Mmcp.market

Protect MCP server

by tomjwxf·io.github.tomjwxf/protect-mcp·v0.5.3·9 stars

Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.

C60/100grade C
What users say
No reviews yet
Be the first
Safety scan
C60/100

full report

Adoption
Growing

9 stars

Reviews

Write one

Nobody has reviewed Protect yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Protect tools (5, 3 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • delete_filewrite action

    Delete a file from the filesystem

  • deploywrite action

    Deploy the application to production

  • read_file

    Read the contents of a file

  • web_search

    Search the web for information

  • write_filewrite action

    Write content to a file

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

1 high1 medium
  • Code scan37 source files scanned8/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 11 days ago15/15
  • Maintainer identitynamespace and repository owner differ4/10

Findings (2)

  • mediumeval / new Function usedexec.eval
    dist/chunk-SU2FZH7U.mjs: …ode, sch); const makeValidate = new Function(`${names_1.default.self}`, `${names_1.de…
  • highShell command built from a string (injection risk)exec.shell-concat
    dist/index.js: … = await import("child_process"); execSync(`docker rm -f ${sandbox.id} 2>/dev/null`, { stdio: "pipe…
Overall 60/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Protect in Claude Code, Cursor or VS Code

Runs npx -y protect-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add protect-mcp -- npx -y protect-mcp
Add to Cursor

What the publisher says

From the Protect repository's README, as published. We do not edit it. Read it on GitHub

protect-mcp

Fail-closed Cedar policy gate plus signed receipts for AI agent tool calls.

protect-mcp is a gate that sits in front of an AI agent's tool calls. It evaluates each call against a Cedar policy, blocks what breaks the rules before it runs, and signs an offline-verifiable Ed25519 receipt of every decision. The configured gateway runs locally and sends no decision telemetry. The separate coordination adapter connects to ScopeBlind’s hosted collaboration service; its requests and returned records have the data path described below. Both are MIT licensed.

For shared repository work, use client projects: people agree on the brief and limits, agents prepare reviews, and both people approve an exact version before the owner's receiver can change the repository. The repository workflow below includes setup and the five bounded agent tools.

Why it is different

evaluation failure, the decision is DENY. The gate never silently allows. An observe mode exists for shadow rollout, but even there a call that would be blocked is flagged would_deny: true, so a failure is never silent.

  • Fail-closed by default. On any policy error, a missing engine, or an

self-test and refuse to arm the gate unless they can show that a known-forbidden action is actually denied. A gate that cannot prove it denies does not start.

  • It proves its own restraint. serve --enforce and doctor run a startup

and verifiable offline with @veritasacta/verify. Signature verification needs no network lookup. Claims about execution still depend on the identified gate operator.

  • Every decision is a receipt anyone can verify. Decisions are Ed25519-signed

Quickstart: install to first useful proof

# 1. Generate an Ed25519 keypair, config template, and sample policy.
npx protect-mcp init

# 2. Print a shadow-mode client configuration, then apply it in your MCP host.
#    This command prints configuration and exits; it does not launch the server.
npx protect-mcp wrap -- node your-mcp-server.js

# 3. Reopen the host and use its tools, then inspect the local-only dashboard.
npx protect-mcp dashboard --open

# 4. Draft a reviewable policy from observed calls.
npx protect-mcp recommend --write

# 5. When reviewed, restart the wrapper in enforce mode with that policy.
npx protect-mcp --policy protect-mcp.recommended.json --enforce -- node your-mcp-server.js

For Claude Desktop, run a dry-run config patch first, then apply it:

npx protect-mcp wrap --claude-desktop
npx protect-mcp wrap --claude-desktop --write
npx protect-mcp dashboard --open

The dashboard binds to 127.0.0.1, reads only local log/receipt files, and does not upload anything. Use npx protect-mcp connect only if you explicitly want a hosted ScopeBlind dashboard.

The gate as an MCP server

If you would rather call the gate as tools than wire the Claude Code hooks, run it as an MCP server:

npx protect-mcp mcp

It speaks MCP over stdio and exposes four read-only tools, the whole loop:

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Protect: common questions

Is Protect MCP server safe?
With care: it is graded C, so read the findings first (60/100). Read the Protect safety report
How do I install Protect?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Protect need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Protect maintained?
The last commit was 11 days ago (2026-09-17). The latest release is v0.5.3.
What can I use instead of Protect?
Servers from other publishers that do the same job: Emilia Protocol MCP server, Ausca MCP server and Agoragentic Agent OS MCP server. Compare all Protect alternatives.

Alternatives to Protect

Same job from other publishers: the closest match first, then the best rated.

All Protect alternatives →
  • Emilia Protocol
    Exact-action approval for consequential agent actions: request, track, and verify signed receipts.
    B
  • Ausca
    Pay-per-call APIs and MCP services for agents, no accounts or keys, with verifiable receipts.
    B
  • Agoragentic Agent OS MCP
    Triptych OS (Agent OS) MCP for governed routing, receipts, and USDC settlement on Base.
    B
  • three.ws Provenance
    Append-only, signed, on-chain-verifiable agent action log — record and audit what agents did.
    B
  • sqz
    Pre-injection context compression for coding agents. Zero LLM calls, zero telemetry, offline-safe.
    A

More from tomjwxf →