Audit-first MCP proxy for AI agents. MCP Warden scans client configs, wraps stdio MCP servers, logs tool calls, flags risky tools, and can append Agentbox-compatible events to an active run.
npx @swarmclawai/mcp-warden@latest policy init --write
npx @swarmclawai/mcp-warden@latest scan --config ./mcp.json
npx @swarmclawai/mcp-warden@latest install --client cursor --config ./mcp.jsonDry-runs are the default. Add --write only after reviewing the plan.
| Command | Purpose |
|---|---|
mcp-warden scan |
Find MCP servers in known client configs or --config |
mcp-warden wrap --name <server> -- <command...> |
Proxy a stdio MCP server and log risk events |
mcp-warden install --client <client> [--write] |
Produce or apply a wrapper rewrite plan |
mcp-warden policy init |
Print or write mcp-warden.config.json |
mcp-warden report |
Summarize Warden audit events |
mcp-warden help-agents |
Print the machine-readable command catalog |
Every data-returning command supports --json and emits one JSON line on stdout.
V1 discovery recognizes claude-code, cursor, cline, windsurf, codex, and explicit --config <path>.
When AGENTBOX_RUN_DIR is set, wrap appends compatible mcp and risk JSONL events into the active Agentbox run.
MCP Warden warns by default. Blocking is opt-in through mcp-warden.config.json:
{
"schemaVersion": 1,
"mode": "audit",
"blockRiskCodes": []
}