Guard · MCP security
MCP security
Five defenses over the MCP servers you have already configured. No server is ever executed to check it. Drift alerts catch a server definition changing under you. An allowlist pins the exact configuration you approved. Canaries plant a non-functional honeytoken and fire if it turns up in a configured MCP server's command, arguments, or URL. The red-team runner attacks your own setup with a tool-poisoning library. Skill supply chain signs and verifies what each skill and subagent is allowed to do.
Start here if you want to see what is exposed in a repo and whether it is contained: Security.
Where to find it
- Localhost:
/mcp-security.html - API:
GET /api/mcp-security/alerts(drift alerts plus the allowlist verdict for every configured server),POST /api/mcp-security/alerts/dismiss,POST /api/mcp-security/allow,GET /api/mcp-security/canary,POST /api/mcp-security/redteam,GET /api/skills/manifest - CLI:
repoops skills signandrepoops skills verify - Navigation: AI Security in the sidebar, then MCP security under All tools, in the MCP and tool inventory group. The page answers at its URL either way.
What it does for you
REPOOPS_MCP_ALLOWLIST_BLOCK=1 is set. Drift becomes a standing watch you dismiss deliberately, not a line in a log.Built vs. planned
All five sections ship today. Each manifest carries an Ed25519 signature under the per-install attestation key beside the HMAC ledger signature; a record holding only the HMAC signature verifies as weaker, not as plain verified. Either way the check catches an out-of-band change by something that does not hold the key, and a local key holder can still re-sign a file they edited. The surface says so rather than implying more. The inventory records environment variable names so a server's secrets can be named; values are never read. LLM-free throughout.
Read more
Last updated