McpVanguard (provnai/McpVanguard) is an MCP server listed on the M8ven Trust Index. It scores 73 out of 100, grade C. It declares 6 tools. No publisher has claimed this listing.

C
Limited view
73/100

McpVanguard

A security proxy and active firewall for the Model Context Protocol that protects host systems from malicious intent, prompt injection, and data exfiltration. It acts as an interception layer between AI agents and tools, providing real-time verification and multi-layered defense mechanisms.

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

provnai

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 7 credentials: VANGUARD_API_KEY, VANGUARD_FINGERPRINT_SECRET, VANGUARD_REVIEW_WEBHOOK_SECRET, VANGUARD_OPENAI_API_KEY, VANGUARD_MINIMAX_API_KEY, VANGUARD_SEMANTIC_CUSTOM_KEY, VANGUARD_VEX_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configVANGUARD_PYTHON
configVIRTUAL_ENV
configDEMO_POISONED_METADATA
configVANGUARD_TOOL_CAPABILITIES_JSON
configVANGUARD_TRUSTED_SERVER_SIGNERS_FILE
configVANGUARD_TRUSTED_SERVER_SIGNER
🔐 secretVANGUARD_API_KEYexport ="replace-with-a-long-random-secret"
configVANGUARD_ALLOWED_IPS
configVANGUARD_ALLOWED_ORIGINS
configVANGUARD_REQUIRE_ORIGIN
configVANGUARD_EXPECTED_BEARER_ISSUER
configVANGUARD_EXPECTED_BEARER_AUDIENCE
configVANGUARD_REQUIRED_BEARER_CLAIMS
configVANGUARD_REQUIRED_BEARER_SCOPES
configVANGUARD_BEARER_SCOPE_MATCH
configVANGUARD_BEARER_CLAIM_POLICY
configVANGUARD_BIND_STREAMABLE_SESSIONS
configVANGUARD_TRUST_PROXY_HEADERS
configVANGUARD_TRUSTED_PROXY_IPS
configVANGUARD_MAX_CONCURRENT_SSE
configVANGUARD_MAX_GLOBAL_CONNECTIONS
configVANGUARD_SSE_RATE_LIMIT
configVANGUARD_SSE_MAX_BODY_BYTES
configVANGUARD_LOG_FILE
configVANGUARD_AUDIT_FORMAT
🔐 secretVANGUARD_FINGERPRINT_SECRET
configVANGUARD_MAX_STREAMABLE_SESSIONS
configVANGUARD_SSE_HEARTBEAT_SECS
configVANGUARD_JWKS_CACHE_TTL_SECS
configVANGUARD_AUTH_MODE
configVANGUARD_JWKS_FILE
configVANGUARD_JWKS_JSON
configVANGUARD_JWKS_URL
configVANGUARD_OAUTH_DISCOVERY_URL
configVANGUARD_AUTH_CLOCK_SKEW_SECS
configVANGUARD_DISCOVERY_CACHE_TTL_SECS
configVANGUARD_JWKS_REFRESH_ON_KID_MISS
configVANGUARD_OAUTH_HTTP_TIMEOUT_SECS
configVANGUARD_BEHAVIORAL_ENABLED
configVANGUARD_BEH_READ_LIMIT
configVANGUARD_BEH_LIST_LIMIT
configVANGUARD_BEH_NETWORK_LIMIT
configVANGUARD_BEH_FLOOD_LIMIT
configVANGUARD_BEH_PAYLOAD_LIMIT
configVANGUARD_STRICT_REDIS
configVANGUARD_BLOCK_ENUMERATION
configVANGUARD_ENTROPY_HIGH
configVANGUARD_ENTROPY_BLOCK
configVANGUARD_ENTROPY_PENALTY
configVANGUARD_REDIS_URL
configVANGUARD_SENSITIVE_PATHS
configVANGUARD_PROFILE
configVANGUARD_TRUSTED_CAPABILITY_SIGNERS_FILE
configVANGUARD_TRUSTED_CAPABILITY_SIGNER
configVANGUARD_MCP_PROTOCOL_PROFILE
configVANGUARD_SEMANTIC_ENABLED
configVANGUARD_OLLAMA_URLOllama Local execution, no API key required
configVANGUARD_OLLAMA_MODEL
configVANGUARD_FLEET_URL
configVANGUARD_FLEET_SYNC_INTERVAL
configVANGUARD_ALLOW_UNSIGNED_FLEET
configVANGUARD_MANAGEMENT_PLANE_MODE
configVANGUARD_REDACT_REVIEW_EXCERPTS
configVANGUARD_REVIEW_WEBHOOK_URL
🔐 secretVANGUARD_REVIEW_WEBHOOK_SECRET
configVANGUARD_TRUSTED_PROVENANCE_SIGNERS_FILE
configVANGUARD_TRUSTED_PROVENANCE_SIGNER
configVANGUARD_DISABLE_UVLOOP
configNIXPACKS
configVANGUARD_LOG_LEVEL
configVANGUARD_RULES_DIR
configVANGUARD_MANAGEMENT_TOOLS_ENABLED
configVANGUARD_BLOCK_THRESHOLD
configVANGUARD_WARN_THRESHOLD
configVANGUARD_MODE
configVANGUARD_EXPOSE_BLOCK_REASON
configVANGUARD_MAX_STRING_LEN
configVANGUARD_RECEIPTS_ENABLED
configVANGUARD_RECEIPT_LOG_FILE
configVANGUARD_RECEIPT_TRANSPORT
configVANGUARD_RECEIPT_REDACTION_MODE
configVANGUARD_RECEIPT_CHAIN_ENABLED
configVANGUARD_RECEIPT_EXTENSIONS_ENABLED
configVANGUARD_METADATA_INSPECTION_ENABLED
configVANGUARD_METADATA_POLICY
configVANGUARD_SERVER_MANIFEST_FILE
configVANGUARD_SERVER_MANIFEST_SIGNATURE_FILE
configVANGUARD_SERVER_MANIFEST_POLICY
configVANGUARD_SERVER_TRUST_POLICY
configVANGUARD_SERVER_MANIFEST_HASH_EXECUTABLE
configVANGUARD_SERVER_PROVENANCE_FILE
configVANGUARD_SERVER_PROVENANCE_SIGNATURE_FILE
configVANGUARD_SERVER_PROVENANCE_POLICY
configVANGUARD_REQUIRED_PROVENANCE_BUILDERS
configVANGUARD_SERVER_ARTIFACT_SIGNATURE_FILE
configVANGUARD_SERVER_ARTIFACT_POLICY
configVANGUARD_ALLOWED_SUPPLIER_IDS
configVANGUARD_SERVER_SIGSTORE_BUNDLE_FILE
configVANGUARD_SERVER_SIGSTORE_POLICY
configVANGUARD_ALLOWED_SIGSTORE_CERT_FINGERPRINTS
configVANGUARD_ALLOWED_SIGSTORE_IDENTITIES
configVANGUARD_ALLOWED_SIGSTORE_OIDC_ISSUERS
configVANGUARD_ALLOWED_SIGSTORE_BUILD_SIGNER_URIS
configVANGUARD_ALLOWED_SIGSTORE_SOURCE_REPOSITORIES
configVANGUARD_ALLOWED_SIGSTORE_SOURCE_REFS
configVANGUARD_ALLOWED_SIGSTORE_SOURCE_DIGESTS
configVANGUARD_ALLOWED_SIGSTORE_BUILD_TRIGGERS
configVANGUARD_ALLOWED_SIGSTORE_TLOG_KEY_IDS
configVANGUARD_ALLOWED_SIGSTORE_GITHUB_REPOSITORIES
configVANGUARD_ALLOWED_SIGSTORE_GITHUB_REFS
configVANGUARD_ALLOWED_SIGSTORE_GITHUB_SHAS
configVANGUARD_ALLOWED_SIGSTORE_GITHUB_TRIGGERS
configVANGUARD_ALLOWED_SIGSTORE_GITHUB_WORKFLOW_NAMES
configVANGUARD_SIGSTORE_TLOG_POLICY
configVANGUARD_CAPABILITY_MANIFEST_FILE
configVANGUARD_CAPABILITY_MANIFEST_SIGNATURE_FILE
configVANGUARD_CAPABILITY_TRUST_POLICY
configVANGUARD_CAPABILITY_MANIFEST_POLICY
configVANGUARD_AUTH_WARNING_TOOL_POLICY
configVANGUARD_DESTRUCTIVE_TOOL_AUTH_POLICY
configVANGUARD_REQUIRED_DESTRUCTIVE_ROLES
configVANGUARD_REQUIRED_DESTRUCTIVE_SCOPES
configVANGUARD_MAX_TOOL_CALLS_PER_MINUTE
configVANGUARD_MAX_RISKY_CALLS_PER_SESSION
configVANGUARD_MAX_BLOCKED_ATTEMPTS_PER_SESSION
configVANGUARD_ALLOWED_SERVER_COMMANDSIf you operate a hosted template or shared gateway, set to restrict which upstream MCP server executables McpVanguard may spawn.
configVANGUARD_SEMANTIC_FAIL_CLOSED
configVANGUARD_DEFAULT_POLICY
configVANGUARD_REGEX_ENGINE
🔐 secretVANGUARD_OPENAI_API_KEYOpenAI Default model: gpt-4o-mini
configVANGUARD_OPENAI_MODEL
configVANGUARD_OPENAI_BASE_URL
🔐 secretVANGUARD_MINIMAX_API_KEY
configVANGUARD_MINIMAX_MODEL
configVANGUARD_MINIMAX_BASE_URL
🔐 secretVANGUARD_SEMANTIC_CUSTOM_KEYUniversal Custom , related custom vars Fast inference providers such as Groq or DeepSeek
configVANGUARD_SEMANTIC_CUSTOM_MODEL
configVANGUARD_SEMANTIC_CUSTOM_URL
configVANGUARD_SEMANTIC_THRESHOLD_BLOCK
configVANGUARD_SEMANTIC_THRESHOLD_WARN
configVANGUARD_SEMANTIC_TIMEOUT_SECS
configVANGUARD_SESSION_TTL
configVANGUARD_TRUSTED_SIGNERS_FILE
configVANGUARD_TRUSTED_SIGNER
configVANGUARD_TRUSTED_SUPPLIER_SIGNERS_FILE
configVANGUARD_TRUSTED_SUPPLIER_SIGNER
configVANGUARD_VEX_URL
configVANGUARD_VEX_API_URL
🔐 secretVANGUARD_VEX_KEY
configVANGUARD_VEX_JWT
configVANGUARD_VEX_AGENT_ID
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

6/6 tools missing one or more hints — handle_call_tool (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_dir (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); read_file (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +3 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool handlers catch errors

Only 0/1 tool handlers wrap calls in try/catch (0%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/provnai/mcpvanguard)](https://m8ven.ai/mcp/provnai/mcpvanguard)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: dfb2162d73c1c8ad89a80c2e4a4811f5770a1f12
code hash: 58d6ad659212dd248fe33522e3e61ea0c748a70d9c12f2cf1274c80ec6491d8b
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client