Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. MCP Guardian
MCP Guardian logo
Health: ActiveRecent health check succeeded.Last checked 9/11/2026, 2:00:54 PM

MCP Guardian

User RatingsBe the first to rate and review this MCP server!
View Repository3 GitHub StarsTotal stargazers on GitHub for the source repository (3 stars).Visit Website
securitygovernancemcpmonitoring

Security and governance proxy for MCP with policy enforcement, cost tracking, health monitoring, and threat protections.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for rudraneel93/mcp-guardian, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Tool Schemas (1) Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

MCP Guardian sits between an AI assistant and its MCP tools to enforce YAML-configured security and governance policies. It supports blocklists, rate limits, token budgets, payload normalization, shell AST analysis, circuit breakers, and live JSON-RPC health probes. Use it when MCP traffic needs centralized controls, auditing, authentication, or operational monitoring.

Use cases

β€’Enforce blocklists, rate limits, and token budgets
β€’Monitor MCP server health with JSON-RPC probes
β€’Analyze shell payloads with semantic AST checks
β€’Authenticate users with OAuth 2.1/OIDC and RBAC
β€’Inspect operations through the web dashboard and Prometheus metrics

Key features

β€’YAML-configurable policy enforcement
β€’Token cost tracking with tiktoken
β€’Live JSON-RPC server health monitoring
β€’OAuth 2.1/OIDC authentication with RBAC
β€’Payload normalization and shell AST analysis
β€’mTLS, circuit breakers, dashboard, and Prometheus metrics

Capabilities & Tool Schemas (1) ~56 tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server β€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Guardian.

Audit

[`persistCallRecord`](src/utils/call-record-cost.ts) β†’ async [`audit-write-queue`](src/database/audit-write-queue.ts) β†’ SQLite; blocks also emit [`StructuredLogger.logBlocked`](src/utils/structured-logger.ts) for SIEM.

Documentation Overview

MCP Guardian

A safety layer between your AI assistant and the tools it uses.

npm version npm downloads Socket Badge Website mcp-guardian MCP server TypeScript MCP SDK License CI

Version 4.1.8 Β· Website Β· npm Β· Install & troubleshooting Β· Changelog

What's new in 4.1.8

  • Incident policy workflow β€” Enterprise AI investigation drawer can generate, preview, accept, or reject blocking rules from incidents
  • npm publish hardening β€” ordered publish script with registry dep resolution checks and clean-install verification before server goes live
  • Dashboard stability β€” fix React hooks ordering in Security/Health panels that caused error #310 on load

What's new in 4.1.7

  • Active Rules controls β€” Security β†’ Policy now includes list/search, soft disable/enable, and hard delete operations synced to YAML
  • Policy runtime semantics β€” enabled: false is honored across rule strategies with backward-compatible defaults
  • Policy mutation APIs β€” cloud + local dashboard endpoints for list/toggle/delete with updated README guidance

What's new in 4.1.6

  • mcp-guardian start β€” one command for proxy + web dashboard on port 4000 (local dev defaults)
  • mcp-guardian setup β€” one-shot install for git clones (pnpm install, build, dashboard SPA)
  • npm tarball β€” prebuilt dashboard UI (deploy/dashboard-spa/out/) built at publish time
  • Install guide β€” expanded troubleshooting in README and docs/INSTALL.md

What's new in 4.1.5

  • npm install β€” fixes broken @mcp-guardian/server@4.1.4 registry manifest (workspace: deps). Use 4.1.5+.

What's new in 4.1.4

  • mcp-guardian onboard from global npm β€” resolves the installed package root (not cwd); writes guardian-configs/ under your current directory; ships scripts/guardian-proxy.sh and policy-audit.yaml in the npm tarball

What's new in 4.1.3

npm install fix β€” registry manifest now matches published tarballs (^4.1.3 semver deps, not workspace:). Use @mcp-guardian/server@4.1.3 or later. Publish via ./scripts/publish-npm-all.sh (server/CLI ship from .tgz so metadata stays correct).

What's new in 4.1.1

npm install hygiene β€” fixes supply-chain scanner findings from 4.1.0:

  • Published tarballs no longer include postinstall or other lifecycle scripts
  • workspace: dependencies are rewritten to semver (^4.1.1) at pack time
  • Publish all packages via ./scripts/publish-npm-all.sh (core β†’ plugin-sdk β†’ server β†’ cli)

What's new in 4.1.0

Industry roadmap plan compliance β€” runtime verification and dashboard wiring for all eleven fleet-wide modules (A1–C5, B1–B3):

  • guardian roadmap audit β€” CLI + GET /api/agentic/plan-compliance/audit verify every shipped module; exit 0 when production-ready
  • Dashboard Agentic AI panels β€” PlanCompliance, Reputation, ZeroTrust, FederatedLearning, Observatory mesh sync, SandboxWizard captured-traffic scorecard, ChainGraph (A1)
  • Protection home strip β€” roadmap compliance score on the main Protection tab with link to Agentic AI
  • A1 ONNX graph path β€” optional fleet chain classifier via GUARDIAN_FLEET_GRAPH_ONNX_MODEL
  • B3 MPC-lite masking β€” pairwise-masked federated gradients (GUARDIAN_FEDERATED_MPC)
  • B2/B1 mesh relays β€” observatory and reputation mesh publish/pull; dev stub via GUARDIAN_OBSERVATORY_STUB
  • Docs & env β€” guardian roadmap * commands documented; production env vars in .env.example

Run guardian roadmap audit --json or open Agentic AI β†’ Overview in the dashboard to confirm 100% compliance.

What's new in 4.0.0

Industry-standard MCP protection β€” Guardian moves from per-call filtering to fleet-wide, cross-agent security:

  • MTX v1 β€” open threat exchange format (@mcp-guardian/mtx) + cloud hub
  • Guardian Certified MCP β€” HMAC attestation, persistent registry, verification API
  • Multi-step attack chains β€” collusion detector + session-chain graph with proxy enforcement
  • Capability graph & intent binding β€” tool/resource graph and session intent allowlists
  • Agent reputation ledger β€” persistent scores with proxy enforcement
  • Dynamic sandbox tiers β€” shadow / redact / allow with RL-ready persistence
  • Protocol fuzzer β€” expanded corpus with real block validation and cert gates
  • Policy simulator β€” /api/policy/simulate + ab_test_policy MCP tool
  • Incident playbooks & AI investigator β€” webhook/isolate executors; Threat Lab–linked investigations
  • Compliance evidence runner β€” live policy + audit wired to SOC2/HIPAA/PCI/FedRAMP/ISO mappings
  • guardian-bench β€” mcp-guardian bench CLI + public leaderboard

See CHANGELOG.md for 3.4.1 production hardening (JWKS refresh, payload limits, SIEM on all block paths, audit retention).

Roadmap (shipped in 4.0): Semantic policy translator with approval flows, config provenance chain, STRIDE/LINDDUN threat modeling, behavioral biometrics, cross-MCP attack chains with SIEM export, digital twin sandbox, zero-trust SPIFFE scoring, decentralized reputation network, ecosystem observatory, insurance risk quantification + PDF export, and federated threat detection β€” docs/AGENTIC_ROADMAP.md.

Fleet mandate for CISO buyers

Guardian v4 is designed as a fleet-wide control plane, not a single-proxy filter:

  • Mandatory policy provenance β€” every YAML change is hash-chained, signed, and exportable to SIEM/auditors
  • Human-in-the-loop policy approval β€” NL drafts must pass simulation + explicit approval before apply
  • Cross-agent attack chain detection β€” session graphs span servers; alerts export as CEF for Splunk/Datadog
  • SPIFFE/mTLS identity β€” zero-trust composite scores include workload identity from SPIFFE SVIDs
  • Cloud observatory + reputation mesh β€” anonymized fleet telemetry and server reputation consensus via MCP Guardian Cloud
  • Insurance-ready risk reports β€” ALE quantification with underwriter PDF export for cyber insurance workflows

What problem does this solve?

Modern AI assistants (Claude, Cursor, Cline, and others) can connect to tools β€” read files, run commands, query databases, post to Slack, and more. Those connections often use a standard called MCP (Model Context Protocol).

