Protect MCP server
Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.
9 stars
Reviews
Write oneNobody has reviewed Protect yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Protect tools (5, 3 write)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
delete_filewrite actionDelete a file from the filesystem
deploywrite actionDeploy the application to production
read_fileRead the contents of a file
web_searchSearch the web for information
write_filewrite actionWrite content to a file
Public scan report
scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it
- Code scan37 source files scanned8/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 11 days ago15/15
- Maintainer identitynamespace and repository owner differ4/10
Findings (2)
- mediumeval / new Function used
exec.evaldist/chunk-SU2FZH7U.mjs: …ode, sch); const makeValidate = new Function(`${names_1.default.self}`, `${names_1.de… - highShell command built from a string (injection risk)
exec.shell-concatdist/index.js: … = await import("child_process"); execSync(`docker rm -f ${sandbox.id} 2>/dev/null`, { stdio: "pipe…
Install Protect in Claude Code, Cursor or VS Code
Runs npx -y protect-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add protect-mcp -- npx -y protect-mcp
What the publisher says
From the Protect repository's README, as published. We do not edit it. Read it on GitHub
protect-mcp
Fail-closed Cedar policy gate plus signed receipts for AI agent tool calls.
protect-mcp is a gate that sits in front of an AI agent's tool calls. It evaluates each call against a Cedar policy, blocks what breaks the rules before it runs, and signs an offline-verifiable Ed25519 receipt of every decision. The configured gateway runs locally and sends no decision telemetry. The separate coordination adapter connects to ScopeBlind’s hosted collaboration service; its requests and returned records have the data path described below. Both are MIT licensed.
For shared repository work, use client projects: people agree on the brief and limits, agents prepare reviews, and both people approve an exact version before the owner's receiver can change the repository. The repository workflow below includes setup and the five bounded agent tools.
Why it is different
evaluation failure, the decision is DENY. The gate never silently allows. An observe mode exists for shadow rollout, but even there a call that would be blocked is flagged would_deny: true, so a failure is never silent.
- Fail-closed by default. On any policy error, a missing engine, or an
self-test and refuse to arm the gate unless they can show that a known-forbidden action is actually denied. A gate that cannot prove it denies does not start.
- It proves its own restraint. serve --enforce and doctor run a startup
and verifiable offline with @veritasacta/verify. Signature verification needs no network lookup. Claims about execution still depend on the identified gate operator.
- Every decision is a receipt anyone can verify. Decisions are Ed25519-signed
Quickstart: install to first useful proof
# 1. Generate an Ed25519 keypair, config template, and sample policy.
npx protect-mcp init
# 2. Print a shadow-mode client configuration, then apply it in your MCP host.
# This command prints configuration and exits; it does not launch the server.
npx protect-mcp wrap -- node your-mcp-server.js
# 3. Reopen the host and use its tools, then inspect the local-only dashboard.
npx protect-mcp dashboard --open
# 4. Draft a reviewable policy from observed calls.
npx protect-mcp recommend --write
# 5. When reviewed, restart the wrapper in enforce mode with that policy.
npx protect-mcp --policy protect-mcp.recommended.json --enforce -- node your-mcp-server.jsFor Claude Desktop, run a dry-run config patch first, then apply it:
npx protect-mcp wrap --claude-desktop
npx protect-mcp wrap --claude-desktop --write
npx protect-mcp dashboard --openThe dashboard binds to 127.0.0.1, reads only local log/receipt files, and does not upload anything. Use npx protect-mcp connect only if you explicitly want a hosted ScopeBlind dashboard.
The gate as an MCP server
If you would rather call the gate as tools than wire the Claude Code hooks, run it as an MCP server:
npx protect-mcp mcpIt speaks MCP over stdio and exposes four read-only tools, the whole loop:
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Protect: common questions
- Is Protect MCP server safe?
- With care: it is graded C, so read the findings first (60/100). Read the Protect safety report
- How do I install Protect?
- It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
- Does Protect need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Protect maintained?
- The last commit was 11 days ago (2026-09-17). The latest release is v0.5.3.
- What can I use instead of Protect?
- Servers from other publishers that do the same job: Emilia Protocol MCP server, Ausca MCP server and Agoragentic Agent OS MCP server. Compare all Protect alternatives.
Alternatives to Protect
Same job from other publishers: the closest match first, then the best rated.
- Emilia ProtocolExact-action approval for consequential agent actions: request, track, and verify signed receipts.not reviewedEstablishedB
- AuscaPay-per-call APIs and MCP services for agents, no accounts or keys, with verifiable receipts.not reviewedEstablishedB
Agoragentic Agent OS MCPTriptych OS (Agent OS) MCP for governed routing, receipts, and USDC settlement on Base.not reviewedEstablishedB- three.ws ProvenanceAppend-only, signed, on-chain-verifiable agent action log — record and audit what agents did.not reviewedEstablishedB
- sqzPre-injection context compression for coding agents. Zero LLM calls, zero telemetry, offline-safe.not reviewedEstablishedA