Mmcp.market

Scopeblind MCP server

by tomjwxf·io.github.tomjwxf/scopeblind-mcp·v1.0.2·10 stars

Scan, protect, and monitor APIs from AI coding tools. Device-level rate limiting.

A88/100grade A
What users say
No reviews yet
Be the first
Safety scan
A88/100

full report

Adoption
Growing

10 stars45 downloads/wk

Reviews

Write one

Nobody has reviewed Scopeblind yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Scopeblind tools (4, 1 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • get_abuse_report

    Fetch real-time abuse statistics for a ScopeBlind tenant. Shows total requests, unique devices, abuse rate, and estimated dollar waste.

  • get_integration_code

    Generate ScopeBlind integration code for a specific framework. Supports: script-tag, express, fastapi, nextjs, agent-sdk, gateway.

  • provision_tenantwrite action

    Create a ScopeBlind tenant for an API endpoint. Returns a slug, verifier URL, and deploy config. The tenant starts in shadow mode (observes traffic, blocks nothing).

  • scan_endpoint

    Scan an API endpoint for abuse vulnerabilities (missing rate limiting, replay protection, CORS exposure). Returns a risk assessment with specific issues found.

Public scan report

scanner v0.1.10 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan3 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 87 days ago12/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 88/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Scopeblind in Claude Code, Cursor or VS Code

Runs npx -y scopeblind-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add scopeblind-mcp -- npx -y scopeblind-mcp
Add to Cursor

What the publisher says

From the Scopeblind repository's README, as published. We do not edit it. Read it on GitHub

⚠️ This repository has moved. Active development continues at ScopeBlind/scopeblind-gateway.

This personal fork may be behind the canonical repository. Please use the org repo for issues, pull requests, and the latest code.

protect-mcp

Security gateway for MCP servers. Shadow-mode logs by default, per-tool policies, optional local Ed25519 receipts, and verification-friendly audit output.

Current CLI path: wrap any stdio MCP server as a transparent proxy. In shadow mode it logs every tools/call request and allows everything through. Add a policy file to enforce per-tool rules. Run protect-mcp init to generate local signing keys and config so the gateway can also emit signed receipts.

Quick Start

# Wrap an existing OpenClaw / MCP config into a usable pack
npx @scopeblind/passport wrap --runtime openclaw --config ./openclaw.json --policy email-safe

# Shadow mode — log every tool call, enforce nothing
npx protect-mcp -- node my-server.js

# Generate keys + config template for local signing
npx protect-mcp init

# Shadow mode with local signing enabled
npx protect-mcp --policy protect-mcp.json -- node my-server.js

# Enforce mode
npx protect-mcp --policy protect-mcp.json --enforce -- node my-server.js

# Export an offline-verifiable audit bundle
npx protect-mcp bundle --output audit.json

What It Does

protect-mcp sits between your MCP client and server as a stdio proxy:

MCP Client ←stdin/stdout→ protect-mcp ←stdin/stdout→ your MCP server

It intercepts tools/call JSON-RPC requests and:

  • Shadow mode (default): logs every tool call and allows everything through
  • Enforce mode: applies per-tool policy rules such as block, ratelimit, and mintier
  • Optional local signing: when signing is configured, emits an Ed25519-signed receipt alongside the structured log

All other MCP messages (initialize, tools/list, notifications) pass through transparently.

What Ships Today

  • Per-tool policies — block destructive tools, rate-limit expensive ones, and attach minimum-tier requirements
  • Structured decision logs — every decision is emitted to stderr with [PROTECT_MCP]
  • Optional local signed receipts — generated when you run with a policy containing signing.key_path, persisted to .protect-mcp-receipts.jsonl, and exposed at http://127.0.0.1:9876/receipts
  • Offline verification — verify receipts or bundles with npx @veritasacta/verify
  • No account required — local keys, local policy, local process

Current Capability Boundaries

These are important before you roll this out or talk to users:

  • Signing is not automatic on the bare npx protect-mcp -- ... path. That path logs decisions in shadow mode. For local signing, run npx protect-mcp init and then start the gateway with the generated policy file.
  • Tier-aware policy checks are live, but manifest admission is not wired into the default CLI/stdio path. The CLI defaults sessions to unknown unless a host integration calls the admission API programmatically.
  • Credential config currently validates env-backed credential references and records credential labels in logs/receipts. Generic per-call injection into arbitrary stdio tools is adapter-specific and is not performed by the default proxy path.
  • External PDP adapters and audit bundle helpers exist as exported utilities. They are not yet fully wired into the default CLI path.

Policy File

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Scopeblind: common questions

Is Scopeblind MCP server safe?
Yes, by our scan: it is graded A (88/100). Read the Scopeblind safety report
How do I install Scopeblind?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Scopeblind need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Scopeblind maintained?
The last commit was 87 days ago (2026-07-03). The latest release is v1.0.2.
What can I use instead of Scopeblind?
Servers from other publishers that do the same job: DNS Doctor MCP server, Dep Scope MCP server and Kalshi Prediction Markets MCP server. Compare all Scopeblind alternatives.

Alternatives to Scopeblind

Same job from other publishers: the closest match first, then the best rated.

All Scopeblind alternatives →
  • DNS Doctor
    Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
    A
  • Dep Scope
    Symbol-level npm dependency analysis: scan verdicts, native alternatives, migration prompts.
    A
  • Kalshi Prediction Markets
    MCP server for Kalshi prediction markets: native RSA-PSS auth, rate limiting, demo/prod safety.
    B
  • Autopilot Jobhunt
    Agentic job hunt: scan careers pages, score against your resume, draft applications. Never applies.
    A
  • Solana Security Standard
    Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.
    A

More from tomjwxf →