That power is useful, but risky:

  • The AI might read files it should not see.
  • It might run shell commands or delete data by mistake or because of a malicious prompt.
  • Secrets can leak through tool arguments.
  • API costs can spike without you noticing.

MCP Guardian sits in the middle. Every tool request goes through Guardian first. Guardian checks your rules, blocks bad requests, logs what happened, and can show you a live dashboard β€” before anything reaches your real tools.

Code
Your AI assistant
       β”‚
       β–Ό
  MCP Guardian  ← reads your rules, blocks bad calls, keeps a log
       β”‚
       β–Ό
  Your real tools (files, GitHub, database, …)

How it works (step by step)

  1. You install Guardian and point it at your existing MCP setup (or run mcp-guardian onboard to do this automatically).
  2. Guardian wraps your tool servers so the AI talks to Guardian instead of talking to them directly.
  3. When the AI tries to use a tool, Guardian receives the request first.
  4. Guardian compares the request to your policy (a simple rules file you control).
  5. If the request is allowed, Guardian forwards it to the real tool and returns the result.
  6. If the request breaks a rule, Guardian blocks it and tells the AI it was denied β€” the real tool never runs.
  7. Every allow and block is saved to a local database so you can review history and see charts on the dashboard.

You stay in control: Guardian does not silently change your rules unless you approve it (for example when reviewing Threat Lab suggestions).


Architecture

This section shows how MCP Guardian is wired together: what runs where, how a tool call flows through governance, and how optional Pro pipelines connect to the proxy.

In this section: System overview Β· Tool call path Β· Transports Β· Agentic AI Β· Dashboard Β· Pro pipelines Β· Learning loop

System overview

When you run mcp-guardian start or pnpm dashboard:proxy, one Node process typically hosts the policy proxy, the dashboard API, and (optionally) agentic services. All components share the same audit database (MCP_GUARDIAN_DB_PATH, default ~/.mcp-guardian/history.db).

mermaid
flowchart TB
  subgraph clients [AI clients]
    Cursor[Cursor / Cline / Claude]
  end

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • MCP Audit logoMCP Audit

    Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or server.

    πŸ”’ Security3 views
    Compare vs MCP Audit β†’
  • Authmcp Gateway logoAuthmcp Gateway

    glama 🐍 ☁️ 🏠 🍎 πŸͺŸ 🐧 - Auth proxy for MCP servers: OAuth2 + DCR, JWT, RBAC, rate limiting, multi-server aggregation, and monitoring dashboard.

    πŸ”’ Security3 views
    Compare vs Authmcp Gateway β†’
  • Platform logoPlatform

    Governance proxy for MCP servers. Wraps any upstream server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.

    πŸ”’ Security3 views
    Compare vs Platform β†’
  • Aegis logoAegis

    Policy-based governance for AI agent tool calls. YAML policies, approval gates, risk assessment, and audit logging. Cross-platform: LangChain, OpenAI, Anthropic, MCP.

    πŸ”’ Security4 views
    Compare vs Aegis β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
3
Stargazers on the source repository.
Last commit
3mo ago
Most recent push to the default branch.
Tools exposed
1
Callable tools this server registers over MCP.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Guardian

It provides a safety and governance layer between an AI assistant and the MCP tools it uses.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Guardian AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/rudraneel93-mcp-guardian?style=directory)](https://allmcps.com/mcp/rudraneel93-mcp-guardian)
HTML Embed
<a href="https://allmcps.com/mcp/rudraneel93-mcp-guardian"><img src="https://allmcps.com/api/badge/rudraneel93-mcp-guardian?style=directory" alt="MCP Guardian on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
AuthOAuth
LicenseMIT
Last updatedAug 10, 2026
3/7 checks healthy over the last 32d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars3
GitHub Star CountTotal stargazers on GitHub representing community popularity (3 stars).
Last commit3mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Jun 7, 2026
48Quality signal: Fair Β· 48/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools24/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to MCP Guardian β†’Install in Claude DesktopInstall in CursorInstall in VS Code