blob/main/plugins/plugin-dev/skills/hook-development/SKILL.md
OpenAI Codex: https://github.com/openai/codex
Codex MCP configuration implementation: https://github.com/openai/codex/blob/main/codex-rs/config/src/mcp_types.rs
MCP TypeScript SDK: https://github.com/modelcontextprotocol/typescript-sdk/blob/v1.29.0/docs/server.md
License
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- AlicenseAqualityDmaintenanceRuntime policy enforcement for AI agents. Evaluate every agent action against your organization's policies before execution, with observe and enforce modes.11MIT

Vaikora Guard MCPofficial
AlicenseNot gradedqualityDmaintenanceEnforces deterministic policies on AI agent tool calls, evaluating actions against compliance modules (SOC 2, HIPAA, GDPR, etc.) and returning ALLOW, BLOCK, or CONSTRAIN decisions with an audit trail.MIT- FlicenseNot gradedqualityBmaintenanceEnables AI coding agents to evaluate actions against team-defined policies, record decisions, and obtain human approvals for potentially risky operations.1651
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.
Related MCP Connectors
Git-native policy layer for AI agents: check_action verdicts against rules approved via PR.
Runtime permission, approval, and audit layer for AI agent tool execution.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ultus-net/workflow-guard-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server