Argos-mcp-guardrail
A lightweight, sub-millisecond security shim that prevents AI agents from accessing sensitive files (.env, SSH keys) and executing destructive commands via MCP.
Install / Use
claude mcp add JUSICK -- npx -y github:JUSICK/Argos-mcp-guardrailIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of Argos-mcp-guardrail
Argos-mcp-guardrail scores 76/100 on our quality scale, 1037th of 1,127 Security skills we index.
Its MCP Server is 5.2 KB long, well organised into 17 sections with 2 code examples: a solid amount of guidance for an agent.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so Argos-mcp-guardrail is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Argos-mcp-guardrail compared with similar skills
All 4 of these similar skills score higher than Argos-mcp-guardrail; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| Argos-mcp-guardrail (this skill)by JUSICK | 76 | 3 | today | MCP Server |
| Agent-Reachby Panniantong | 100 | 93.0k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.1k | today | MCP Server |
Frequently asked questions
- How do I install Argos-mcp-guardrail?
- Run
claude mcp add JUSICK -- npx -y github:JUSICK/Argos-mcp-guardrail. The install tabs above show the steps for each supported agent. - Which AI agents does Argos-mcp-guardrail work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is Argos-mcp-guardrail safe to use?
- It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is Argos-mcp-guardrail still maintained?
- The repository was last updated today, so Argos-mcp-guardrail is actively maintained.
Skill content
View source on GitHubArgos (argos)
Zero-overhead policy enforcement gateway and runtime guardrail for Model Context Protocol (MCP) servers.
argos acts as a transparent security pipe between AI clients (Claude Desktop, Cursor) and underlying MCP tool servers. Inspired by the zero-friction philosophy of Quad9/Pi-hole, it inspects raw JSON-RPC traffic on the fly and deterministically blocks unauthorized file access, path traversal attacks, and destructive commands before they reach your system.
<img width="1734" height="875" alt="image" src="https://github.com/user-attachments/assets/3554e752-14a8-4893-b7af-f4f81800e170" />
Features
- Sub-millisecond Overhead: Built with pure Rust and Tokio asynchronous streams. Zero perceptible lag for the agent or developer.
- Path Traversal Sandboxing: Enforces strict workspace boundaries via OS path canonicalization and
../stripping. - Secret & Sensitive File Shield: Block access to
.env, private keys (id_rsa,id_ed25519), and cloud credentials. - Destructive Command Blocker: Intercepts dangerous terminal commands (
rm -rf, disk formatters, fork bombs). - Local Audit Logging: Records blocked and allowed actions into a structured, JSON-lines log (
argos-audit.log) without cloud telemetry. - Flexible Configuration: Declarative rule customization via
argos.toml. - Your Own Local & Private Tool: Built entirely in Rust as a self-contained, ~1 MB single binary with zero external telemetry or cloud dependencies. Argos relies strictly on deterministic pattern matching, native OS primitives, and JSON-RPC stream interception—ensuring your sensitive code, configuration keys, and audit trails never leave your local machine.
Quick Start
1. Installation
Option A: Pre-built Binaries (Windows & Linux)
Download the latest pre-compiled binary for your system from the Releases page:
- Windows: Download
argos.exe(or unpackargos-windows-x86_64.zip). - Linux: Download and extract
argos-linux-x86_64.tar.gz:tar -xvf argos-linux-x86_64.tar.gz chmod +x argos
Option B: Build from Source (macOS, or any platform)
If you are running macOS (Apple Silicon / Intel) or prefer compiling locally:
git clone [https://github.com/JUSICK/Argos-mcp-guardrail.git](https://github.com/JUSICK/Argos-mcp-guardrail.git)
cd Argos-mcp-guardrail
cargo build --release
The compiled binary will be located at:
- Linux / macOS: target/release/argos
- Windows: target/release/argos.exe
2. Configure policies (argos.toml)
Create and place argos.toml next to the argos executable or in your workspace root:
[filesystem]
# Enforce workspace boundary checks
block_path_traversal = true
# Block access to sensitive files and credentials
blocked_patterns = [".env", ".ssh", "id_rsa", "id_ed25519", "credentials", ".aws", ".npmrc"]
# Explicit exceptions allowed through the policy
allowed_patterns = [".env.example", ".env.sample", ".env.template"]
[commands]
# Block destructive terminal commands
blocked_commands = [
"rm -rf",
"mkfs",
":(){ :|:& };:",
"chmod -R 777",
"dd if="
]
[audit]
enabled = true
# Allows to log ALLOWED processes
log_allowed = false
# Just a file name to create one in the same directory where argos is, or full dir
log_file = "argos-audit.log"
3. Integrate with Claude Desktop or Cursor
Update your claude_desktop_config.json:
Windows Example:
{
"mcpServers": {
"Argos": {
"command": "C:\\path\\to\\argos.exe",
"args": [
"--",
"npx.cmd",
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\\Users\\username\\projects\\my-workspace"
]
}
}
}
MacOS / Linux
{
"mcpServers": {
"Argos": {
"command": "/usr/local/bin/argos",
"args": [
"--",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/projects/my-workspace"
]
}
}
}
Restart Claude Desktop, and Argos will actively guard your tool calls against unauthorized filesystem traversal and credential exposure.
4. How it works:
[ AI Client (Claude / Cursor) ]
│
│ stdin / stdout (JSON-RPC)
▼
┌───────────────────────┐
│ argos │ <── Inspects tools/call in <0.2ms
└───────────────────────┘
│ │
(If Allowed) (If Blocked) ──> Returns JSON-RPC Error & logs event
│
▼
[ Real MCP Tool Server ]
You are able to have as many Argos as you want, change their names e.g. "Argos-Backend", "Argos-Frontend" for a big project that has 2 or more AI agents.
MIT License. Free for personal and commercial use.
Related Skills
Agent-Reach
93.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.6kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.1k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
