Back to Browse

Guard Core MCP Server

Developer ToolsLow Risk9.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.

About

Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.

Security Report

9.0
Low Risk9.0Low Risk

Valid MCP server (1 strong, 0 medium validity signals). 2 known CVEs in dependencies Package registry verified. Imported from the Official MCP Registry.

4 files analyzed · 3 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-guard-core-guard-core-mcp": {
      "args": [
        "guard-core-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Guard Core MCP

An MCP server that lets AI coding agents answer questions about the Guard security ecosystem from the libraries themselves, instead of from memory.

Covers the whole family: the Python trio (fastapi-guard, guard-core, guard-agent) by live introspection, and the Go, TypeScript, PHP and Rust engines, their twenty framework adapters, their telemetry agents, and the guard-core-app SaaS ingestion contract from a verified registry and knowledge corpus.

Why

Your agent can already read the docs. What it cannot do is tell you that the redis_failopen in your config is silently doing nothing because the real field is redis_fail_open, or that the flag you are reaching for did not exist until guard-core 3.5.0, or whether a given request would actually be blocked and by which pattern.

This server answers those from the installed package: real pydantic validation, real field metadata, and the real detection engine. It also answers the cross-language questions the libraries cannot answer: which package guards a Gin, Fastify, Laravel or Rocket app, whether it is tagged or still path-dependent, how to wire its telemetry agent, and what response codes the SaaS ingest endpoint returns.

Install

Install it into your project's environment, not as an isolated tool:

uv add --dev guard-core-mcp
claude mcp add guard-core -- uv run guard-core-mcp

uvx guard-core-mcp will start, but an isolated environment contains no guard-core or fastapi-guard for it to introspect, so it can only answer from bundled documentation. Running it inside your own environment is what makes the answers match the versions you actually ship.

Tools

ToolAnswers
versionsWhich Guard libraries are installed here, and at what version
validate_configIs this config valid, including typo'd keys pydantic silently ignores
config_fieldsWhat is this setting, what does it default to, does a setting for X exist
search_docsWhere do the docs cover this
get_docThe full text of one documentation page
check_payloadWould this request be blocked, and by which pattern
ecosystemThe full registry matrix: 5 languages, engines, adapters, agents, conformance, SaaS contract
adapter_setupInstall plus a verified minimal integration for one adapter (e.g. go + gin)
wire_agentHow to set up the telemetry agent for a language, including the ingestion contract

The ecosystem tools are pure data, so they work everywhere, with or without the Python libraries installed. Every quick-start snippet is copied verbatim from the sibling repo READMEs, and release_status tells you honestly whether a package is published, tagged, or still untagged (source, main, or path dependency only).

ChatGPT plugin

The same tools are also served remotely at https://mcp.guard-core.com/mcp and packaged as a ChatGPT plugin: sign in with a guard-core account, and ChatGPT can validate configs, search the docs and run payloads through the hosted detection engine (the latest published releases, not your local versions). The packaging lives in plugin/, the hosted server in guard_core_mcp.hosting, and the full story (env vars, Docker image, developer-mode test loop, submission checklist) in the ChatGPT plugin guide.

Licence

MIT

mcp-name: io.github.Guard-Core/guard-core-mcp

Reviews

No reviews yet

Be the first to review this server!