workflow-guard-mcp
workflow-guard-mcp
Переносимые защитные ограничения для агентных кодинг-клиентов, поддерживающих Model Context Protocol (MCP).
Проект призван уменьшить радиус поражения быстрых и высокоавтономных рабочих процессов кодинга, предоставляя клиентам общую точку принятия решений по политике. Сам MCP-сервер не выполняет предлагаемое действие.
Статус
Этот репозиторий — ранний каркас. Текущий инструмент guard_check демонстрирует стабильный контракт принятия решений по политике; это ещё не полный порт политик opencode-workflow-guard.
Самое главное, подключение MCP-сервера не делает его перехватчиком для каждого нативного инструмента, который может выполнить кодинг-клиент. Жёсткое применение зависит от поддержки интеграции в хост-приложении. См. Совместимость и План.
Related MCP server: Vaikora Guard MCP
Инструменты
guard_check: оценивает предлагаемое действиеshell,file_write,gitилиnetworkи возвращаетallow,denyилиaskс машиночитаемым ID политики.guard_status: сообщает текущий режим применения политик сервера. Он явно идентифицирует этот каркас как зависящую от хост-приложения рекомендацию по политике.
Разработка
Требуется Node.js 20 или новее.
npm install
npm test
npm run typecheck
npm run buildНачальный транспорт — stdio, поскольку и Claude Code, и Codex поддерживают локальные MCP-серверы на stdio. Streamable HTTP можно добавить без изменения API политик.
Принцип проектирования
Публичное обещание намеренно уже, чем «этот MCP помещает вашего кодинг-агента в песочницу». Он централизует политики. Клиентские адаптеры применяют эту политику везде, где клиент предоставляет надёжный механизм перехвата; в противном случае результат остаётся рекомендательным и его следует сочетать со встроенными средствами песочницы и контроля одобрений клиента.
Источники
Дизайн совместимости был проверен по актуальной официальной документации и исходному коду на 2026-08-27:
Anthropic Claude Code MCP: https://docs.claude.com/en/docs/claude-code/mcp
Хуки Anthropic Claude Code: https://github.com/anthropics/claude-code/blob/main/plugins/plugin-dev/skills/hook-development/SKILL.md
OpenAI Codex: https://github.com/openai/codex
Реализация конфигурации MCP в Codex: https://github.com/openai/codex/blob/main/codex-rs/config/src/mcp_types.rs
MCP TypeScript SDK: https://github.com/modelcontextprotocol/typescript-sdk/blob/v1.29.0/docs/server.md
Лицензия
MIT
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Tools
Related MCP Servers
- AlicenseAqualityDmaintenanceRuntime policy enforcement for AI agents. Evaluate every agent action against your organization's policies before execution, with observe and enforce modes.11MIT

Vaikora Guard MCPofficial
AlicenseNot gradedqualityDmaintenanceEnforces deterministic policies on AI agent tool calls, evaluating actions against compliance modules (SOC 2, HIPAA, GDPR, etc.) and returning ALLOW, BLOCK, or CONSTRAIN decisions with an audit trail.MIT- FlicenseNot gradedqualityBmaintenanceEnables AI coding agents to evaluate actions against team-defined policies, record decisions, and obtain human approvals for potentially risky operations.1651
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.
Related MCP Connectors
Git-native policy layer for AI agents: check_action verdicts against rules approved via PR.
Runtime permission, approval, and audit layer for AI agent tool execution.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ultus-net/workflow-guard-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server