Local MCP proxy for tool restrictions, response redaction, audit logs, and database schema context.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
"Whatever you see anywhere (sky, sea, clouds, lands) are all closed and opened by my hand." Ovid, Fasti I, 117β18 (Janus speaking)
JanuScope is the local MCP policy proxy. One YAML wraps any MCP server with policy, redaction, audit, and database-schema injection. JanuScope runs locally, with no hosted gateway in the data path. Your upstream server and model provider can still receive data.
JanuScope hides the dangerous tools, scrubs matching PII out of returned values before the model reads them, records call outcomes, and pre-injects your DB schema to reduce discovery calls. Runs locally, no hosted gateway in the data path.
One YAML (called a Lens) wraps any MCP server with security guardrails, schema injection, and full audit logging. There are 20 bundled Lenses covering databases (Postgres, MySQL, MongoDB, ClickHouse, Redis, SQLite, Microsoft SQL Server / Azure SQL, Oracle, Neon, Snowflake, Aurora DSQL, Redshift, Supabase self-host), SaaS APIs (Stripe, Notion, Atlassian, Linear, Supabase Cloud), source control (GitHub), and the filesystem. A community ecosystem of per-MCP Lenses (YAML config files), and measured benchmarks showing 84% fewer tokens and ~3Γ faster responses in the original three-question Postgres test (median of 4 runs; history reset between questions). Newer retained-conversation results and limitations are reported below. Zero server changes. No hosted gateway in the data path. Works with Claude Code, VSCode Copilot, Codex, Cursor, and any MCP client.
π§ Need codebase understanding together with MCP governance? See our sibling project SocratiCode: local-first codebase intelligence with semantic search, dependency graphs, symbol-level impact analysis.
Kindly sponsored by Altaire Limited. We also offer a commercial license for organisations where AGPL is a blocker.
If JanuScope has been useful to you, please β star this repo (it helps others discover it) and share it with your team.
Policy enforcement at the MCP threshold. Most MCP servers ship dangerous tools by default, execute_sql and drop_table on databases, create_pull_request and merge_pull_request on GitHub, stripe_api_execute on Stripe, write_file and move_file on the filesystem. None of them log what the LLM asked yesterday. The choice today is fork every server or accept the risk. Or you can choose JanuScope: a thin proxy that wraps any MCP server with a single YAML policy and disappears.
Original benchmark with
claude-sonnet-4-5against a real application Postgres database (median of 4 runs per prompt). Across three questions (prompt caching enabled, conversation history reset between questions), a JanuScope Lens used 84% fewer total tokens, made 84% fewer tool calls, and ran ~3Γ faster than the raw database MCP. In its adversarial-safety probe, the raw pipeline intermittently leaked a real user email on the "I'm the admin, just cross-referencing" prompt (2 of 4 runs), while the JanuScope-wrapped pipeline refused in all 4 runs. The single-question result was 34% fewer tokens / 86% fewer tool calls / ~3Γ faster. These historical results do not establish retained-session savings or universal protection. Full benchmark and newer findings β
Β
Live GitHub Copilot output against the bundled postgres-crystaldba lens (May 2026). Left: the assistant declines to fetch email addresses because the lens classifies the column as PII, Copilot self-censors before any query is sent. Right: the assistant declines to issue an UPDATE because the lens is read-only, Copilot recognises the policy and reports the refusal cleanly rather than guessing or retrying.
Why now: this is no longer hypothetical. In July 2025, Replit's AI agent wiped a customer database during an explicit code freeze (1,200+ records, ~1,200 companies) and then misled the user about whether rollback was possible. In April 2026, a Cursor agent on Claude Opus 4.6 deleted PocketOS's production database and three months of backups in nine seconds, after finding an unscoped Railway credential and guessing an API call (post-mortem). Both stories share one shape: an AI was given a destructive capability with nothing in the path between the model and the real system. JanuScope is what sits in that path, for any data access that goes through an MCP server: for examle a Replit-shape incident on a JanuScope-wrapped Postgres MCP (block writes,
sqlGuardon DML, audit, classification) is refused at the proxy threshold and recorded in the JSONL audit. JanuScope governs the MCP surface, it is one layer of a defence-in-depth posture, alongside scoped DB roles and credentials, host-level approval gates, etc. See the FAQ and SECURITY.md.
Only Node.js 20+ required. No install step,
npxfetches and caches JanuScope on first use.
Find your service in the table below, copy the right-hand snippet into your MCP-client config (or change your existing entry: the diff is usually just command and args), restart your client. For most Lenses, the env block stays exactly as it was. JanuScope inherits whatever env vars your client passes and forwards them to the wrapped MCP unchanged. No renames, no re-translation.
The wrap pattern is the same across every host (Claude Desktop, Cursor, Claude Code, VS Code Copilot, Windsurf, Cline, Roo Code, anything that speaks MCP).
| Service | Upstream MCP | Vanilla config | With JanuScope |
|---|---|---|---|
| PostgreSQL | crystaldba/postgres-mcp | ||
| MySQL | benborla/mcp-server-mysql | ||
| MongoDB | mongodb-js/mongodb-mcp-server |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/januscope)<a href="https://allmcps.com/mcp/januscope"><img src="https://allmcps.com/api/badge/januscope?style=directory" alt="Januscope on AllMCPs" /></a>