MCP Guard
Static audit of your MCP server configuration.
The problem
MCP gives agents access to tools, files, and APIs β and most configs ship with plaintext tokens, auto-installed remote servers, and a filesystem server rooted at your home directory. One bad config line is a foothold.
What it does
Paste your claude_desktop_config.json or mcp.json and get a scored audit: plaintext secrets, unpinned remote installs (npx -y), shell pipes, and over-broad filesystem roots β each with a concrete fix. The config never leaves the request.
Capabilities
- Detects plaintext secrets embedded in server env
- Flags unpinned remote installs (supply-chain risk)
- Catches shell pipes / destructive command chains
- Flags filesystem servers rooted at / or $HOME
- Runs in the browser or as an npm package / CI gate
How you run it
Paste your config in the browser for a scored audit. Subscribers can install @playciso/mcpguard and fail CI on any high-severity finding.
Roadmap
- Static config audit + scoring
- In-browser audit form
- npm package + CI gate
- Runtime proxy: allow-lists + redaction
- Tamper-evident audit log
Related tools
FAQ
What is MCP governance?
MCP governance is the set of controls that keep AI agentsβ use of Model Context Protocol (MCP) servers safe: an allowlist of approved servers, least-privilege scoping of the tools and data each exposes, authentication and secret handling, human approval for high-impact actions, and full logging of every tool call. It matters because an MCP server hands an agent real capability in your environment.
What does MCP Guard check?
MCP Guard statically audits an MCP server configuration for the things that make one risky β over-broad permissions and tool scopes, weak or missing authentication, and unnecessary exposure β and flags where it deviates from least-privilege governance.
Why do MCP servers need governance?
Because an MCP server exposes tools, data or actions an AI agent can call, and an agent processing untrusted content can be steered by prompt injection into misusing that access. Governing the server β least privilege, auth, approval gates, logging β bounds what a hijacked agent can actually do.
MCP Guard runs inside PlayCISO for subscribers. The source stays private β no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.