WARDEN — MCP Security Firewall MCP server
MCP security firewall: vet tool definitions before they reach the model.
0 stars51 downloads/wk
Reviews
Write oneNobody has reviewed WARDEN — MCP Security Firewall yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
WARDEN — MCP Security Firewall tools (6, 2 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
canonicalize_jsonReturn the RFC 8785 JSON Canonicalization Scheme serialization WARDEN uses for threat-feed signatures and tool-def pins, so another implementation can byte-check against it. Integers only inside ±(2^53−1); lone surrogates and non-integers are refused with a reason code, not escaped.
check_egress_urlAsk EgressGuard whether a URL's hostname is on an operator allowlist. A tool reaching a host you never listed is the classic phone-home tell. Empty allowlist blocks everything (fail-closed), not everything-allowed.
classify_sensitive_toolsSplit advertised tool names into sensitive vs safe using the operator's case-insensitive * globs (the same policy.sensitiveToolPatterns a host would use). Sensitive tools stay advertised; they require per-call approval — this tool does not run them.
list_scan_rulesReturn the in-force static-scan ruleset: version, digest, and every rule's code, severity, tier (block vs advise), surfaces (name / description / inputSchema), optional regex source, and named guards. A recorded verdict is only reproducible together with this identity.
static_scan_toolswrite actionRun only the static-scan gate (ruleset v4, 25 signatures with context guards) over advertised tool names, descriptions, and input schemas. Returns findings, a 0..1 gate score, and the published ruleset digest.
vet_mcp_serverwrite actionRun WARDEN's ordered gate chain (static-scan → threat-feed → origin → pinning) over a server identity plus its advertised tools/list payload and return a recordable verdict (allow/block, 0..1 product score, findings, allowedTools/blockedTools, ruleset digest).
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan29 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 15 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install directly
Runs npx -y @aimarket/warden on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add warden -- npx -y @aimarket/warden
WARDEN — MCP Security Firewall: common questions
- Is WARDEN — MCP Security Firewall MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the WARDEN — MCP Security Firewall safety report
- How do I install WARDEN — MCP Security Firewall?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does WARDEN — MCP Security Firewall need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is WARDEN — MCP Security Firewall maintained?
- The last commit was 15 days ago (2026-09-05). The latest release is v0.5.0.
- What can I use instead of WARDEN — MCP Security Firewall?
- Servers from other publishers that do the same job: MCP server, HOL Guard MCP server and Dvalincode MCP server. Compare all WARDEN — MCP Security Firewall alternatives.
Alternatives to WARDEN — MCP Security Firewall
Same job from other publishers: the closest match first, then the best rated.
- MCPAuthorize consequential AI agent actions before executionnot reviewedEstablishedA
- HOL GuardLocal-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.not reviewedEstablishedA
- DvalincodeDeterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.not reviewedGrowingA
- ProjectmemCoding agent memory — one local MCP server for every project. Warns before repeating failed fixes.not reviewedGrowingA
runxThe governed runtime for agent skills. Search the catalog and inspect a skill before running it.not reviewedGrowingA