Cordon for MCP server
Cordon for MCP. Security gateway with policy enforcement, audit log, and HITL approvals.
1 stars42 downloads/wk
Reviews
Write oneNobody has reviewed Cordon for MCP yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Cordon for MCP tools
No tool declarations could be read from the package source. They show once the server is installed.
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan4 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 61 days ago12/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install Cordon for MCP in Claude Code, Cursor or VS Code
Runs npx -y @getcordon/cli on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add cordon -- npx -y @getcordon/cli
What the publisher says
From the Cordon for MCP repository's README, as published. We do not edit it. Read it on GitHub
Cordon for MCP
The Security Gateway for MCP Tool Calls
Website • Writeup
Quickstart • Why Cordon • How It Works • Configuration • Roadmap • Contributing
Every company wants to deploy AI agents. No company is willing to give an agent the keys to their database.
Cordon closes the trust gap.
From the maintainer of Agent Toolbelt — 25+ MCP tools, ~1,600 weekly npm downloads.
Demo
https://github.com/user-attachments/assets/153d978f-6303-443a-b49b-b4ec7ebf0452
The Problem
The Model Context Protocol (MCP) has made it trivially easy to give AI agents access to powerful tools — databases, file systems, APIs, cloud infrastructure.
But MCP has no built-in security model. No audit logs. No approval workflows. No rate limits. Today, an AI agent is either off or full admin. There is nothing in between.
This is the single biggest blocker preventing AI agents from reaching production.
The Solution
Cordon is the security gateway that sits between the LLM and your MCP servers.
It acts as a firewall, an auditor, and a remote control — giving you complete visibility and authority over what your AI agents can and cannot do.
┌─────────┐ ┌──────────┐ ┌──────────────┐
│ LLM / │ ──▶ │ Cordon │ ──▶ │ MCP Server │
│ Agent │ ◀── │ Gateway │ ◀── │ (database, │
└─────────┘ └──────────┘ │ fs, APIs) │
│ └──────────────┘
├── Policy Engine
├── Audit Logger
└── Approval WorkflowsNo infrastructure changes. No rewrites. One config file.
Quickstart
Step 1 — Initialize
Run this inside your project (where your claudedesktopconfig.json exists):
npx @getcordon/cli initThis reads your existing Claude Desktop MCP config, generates cordon.config.ts, and patches Claude Desktop to route all tool calls through Cordon.
Step 2 — Start
npx @getcordon/cli startCordon starts, connects to your MCP servers, and begins intercepting tool calls. Restart Claude Desktop and every tool call now flows through the gateway.
Manual setup
If you prefer to configure manually, install globally and create a config:
npm install -g @getcordon/cli
cordon initcordon init generates a cordon.config.ts:
import { defineConfig } from '@getcordon/policy';
export default defineConfig({
servers: [
{
name: 'database',
transport: 'stdio',
command: 'npx',
args: ['-y', '@my-org/db-mcp-server'],
policy: 'read-only', // Block all write operations
},
{
name: 'github',
transport: 'stdio',
command: 'npx',
args: ['-y', '@modelcontextprotocol/server-github'],
policy: 'approve-writes', // Reads pass; writes require approval
tools: {
delete_branch: 'block', // Never, regardless of approval
},
},
],
audit: {
enabled: true,
output: 'stdout', // or 'file'
},Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Cordon for MCP: common questions
- Is Cordon for MCP server safe?
- Yes, by our scan: it is graded A (88/100). Read the Cordon for MCP safety report
- How do I install Cordon for MCP?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Cordon for MCP need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Cordon for MCP maintained?
- The last commit was 62 days ago (2026-07-28). The latest release is v0.3.0.
- What can I use instead of Cordon for MCP?
- Servers from other publishers that do the same job: Wireshark MCP server, Mastyf AI MCP server and npm Registry MCP Server. Compare all Cordon for MCP alternatives.
Alternatives to Cordon for MCP
Same job from other publishers: the closest match first, then the best rated.
- WiresharkProfessional network analysis with tshark. Security audits, deep-dives, and threat detection.not reviewedEstablishedA
- Mastyf AIRuntime proxy for MCP security, cost governance & auditnot reviewedGrowingB
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- IdentArk GatewayZero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.not reviewedGrowingA
- KastellServer security audit (413 checks), hardening, and fleet management across 4 cloud providers.not reviewedGrowingB