Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Status โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ’ป Developer Tools
  3. Toolgovern
Toolgovern logo
Health: ActiveRecent health check succeeded.Last checked 10/4/2026, 8:17:18 AM

Toolgovern

User RatingsBe the first to rate and review this MCP server!
View RepositoryVisit Website
agent-governancepolicy-validationsecuritydeveloper-tools

Validates agent tool calls against scope and security rules before execution, with signed, rule-specific traces for allow and deny decisions.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "toolgovern": {
      "command": "npx",
      "args": [
        "-y",
        "toolgovern-cli"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ’ป More in Developer Tools

Overview

The toolgovern MCP server exposes toolgovern's policy-validation CLI as a generic MCP tool for checking agent tool calls before execution. It evaluates actual arguments against declared network, filesystem, credential, agent, and information-flow scopes, then returns an allow or deny decision with fired rule IDs. Use it when an agent needs pre-execution controls for shell, filesystem, network, or credential-related operations. The underlying npm and Python packages also support signed JSONL traces for reviewing decisions.

Use cases

โ€ขValidate shell commands before execution
โ€ขEnforce filesystem and network scope for sub-agents
โ€ขBlock access to credentials and sensitive files
โ€ขRecord allow and deny decisions for audits

Key features

โ€ขArgument-aware policy classification
โ€ขFilesystem, network, credential, and agent scope checks
โ€ขOptional information-flow control
โ€ขRule-specific denial reasons
โ€ขSigned chained JSONL traces
โ€ขSynchronous 35-rule classifier

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Toolgovern.

Extracted Tool Capabilities
Argument-aware policy classification
Filesystem, network, credential, and agent scope checks
Optional information-flow control
Rule-specific denial reasons
Signed chained JSONL traces
Synchronous 35-rule classifier

How Toolgovern works

What toolgovern MCP server does

The toolgovern MCP server provides an MCP-facing entry point to toolgovern's policy validator. It is intended to sit before an agent tool call and decide whether that call may proceed. The validator examines the arguments supplied to the call rather than relying only on the tool name. For example, two calls made through a tool named bash can receive different decisions when one lists an allowed directory and another pipes a network download into a shell.

The policy model covers shell and process risks, filesystem boundaries, network egress, credentials and secrets, inherited permissions between agents, and optional information-flow labels. A denied call identifies the rule or rules responsible for the decision, rather than returning only a general security error.

How it works

A governed call is evaluated against a declared scope and, where applicable, the scope granted by a coordinator agent. Sub-agent permissions are constrained by the intersection of their requested scope and the coordinator's effective scope. These checks occur for each call.

The synchronous classifier contains 35 rules. Examples include destructive shell commands, pipe-to-shell patterns, path traversal, writes outside an allowed filesystem path, access to sensitive credential files, undeclared network destinations, private or metadata targets, and cross-agent scope violations. The npm package also provides an asynchronous DNS-related TG03 check for hostname arguments; it fails closed when the resolution check cannot establish that the destination is safe.

Decisions can be written as signed JSONL trace entries. Each entry records the decision, fired rule IDs, hashed arguments, declared scope, agent and session identifiers, and a link to the preceding trace entry. This makes the reason for a denial available for later review.

Setup and configuration

The repository publishes an npm package named toolgovern and a Python package named toolgovern-cli. Install the JavaScript package with npm install toolgovern; the npm CLI can be added with npm install --save-dev toolgovern-cli. For Python, install the independent port with pip install toolgovern-cli.

The library API shown in the project uses governTool, ScopeRegistry, and TraceWriter. A caller supplies an existing tool definition, the agent and session identifiers, a declared scope, and optionally a coordinator registry and trace destination. The provided material does not specify additional environment variables or MCP-client-specific configuration.

Tools and capabilities

The toolgovern MCP server presents the CLI as one generic MCP tool rather than exposing a separate MCP tool for every policy rule. Its supported validation surface includes:

  • Shell and process execution checks
  • Filesystem scope and path-escape checks
  • Network destination and egress checks
  • Credential and secret access checks
  • Coordinator and sub-agent scope inheritance
  • Optional information-flow control using declared labels
  • Rule-specific allow or deny results
  • Signed, chained JSONL decision traces

Limitations and notes

The classifier evaluates one call at a time and does not retain cross-call session state. Consequently, the TG06 high-risk tool-combination category and TG07 modified-retry detection are not implemented in the stated v0.1 rule pack. Information-flow control is opt-in and requires a caller-declared policy; it does not infer labels automatically or perform cross-call taint tracking.

The project supplies both npm and Python distributions, described as independent implementations of the same core classifier. The README excerpt does not document a client-specific setup, required environment variables, or an MCP transport configuration, so those details should be verified before deployment.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • Depwire logoDepwire

    Dependency graph + 15 MCP tools for AI coding assistants. Parses TypeScript, JavaScript, Python, Go, Rust, and C. Arc diagram visualization, health scoring, dead code detection, and temporal graph.

    ๐Ÿ’ป Developer Tools4 views
    Compare vs Depwire โ†’
  • Claude Task Master logoClaude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    ๐Ÿ’ป Developer Tools9 views
    Compare vs Claude Task Master โ†’
  • MCP Server Docker logoMCP Server Docker

    Integrate with Docker to manage containers, images, volumes, and networks.

    ๐Ÿ’ป Developer Tools3 views
    Compare vs MCP Server Docker โ†’
  • Roast My Design System logoRoast My Design System

    Audit your Design System and serve your Agent the rules that keep AI-written UI on-system.

    ๐Ÿ’ป Developer Tools4 views
    Compare vs Roast My Design System โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

npm downloads
180
Package downloads in the last 30 days.
Last commit
14d ago
Most recent push to the default branch.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Toolgovern

toolgovern is an MCP server that connects MCP clients to the toolgovern CLI policy-validation engine. Its main tool validates agent tool calls against shell, filesystem, network, credential, agent-scope, and optional information-flow rules before execution, returning an allow or deny decision with the rules that fired.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewToolgovern AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/toolgovern?style=directory)](https://allmcps.com/mcp/toolgovern)
HTML Embed
<a href="https://allmcps.com/mcp/toolgovern"><img src="https://allmcps.com/api/badge/toolgovern?style=directory" alt="Toolgovern on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ’ปDeveloper Tools
More technical detailsExpand โ–พ
TransportSTDIO
RuntimeNode.js
LicenseApache-2.0
Last updatedOct 6, 2026
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit14d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 25, 2026
npm downloads180/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
43Quality signal: Fair ยท 43/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity6/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 4d ago via OSV.dev ยท toolgovern-cli (npm)

โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ’ป Developer Tools โ†’Best MCP servers for Developers โ†’Alternatives to Toolgovern โ†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients