Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Bouncer Gates
B
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Bouncer Gates

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

Stops secrets, cross-tenant queries and unsafe migrations before they merge.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for bouncer-gates, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

bouncer-gates

Five checks that stop the expensive mistakes before they merge, whether a person or an agent wrote the code.

Hardcoded secrets. Database queries that leak one customer's data to another. Float maths on money. Migrations that break the running app. Docs that link to files which no longer exist.

Agents write most new code now, and they make exactly these mistakes: a key pasted in to make a test pass, a query with no tenant filter because the prompt never mentioned tenants. bouncer-gates runs inside Claude Code and Cursor, so the agent hears about it in the same turn it wrote it, and again in CI so nothing gets through.

Try it on any repository in ten seconds:

Terminal
npx bouncer-gates

Or paste some code into the playground and watch the same checks run on it.


Quick start

Terminal
npx bouncer-gates --init          # writes bouncer-gates.config.json, reads your Prisma schema if you have one
npx bouncer-gates --init-agents   # wires the same checks into Claude Code and Cursor for this repo
npx bouncer-gates                 # runs every check and prints what it found

Add it to GitHub Actions:

yaml
steps:
  - uses: actions/checkout@v4
    with:
      fetch-depth: 0             # needed so the migration check can see what is new
  - uses: ajeermahmood/bouncer-gates@v0
    with:
      version: "0.5.0"

That is the whole setup. Everything below is detail.

In the editor, with the agent

--init-agents commits two things into the repository: an MCP server the agent can call, and a hook that scans every file the agent writes. When a file has a blocking finding, the agent sees the file, the line, what is wrong and what to do instead, in the same turn:

Code
x src/orders.ts:12  scope/unscoped-query
  "order" is tenant-owned, but nothing in this query mentions "tenantId", so it returns rows from every tenant.
  fix: Add tenantId to the where clause, or go through a tenant-scoped client.

Any other MCP client can run npx -y bouncer-gates --mcp, and any post-edit hook can pipe its event to npx -y bouncer-gates --hook. How it works, and what it will not do.

What it checks

CheckCatchesExample of what it stops
secretsPasswords, API keys and private keys committed to the repo, plus a few risky shapes like curl ... | shconst apiKey = "sk_live_...", a committed .env with a real password
scopeQueries on multi-tenant tables that are not limited to one tenantprisma.order.findMany({ where: { status: "paid" } }) with no tenantId
moneyCurrency handled as floats, or * 100 assuming every currency has two decimalsMath.round(parseFloat(price) * 100)
migration-safetySQL migrations that break the version of the app still running during a deployALTER TABLE orders DROP COLUMN total while old code still reads it
doc-linksMarkdown links to files that do not exist[setup](docs/setup.md) after the file moved

Each check exists because of a real, expensive bug. None is a style opinion. The gate reference explains every rule with a bad example and a fixed one.

When it finds something

Every finding names the file, the line, what is wrong and what to do instead:

Code
  FAIL  scope

    x src/orders.ts:2  scope/unscoped-query
      "order" is tenant-owned, but nothing in this query mentions "tenantId", so it returns rows from every tenant.
      fix: Add tenantId to the where clause, or go through a tenant-scoped client.

You have three options, in this order:

  1. Fix it. Usually the right answer.
  2. Explain why it is fine. Put a comment on the line, or the line above it, with a reason. The reason is required; a bare marker does nothing.
    server.ts
    // bouncer-gates-ok(scope): nightly revenue report spans every tenant by design
    const all = await prisma.order.findMany();
    
  3. Record existing problems so only new ones block. On a codebase that already has findings, run this once and commit the file it writes:
    Terminal
    npx bouncer-gates --baseline-write
    
    Old findings stop blocking. Anything new still does. The file is readable, and the count in it should only ever go down.

Configuration

bouncer-gates --init writes this for you. Edit it by hand any time.

config.json
{
  "exclude": ["fixtures/**"],
  "scope": {
    "models": ["order", "customer"],
    "tables": ["orders", "customers"],
    "column": "tenantId",
    "clients": ["prisma"],
    "rawAccessor": "raw"
  },
  "doc-links": { "repoUrl": "https://github.com/you/your-repo" }
}
  • exclude: files not to scan at all. The run prints how many files each pattern removed, every time, so the list cannot grow quietly.
  • scope.models / tables: the models and tables that belong to a tenant. --init fills these from any model in your Prisma schema that has a tenantId field.
  • scope.clients: plain client names, like prisma, whose queries should be checked for the tenant column. Use this when you do not have a scoped wrapper.
  • scope.rawAccessor: if you do have a scoped wrapper, this is the name of the raw client it hides, like db.raw. Reaching for it gets flagged.
  • doc-links.repoUrl: lets absolute links back to your own repository be checked as file paths too.

