mcp-guardian (rudraneel93/mcp-guardian) is an MCP server listed on the M8ven Trust Index. It scores 0 out of 100, grade F. It declares 62 tools. No publisher has claimed this listing.
Security, cost, and health governance proxy for MCP infrastructure. Enforces YAML-configurable security policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features OAuth 2.1/OIDC with RBAC, web dashboard, payload normalization, semantic shell AST analysis, mTLS, and a formal STRIDE threat model.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
rudraneel93
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
scan_securityScan MCP server configurations for security vulnerabilities (CVEs, auth, typo-squatting, secrets)
audit_costsAudit token usage and estimate costs per MCP server
check_healthCheck health, latency, and reliability of MCP servers
full_reportGenerate a complete security, cost, and health report for all MCP servers
start_behavior_observationStart observing AI agent tool calls to learn usage patterns for policy generation
stop_behavior_observationStop the current observation window and finalize collected data
generate_policy_from_observationsGenerate a minimal-privilege YAML policy based on observed tool call patterns
suggest_policy_improvementsCompare observed behavior against current policy and suggest additions/removals
observation_statusGet current behavior observation status and summary
scan_prompt_injectionScan tool call arguments for prompt injection payloads targeting downstream AI agents
prompt_injection_reportGet prompt injection detection statistics
predict_threatsGenerate threat forecast for all configured MCP servers with 30/90/365-day projections
threat_forecast_for_serverDetailed threat forecast for a specific server with risk factors and preemptive hardening recommendations
preemptive_recommendationsGet suggested preemptive policy changes based on threat forecasts
verify_supply_chainFull supply chain integrity verification with signed attestation for MCP server packages
supply_chain_statusCurrent trust graph state for all MCP server packages
sbom_exportExport Software Bill of Materials for MCP server packages
detect_driftCompare current MCP server behavior against a known-good baseline to detect anomalies
capture_baselineCapture current server state as a known-good behavioral baseline
rollback_server_configRevert to a previous known-good configuration snapshot
drift_historyList all detected drift events
generate_compliance_evidenceGenerate auditor-ready compliance evidence bundle for a framework
compliance_gap_analysisIdentify missing compliance controls and recommend policies
compliance_postureGet current compliance posture score across all frameworks
list_compliance_frameworksList all supported compliance frameworks
run_self_assessmentRun a full autonomous red team assessment with attack generation and policy testing
schedule_red_teamConfigure periodic autonomous red team assessments
red_team_resultsGet latest red team assessment results and recommendations
ab_test_policyA/B test a proposed policy change against historical attack corpus
contribute_threat_signatureSubmit an anonymized threat signature to the cross-deployment intelligence mesh
threat_intel_statusGet mesh connectivity, contribution stats, and known threat feed
deploy_honeypotDeploy an ephemeral fake MCP server to detect adversarial probing
honeypot_reportGet attack patterns observed by all active honeypots
destroy_honeypotTear down a specific honeypot and retrieve captured data
list_honeypotsList all active and destroyed honeypots with summary
negotiate_agent_trustInitiate an automated trust handshake with another AI agent behind Guardian
agent_trust_statusView all active trust relationships and session details
revoke_agent_trustImmediately terminate a trust relationship
trust_registry_listList all registered agents in the trust registry
agentic_statusGet overall status of all agentic AI features including metrics, scheduler, and task queue
compute_trust_scoreCompute an A+-F trust score for an MCP server across 8 security dimensions (like SSL Labs for MCP)
scan_response_dlpScan MCP tool responses for PII, credentials, sensitive paths, and data exfiltration
certify_serverRun MCP server certification (Bronze/Silver/Gold/Platinum)
list_certified_serversList MCP servers in the local certification registry with level and expiry
verify_certificationVerify a server certification attestation (JWS) and level
declare_intentDeclare session intent and allowed tools for intent-binding enforcement
run_protocol_fuzzerRun MCP protocol fuzzer — test defenses against malformed JSON-RPC, overflow, injection
check_slaCheck SLA compliance — p50/p95 latency, error rate, circuit breaker state per tool
run_incident_playbookExecute an incident response playbook (prompt_injection, credential_leak, shell_injection)
get_agent_reputationGet agent reputation score — Trusted/Standard/Suspicious/Blocked tier with bypass rate and entropy
harden_configAnalyze MCP server config and get A-F hardening grade with one-click recommendations
detect_collusionDetect agent-to-agent collusion patterns (recon-then-exploit, coordinated exfil, token sharing)
policy_to_natural_languageExplain MCP Guardian policy YAML in plain English for compliance stakeholders
natural_language_to_policyConvert a natural-language security goal into a draft YAML policy rule (requires approval before enforce)
query_server_reputationQuery decentralized MCP server reputation (8-dimension consensus score)
quantify_insurance_riskCompute cyber insurance ALE (Annualized Loss Expectancy) for an MCP server
sample_agent_trustThompson Sampling — run Bayesian bandit trust sampling for an agent (Beta posterior, exploration/exploitation)
tune_policy_ruleContextual Bandit (LinUCB) — select optimal policy action (enforce/relax/skip) based on context
adapt_thresholdSARSA — adaptively tune rate limit, latency limit, or confidence threshold via reinforcement learning
select_fuzz_strategyREINFORCE — use policy gradient to select optimal fuzzer mutation strategy
echoEcho arguments back
searchSearch (harness probe)
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
CONTROL_PLANE_POLICY_PATHCONTROL_PLANE_PORTCONTROL_PLANE_RULES_CACHE_MSCORPUS_MIN_ATTACK_SAMPLESCORPUS_MIN_F1DASHBOARD_ALLOWED_ORIGINSDASHBOARD_AUTH_DISABLEDtrue in dev scriptDASHBOARD_ENABLEDtrue when using mcp-guardian start or dashboard:proxyDASHBOARD_PORT4000GUARDIAN_AI_DISABLE_THREAT_POLLGUARDIAN_AI_ENABLEDGUARDIAN_AI_INSTANT_LEARNINGGUARDIAN_ANOMALY_BLOCKGUARDIAN_AUDIT_SYNC_ENABLEDGUARDIAN_AUTO_CORPUS_PROMOTEGUARDIAN_BENCH_RUN_HARNESSGUARDIAN_CI_BYPASS_LICENSELocal development can use =true with pnpm dashboard:proxy. Production Pro needs a license — [PRO_SETUP.md](docs/PRO_SETUP.md).GUARDIAN_CONTROL_PLANE_URLGUARDIAN_DAILY_BUDGET_USDDaily spend alert thresholdGUARDIAN_DASHBOARD_API_RATE_LIMITGUARDIAN_DASHBOARD_SPAGUARDIAN_DISABLE_SEMANTICGUARDIAN_FEDERATED_LEARNING_MIN_REPORTSGUARDIAN_FUZZ_TARGETGUARDIAN_GATEWAY_MODEGUARDIAN_HEALTH_PROBE_TIMEOUT_MSGUARDIAN_HEALTH_REPORT_LLMGUARDIAN_INSIGHTS_LLMGUARDIAN_INTERNAL_ADMIN_TOKENGUARDIAN_LICENSE_KEYGUARDIAN_POLICY_MODEGUARDIAN_POLICY_PATHGUARDIAN_POLICY_SIGNING_EXPIRES_ATGUARDIAN_POLICY_SIGNING_ISSUERGUARDIAN_POLICY_SIGNING_KEY_IDGUARDIAN_POLICY_SYNC_ENABLEDGUARDIAN_POLICY_TIMING_ENVELOPEGUARDIAN_REGIONGUARDIAN_REQUEST_TIMEOUT_MSGUARDIAN_SEMANTIC_ASYNCGUARDIAN_SEMANTIC_STORE_CALIBRATIONGUARDIAN_SOAR_PLAYBOOKSGUARDIAN_SSE_PROXY_PORTGUARDIAN_STICKY_SESSION_AUTHGUARDIAN_STREAMABLE_HTTP_UPSTREAM_RELAYGUARDIAN_SWARM_SKIP_CONTINUOUSGUARDIAN_TENANT_IDGUARDIAN_TOOL_TIMEOUT_JSONGUARDIAN_WS_ENABLEDtrueGUARDIAN_WS_PUSH_INTERVAL_MSLIVE_ATTACK_BENIGN_RATIOLIVE_ATTACK_DURATION_MINUTESLIVE_ATTACK_ESCALATIONLIVE_ATTACK_INTERVAL_MSMCP_FS_ROOTMCP_GUARDIAN_COST_BUDGETMCP_GUARDIAN_DB_PATHThe dashboard is not a separate database — it reads the same call_records the proxy writes. Set consistently when running pnpm real-life:filesystem or other tests so charts match proxy traffic.MCP_GUARDIAN_HOMEMCP_GUARDIAN_MODEMCP_GUARDIAN_POLICYPath to your rules fileMCP_GUARDIAN_POLICY_PATHMETRICS_PORTNO_COLORREAL_LIFE_BURST_REPEATSREAL_LIFE_FILESYSTEM_MCP_ENTRYREAL_LIFE_METRICS_ENABLEDREAL_LIFE_POLICY_PATHREAL_LIFE_PROXY_READY_MSREAL_LIFE_SEMANTIC_DRAIN_MSREAL_LIFE_UPSTREAM_READY_MSREPLICA_COUNTSOC_API_PORTSOC_API_REFRESH_INTERVAL_MSSTUB_ROLESWARM_CALIBRATE_AUTO_LABELSWARM_CALIBRATE_CAPTURETSX_DISABLE_IPCGUARDIAN_ENCODING_GUARDMCP_GUARDIAN_MAX_POLICY_ARGS_BYTESMCP_GUARDIAN_MAX_JSON_DEPTHGUARDIAN_GITHUB_ALLOWED_REPOSGUARDIAN_THREAT_STATE_PATHGUARDIAN_DISABLE_THREAT_INTEL_GUARDMCP_GUARDIAN_MAX_TIMING_PROBES_PER_MINMCP_GUARDIAN_MAX_ENUM_PROBES_PER_SESSIONGUARDIAN_TIMING_GUARDDATABASE_URLPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
62/62 tools missing one or more hints — scan_security (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); audit_costs (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); check_health (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +59 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 2/62 tools referenced in tests (3%)
Write tests that reference each tool by name so every tool has at least one test.
Readable source code
2 files appear obfuscated, including code that decodes and evaluates itself at runtime
Ship unminified, readable source.
Production dependencies are patched
0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.25.2 (high), axios@1.7.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Dependency freshness
3/28 production deps abandoned (no release in 2+ years): bash-parser@2022-06-13 (4.2y), proper-lockfile@2022-06-24 (4.2y), webhook-discord@2022-06-28 (4.2y)
Domain consistency
npm scope @mcp-guardian doesn't match GitHub owner rudraneel93
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/rudraneel93/mcp-guardian)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check