{"name":"io.github.Shalimov04/mcp-airlock","slug":"shalimov04-mcp-airlock","title":"mcp-airlock","description":"Governance proxy for MCP servers: allowlist, forced dry run, human confirmation, blast radius, audit","url":"https://mcp.market/server/shalimov04-mcp-airlock","rating":null,"grade":"B","score":75,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":41,"stars":25,"forks":2,"downloads_week":278,"last_push_at":"2026-09-16T15:38:14.000Z","license":"MIT"},"claimed":false,"transport":"pypi","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/Shalimov04/mcp-airlock","website":null,"version":"0.2.0","remotes":[],"packages":[{"registryType":"pypi","registryBaseUrl":"https://pypi.org","identifier":"mcp-airlock","version":"0.2.0","runtimeHint":"uvx","transport":{"type":"streamable-http","url":"http://127.0.0.1:9000/mcp","headers":[{"description":"Bearer JWT identifying the caller; the proxy refuses calls without a principal","isRequired":true,"isSecret":true,"name":"Authorization"}]},"packageArguments":[{"description":"Policy YAML: which tools are allowed and at which tier per environment","isRequired":true,"format":"filepath","type":"named","name":"--policy","valueHint":"policy.yaml"},{"description":"The MCP server being proxied","isRequired":true,"type":"named","name":"--upstream","valueHint":"http://127.0.0.1:8080/mcp"},{"description":"Environment name, selects the tier column in the policy","default":"prod","type":"named","name":"--env"}],"environmentVariables":[{"description":"HS256 secret for verifying bearer tokens (or set AIRLOCK_JWKS_URL for OIDC)","isSecret":true,"name":"AIRLOCK_JWT_SECRET"},{"description":"Key for signing confirmation tokens; set it when running more than one replica","isSecret":true,"name":"AIRLOCK_SECRET"}]}],"tools":[],"scan":{"score":75,"grade":"B","scanned_at":"2026-09-19T10:14:21.187Z","report":{"scannerVersion":"0.1.3","scannedAt":"2026-09-19T10:14:21.177Z","components":{"code":{"score":20,"max":25,"notes":["12 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 3 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"net.raw-ip","severity":"medium","component":"code","title":"Network call to a raw IP address","evidence":"mcp_airlock-0.2.0/src/mcp_airlock/__main__.py: …airlock --policy policy.yaml --upstream http://127.0.0.1:9001/mcp\"\"\" from __future__ import annotatio…"}],"inputs":{"packages":[{"registryType":"pypi","identifier":"mcp-airlock","version":"0.2.0","found":true,"weeklyDownloads":278,"license":"MIT","dependencyCount":10,"publishedAt":"2026-09-16T11:58:10.204551Z","repositoryUrl":"https://github.com/Shalimov04/mcp-airlock"}],"repo":{"found":true,"owner":"Shalimov04","repo":"mcp-airlock","archived":false,"pushedAt":"2026-09-16T15:38:14Z","stars":25,"forks":2,"openIssues":3,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/69015382?v=4","ownerCreatedAt":"2020-07-30T20:07:40Z","license":"MIT"},"icon":{"url":null,"source":"none"},"presence":{"stars":25,"forks":2,"downloadsWeek":278,"license":"MIT","lastPushAt":"2026-09-16T15:38:14.000Z","score":41}}}},"grade_history":[],"reviews":[]}