πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All tools
betaModel Context Protocol Guard

MCP Guard

Static audit of your MCP server configuration.

In the wildβ€” MCP Guard runsβ€” Issues surfacedβ€” CountriesΒ· opt-in only

The problem

MCP gives agents access to tools, files, and APIs β€” and most configs ship with plaintext tokens, auto-installed remote servers, and a filesystem server rooted at your home directory. One bad config line is a foothold.

What it does

Paste your claude_desktop_config.json or mcp.json and get a scored audit: plaintext secrets, unpinned remote installs (npx -y), shell pipes, and over-broad filesystem roots β€” each with a concrete fix. The config never leaves the request.

Capabilities

  • Detects plaintext secrets embedded in server env
  • Flags unpinned remote installs (supply-chain risk)
  • Catches shell pipes / destructive command chains
  • Flags filesystem servers rooted at / or $HOME
  • Runs in the browser or as an npm package / CI gate

How you run it

Paste your config in the browser for a scored audit. Subscribers can install @playciso/mcpguard and fail CI on any high-severity finding.

Roadmap

  • Static config audit + scoring
  • In-browser audit form
  • npm package + CI gate
  • Runtime proxy: allow-lists + redaction
  • Tamper-evident audit log

FAQ

What is MCP governance?

MCP governance is the set of controls that keep AI agents’ use of Model Context Protocol (MCP) servers safe: an allowlist of approved servers, least-privilege scoping of the tools and data each exposes, authentication and secret handling, human approval for high-impact actions, and full logging of every tool call. It matters because an MCP server hands an agent real capability in your environment.

What does MCP Guard check?

MCP Guard statically audits an MCP server configuration for the things that make one risky β€” over-broad permissions and tool scopes, weak or missing authentication, and unnecessary exposure β€” and flags where it deviates from least-privilege governance.

Why do MCP servers need governance?

Because an MCP server exposes tools, data or actions an AI agent can call, and an agent processing untrusted content can be steered by prompt injection into misusing that access. Governing the server β€” least privilege, auth, approval gates, logging β€” bounds what a hijacked agent can actually do.

Included with any PlayCISO plan

MCP Guard runs inside PlayCISO for subscribers. The source stays private β€” no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.

MCP Guard β€” MCP Server Governance & Security Audit Β· PlayCISO