Without a scope section, the scope check reports skipped, not passed.

All the commands

Terminal
npx bouncer-gates                        # every check, whole repository
npx bouncer-gates --init                 # write a starter config
npx bouncer-gates --init-agents          # wire the gates into Claude Code and Cursor
npx bouncer-gates --mcp                  # serve the gates over MCP, for any agentic editor
npx bouncer-gates --hook                 # scan the file named by a hook event on stdin
npx bouncer-gates --changed              # only files this branch touched
npx bouncer-gates --only scope,money     # just some checks
npx bouncer-gates --explain scope        # what a check does and how to excuse a case
npx bouncer-gates --baseline-write       # record existing findings
npx bouncer-gates --json                 # machine-readable output
npx bouncer-gates --sarif                # for the GitHub Security tab

Exit code 0 means clean, 1 means something blocked, 2 means the tool itself could not run (bad flag, broken config, not a git repository). CI treats 1 and 2 differently on purpose: a broken tool should not look like a codebase full of problems.

What it does not do

Honest limits, so nobody trusts it further than it deserves:

  • It matches shapes in text. It does not understand your code. A tenant filter built in a helper the check cannot see will be reported, and the comment above is the fix.
  • The money and scope checks only read JavaScript and TypeScript.
  • The migration check only reads .sql files. Migrations written in JavaScript or TypeScript are not checked.
  • Secrets split across lines, or with no recognisable prefix, are not found. For deep history scanning use gitleaks or trufflehog; this is the cheap guard on the door, not the audit.
  • A query inside prisma.$transaction(async (tx) => ...) uses a client the check cannot follow.

Every rule's blind spots are listed in the gate reference.

Words used here

  • Gate or check: one of the five things it looks for.
  • Finding: one problem it reports, with a file and line.
  • Blocking: a finding that makes the run exit 1. Warnings do not.
  • Baseline: the file that records findings you have chosen to live with for now, so only new ones block.
  • Acknowledge or excuse: the bouncer-gates-ok comment that says a specific line is fine, and why.

Telemetry

One anonymous ping a day: a random id, the version, the runtime, the OS and the Node major. Nothing about your code, ever. BOUNCER_TELEMETRY=0 turns it off. Everything it sends.

More

  • Inside the editor: the MCP server and the hook, what the agent sees, other editors
  • Gate reference: every rule, a bad and a good example, what it misses
  • Rolling it out on an existing codebase
  • Design notes: why it never fails open, why findings never quote the secret, the false-positive story, and the speed work
  • Architecture: gates are pure functions, which is why the same code runs in the CLI, in a Cloudflare Worker and in your browser
  • Deployment: the playground, the API and npm
  • Contributing: adding a gate, and how to decide whether something should be one

Development

Terminal
npm install
npm test                        # unit tests
npm run check                   # bouncer-gates on itself
npm run bench -- ../some-repo   # measure against a real codebase
npm run dev                     # the playground site

Licence

MIT. Take any of it.

Built by Ajeer Mohammed. The rules come from running checks like these across eight production repositories, on a multi-tenant platform where missing one meant a merchant seeing another merchant's orders.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • I
    Ida Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • K
    Kody

    Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.

    πŸ”’ Security1 views
    Compare vs Kody β†’
  • U
    Ui Ux Suite

    UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.

    πŸ”’ Security1 views
    Compare vs Ui Ux Suite β†’
  • A
    Agent Security Scanner MCP

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    πŸ”’ Security1 views
    Compare vs Agent Security Scanner MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Bouncer Gates

We don't have a confirmed install command for bouncer-gates yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/ajeermahmood/bouncer-gates) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewBouncer Gates AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/bouncer-gates?style=directory)](https://allmcps.com/mcp/bouncer-gates)
HTML Embed
<a href="https://allmcps.com/mcp/bouncer-gates"><img src="https://allmcps.com/api/badge/bouncer-gates?style=directory" alt="Bouncer Gates on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Bouncer Gates β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients