Skip to content

Repository files navigation

MCP Warden

Audit-first MCP proxy for AI agents. MCP Warden scans client configs, wraps stdio MCP servers, logs tool calls, flags risky tools, and can append Agentbox-compatible events to an active run.

npm version License: MIT CI

30-second demo

npx @swarmclawai/mcp-warden@latest policy init --write
npx @swarmclawai/mcp-warden@latest scan --config ./mcp.json
npx @swarmclawai/mcp-warden@latest install --client cursor --config ./mcp.json

Dry-runs are the default. Add --write only after reviewing the plan.

Commands

Command Purpose
mcp-warden scan Find MCP servers in known client configs or --config
mcp-warden wrap --name <server> -- <command...> Proxy a stdio MCP server and log risk events
mcp-warden install --client <client> [--write] Produce or apply a wrapper rewrite plan
mcp-warden policy init Print or write mcp-warden.config.json
mcp-warden report Summarize Warden audit events
mcp-warden help-agents Print the machine-readable command catalog

Every data-returning command supports --json and emits one JSON line on stdout.

Supported Clients

V1 discovery recognizes claude-code, cursor, cline, windsurf, codex, and explicit --config <path>.

Agentbox Integration

When AGENTBOX_RUN_DIR is set, wrap appends compatible mcp and risk JSONL events into the active Agentbox run.

Policy

MCP Warden warns by default. Blocking is opt-in through mcp-warden.config.json:

{
  "schemaVersion": 1,
  "mode": "audit",
  "blockRiskCodes": []
}

About

Audit-first MCP proxy for AI agents

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages