The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the MCP Dandan listing page.
MCP-Dandan
MCP-Dandan is an integrated monitoring service that observes MCP (Model Context Protocol) communications and detects security threats in real time. It features a modern desktop UI built with Electron for easy monitoring and management.
MCP-Dandan has been featured and listed across MCP and AI security communities, open-source collections, and platforms:
https://github.com/user-attachments/assets/928686ab-a5aa-4486-8d8e-d4a9592adc3e
The server will start on http://127.0.0.1:8282 and the Electron desktop app will launch automatically.
Identifies potential command injection patterns in tool calls.
Monitors unauthorized file system access attempts.
Detects potential PII leakage with built-in rules and optional user-defined customization.
Identifies suspicious data transfer patterns.
Uses semantic analysis to detect misuse of MCP tools:
https://github.com/user-attachments/assets/3d6f2304-0a6b-492e-9f2d-bba76df98b4c
Input your MISTRAL_API_KEY to enable the Tools Poisoning Engine, and configure detection settings as needed.
https://github.com/user-attachments/assets/19bcbdfb-c893-468d-a8a6-1c7b70a1c7b7
Full Documentation
For detailed explanations and technical documentation, please refer to the
MCP-Dandan Wiki.Have questions or suggestions?
Please visit the Discussions tab.