Shellward MCP server
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
138 stars506 downloads/wk
Reviews
Write oneNobody has reviewed Shellward yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Shellward tools (7)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_commandCheck if a shell command is safe to execute. Detects rm -rf, reverse shells, fork bombs, curl|sh, etc.
check_injectionDetect prompt injection attempts in text. Supports 32+ rules for Chinese and English, with hidden character detection.
check_pathCheck if a file path operation is safe. Protects .env, .ssh/, .aws/credentials, private keys, /etc/passwd, etc.
check_responseCheck an AI response for security issues: canary token leaks and sensitive data exposure.
check_toolCheck if a tool name is allowed. Blocks payment/transfer tools, flags exec/shell tools as sensitive.
scan_dataScan text for sensitive data: PII (Chinese ID cards, phone numbers, bank cards), API keys, passwords, private keys, JWT tokens, SSN, credit cards.
security_statusGet current ShellWard security status: mode, active layers, detection capabilities.
Public scan report
scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan88 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 6 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Findings (1)
- mediumeval / new Function used
exec.evaldist/auto-check.js: … = [ { pattern: /eval\s*\(/, name: 'eval()' }, { pattern: /\/dev\/tcp|nc\s+-e…
Install Shellward in Claude Code, Cursor or VS Code
Runs npx -y shellward on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add shellward -- npx -y shellward
What the publisher says
From the Shellward repository's README, as published. We do not edit it. Read it on GitHub
ShellWard
AI 应用合规网关 — 为中国监管而生的 AI Agent 安全合规工具(网安法 2026 / PIPL / 等保2.0 / 数据出境 / AI标识)。先一行命令体检项目合规风险,再在运行时拦截提示注入、数据外泄与危险命令。中文威胁检测 + 中文 PII + 零依赖——英文工具不做的事。
🌐 官网: https://jnmetacode.github.io/shellward/
中文 | English
30 秒合规体检
零安装、只读、不上传任何数据。一行命令,扫出你的 AI 项目踩了哪些合规红线:
npx shellward scan输出一张映射到 网安法 / PIPL / 等保2.0 / 数据出境 / AI标识 的红黄绿评分卡,并精确到 文件:行:
## 🔍 项目实测风险
🌐 数据出境风险: 2 | 🔑 硬编码密钥: 3 | 🪪 个人信息暴露: 2 | 📂 .env 权限: 1
- .env:2 境外大模型端点: OpenAI — 向其发送个人信息即构成数据出境
- package.json:12 境外大模型 SDK 依赖: openai — 项目内含数据出境通道
- src/config.ts:3 硬编码 GitHub Token: ghp_12*** — 凭据不应写入源码
- customers.csv:2 手机号 13912*** — 个人信息出现在文件中,需评估脱敏
合规得分: 63/100 [C]🆕 让你的 agent 做一次完整合规审计(Skill)
scan 是确定性扫描:它能告诉你「项目里有境外模型端点」,但判断不了个人信息有没有真的流过去;14 个法规控制项里也有 11 个它只能标「需人工确认」。这一段交给你的编码 agent 来做——Claude Code、Cursor、Codex 等支持 Agent Skills 的工具都能用。
把这句话粘贴给你的 agent:
安装 https://github.com/jnMetaCode/shellward 里的 china-ai-compliance-audit skill,然后用它审计当前项目。或者用命令装:npx skills add jnMetaCode/shellward --skill china-ai-compliance-audit
它会先跑 shellward scan 拿确定性基线,再顺着数据流逐项取证,最后产出 .compliance/COMPLIANCE-REPORT.md。和「让 AI 随便看看合不合规」的区别在三道闸:
另外:14 个控制项必须全部有结论,不许悄悄跳过;报告里不许出现完整密钥、手机号、身份证号——合规报告自己不能泄漏数据。
示例(演示项目 · 完整记录):一个客服机器人,shellward scan 给 75 分 [B]、只报出「有 OpenAI 端点」;审计顺着调用链查到客户手机号和身份证号被拼进 system prompt 发往境外——2 条严重、3 条高,外加 6 个只有人能回答的问题(比如「审核是不是在网关侧做了」——仓库里看不到的事,它不替你下结论)。
这是技术自查材料,不是法律意见。备案、定级、PIA 等主体责任不能由工具代替。
团队要对多个 AI 项目做合规自查、或想把它接进内部流程? 邮件 jnMetaCode@qq.com,说一下团队规模和场景。
想在浏览器里看?npx shellward scan --open(扫完直接打开报告)或 --serve(本地 http://localhost 提供报告)——数据全程不出本机。
Web 扫描器 / 客户端(双模式):
- shellward web — 公开仓库 web 扫描器:网页贴「公开仓库 URL」或用 /scan?repo=URL 链接体检(可部署,见 Dockerfile)。
- shellward web --local — 本地 web GUI(客户端体验):填本地路径扫描,私有代码不上传、不出本机,无需命令行。
--json 供 CI · --ci 发现 critical 时让构建失败 · --html report.html 导出可打印成 PDF 的报告(备案/审计存档)· 也可作 GitHub Action 接入 PR 门禁。
检测重点:境外大模型端点与 SDK 依赖(数据出境——中国独有、英文工具没有的概念)、硬编码密钥、文件中的中文 PII、.env 暴露。扫到境外模型(如 openai 依赖)时,直接给出境内合规替代(通义千问 / DeepSeek / Kimi / 智谱)及其 OpenAI 兼容 baseurl——多数迁移只需改一个 baseurl。
想在浏览器里看报告? 在项目目录跑 npx shellward scan --open —— 自动扫描并在浏览器打开报告,无需上传、无弹框、数据不出本机(最干净)。也可 npx shellward web --local 起本地图形界面(粘贴/点选路径,服务端直读)。
更多命令、运行时防护(MCP / 插件)、与英文文档见下方 English 章节。
English
AI Agent Security & Compliance Gateway — the AI agent security middleware built for China's regulatory regime (CSL / PIPL / MLPS 2.0 / cross-border data / AI labeling). Scan your project for compliance risks, then block prompt injection, data exfiltration, and dangerous commands at runtime. Chinese-language threat detection + Chinese PII + zero dependencies — things English tools don't do.
Quick start: npx shellward scan — zero install, read-only, nothing uploaded. Outputs a red/yellow/green scorecard mapped to Chinese regulations plus concrete file:line findings, and prescribes domestic compliant model alternatives for any overseas LLM it finds.
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Shellward: common questions
- Is Shellward MCP server safe?
- Yes, by our scan: it is graded A (85/100). Read the Shellward safety report
- How do I install Shellward?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Shellward need an API key?
- No secret keys are declared. It reads 3 settings from the environment.
- Is Shellward maintained?
- The last commit was 6 days ago (2026-09-21). The latest release is v0.5.11.
- What can I use instead of Shellward?
- Servers from other publishers that do the same job: Dvalincode MCP server, Godot MCP server and sqz MCP server. Compare all Shellward alternatives.
Alternatives to Shellward
Same job from other publishers: the closest match first, then the best rated.
- DvalincodeDeterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.not reviewedGrowingA
- Godot MCPAgent-driven Godot playtesting: editor control, input injection, game-time stepping, live state.not reviewedEstablishedA
- sqzPre-injection context compression for coding agents. Zero LLM calls, zero telemetry, offline-safe.not reviewedEstablishedA
- HOL GuardLocal-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.not reviewedEstablishedA