Validates agent tool calls against scope and security rules before execution, with signed, rule-specific traces for allow and deny decisions.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Toolgovern.
The toolgovern MCP server provides an MCP-facing entry point to toolgovern's policy validator. It is intended to sit before an agent tool call and decide whether that call may proceed. The validator examines the arguments supplied to the call rather than relying only on the tool name. For example, two calls made through a tool named bash can receive different decisions when one lists an allowed directory and another pipes a network download into a shell.
The policy model covers shell and process risks, filesystem boundaries, network egress, credentials and secrets, inherited permissions between agents, and optional information-flow labels. A denied call identifies the rule or rules responsible for the decision, rather than returning only a general security error.
A governed call is evaluated against a declared scope and, where applicable, the scope granted by a coordinator agent. Sub-agent permissions are constrained by the intersection of their requested scope and the coordinator's effective scope. These checks occur for each call.
The synchronous classifier contains 35 rules. Examples include destructive shell commands, pipe-to-shell patterns, path traversal, writes outside an allowed filesystem path, access to sensitive credential files, undeclared network destinations, private or metadata targets, and cross-agent scope violations. The npm package also provides an asynchronous DNS-related TG03 check for hostname arguments; it fails closed when the resolution check cannot establish that the destination is safe.
Decisions can be written as signed JSONL trace entries. Each entry records the decision, fired rule IDs, hashed arguments, declared scope, agent and session identifiers, and a link to the preceding trace entry. This makes the reason for a denial available for later review.
The repository publishes an npm package named toolgovern and a Python package named toolgovern-cli. Install the JavaScript package with npm install toolgovern; the npm CLI can be added with npm install --save-dev toolgovern-cli. For Python, install the independent port with pip install toolgovern-cli.
The library API shown in the project uses governTool, ScopeRegistry, and TraceWriter. A caller supplies an existing tool definition, the agent and session identifiers, a declared scope, and optionally a coordinator registry and trace destination. The provided material does not specify additional environment variables or MCP-client-specific configuration.
The toolgovern MCP server presents the CLI as one generic MCP tool rather than exposing a separate MCP tool for every policy rule. Its supported validation surface includes:
The classifier evaluates one call at a time and does not retain cross-call session state. Consequently, the TG06 high-risk tool-combination category and TG07 modified-retry detection are not implemented in the stated v0.1 rule pack. Information-flow control is opt-in and requires a caller-declared policy; it does not infer labels automatically or perform cross-call taint tracking.
The project supplies both npm and Python distributions, described as independent implementations of the same core classifier. The README excerpt does not document a client-specific setup, required environment variables, or an MCP transport configuration, so those details should be verified before deployment.
Factual signals from GitHub, npm, and our automated checks โ not a rating.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/toolgovern)<a href="https://allmcps.com/mcp/toolgovern"><img src="https://allmcps.com/api/badge/toolgovern?style=directory" alt="Toolgovern on AllMCPs" /></a>