mcp-guard
Stop AI agents from doing dangerous things through MCP. Wraps any MCP server with allow/block/hold-for-approval guardrails.
Install / Use
claude mcp add sidclawhq -- npx -y github:sidclawhq/mcp-guardIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of mcp-guard
mcp-guard scores 81/100 on our quality scale, 2043rd of 3,551 Development & Engineering skills we index.
Its MCP Server is 6.5 KB long, well organised into 18 sections with 10 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 3 months ago, so mcp-guard is actively maintained.
- Our last check on 2026-09-18 found the source still online.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
mcp-guard compared with similar skills
All 4 of these similar skills score higher than mcp-guard; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| mcp-guard (this skill)by sidclawhq | 81 | 3 | 3mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 86.2k | 14d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.1k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install mcp-guard?
- Run
claude mcp add sidclawhq -- npx -y github:sidclawhq/mcp-guard. The install tabs above show the steps for each supported agent. - Which AI agents does mcp-guard work with?
- It is written for Claude Code, Claude Desktop and Cursor, as a MCP Server file. Other agents that read the same format can often use it too.
- Is mcp-guard safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is mcp-guard still maintained?
- The repository was last updated about 3 months ago, so mcp-guard is actively maintained.
Skill content
View source on GitHubGet started
See it in action (30 seconds)
npx sidclaw-mcp-guard@latest demo
Set up a real guarded MCP server (2 minutes)
npx sidclaw-mcp-guard@latest quickstart
Creates a config, writes .mcp.json for Claude Code, and starts the approval dashboard.
Policy rules — no regex needed
Rules use semantic patterns — human-readable shortcuts instead of raw regex:
# sidclaw.config.yaml
rules:
- name: allow-reads
description: Read-only queries are safe
match:
pattern: sql-read # SELECT, EXPLAIN, SHOW
action: allow
- name: approve-writes
description: Data changes need approval
match:
pattern: sql-write # INSERT, UPDATE, DELETE
action: approve
- name: deny-destructive
description: Schema changes are never allowed
match:
pattern: sql-destructive # DROP, TRUNCATE, ALTER, CREATE
action: deny
default: deny
Available patterns: sql-read, sql-write, sql-destructive, file-read, file-write, file-delete, shell-safe, shell-risky, shell-destructive.
Note: In config, the action is called
approve(what the user writes). In output, it displays asHOLD(describing the state of the call while waiting for human review).
Power users can still use regex via match.args — see docs/config.md.
Approve from your browser
Every guard instance can run a local approval dashboard:
sidclaw-mcp-guard --ui --upstream npx --upstream-args "..."
Open http://localhost:9091 — see pending requests, approve or deny with one click, inspect the audit trail.
Or use the CLI: npx sidclaw-mcp-guard approve <id>
Plain-English explanations
Every decision explains itself:
✔ ALLOW SELECT * FROM users
Allowed: read query on users. Read-only queries are safe.
⏳ HOLD DELETE FROM users WHERE id = 42
Held for approval: delete from users. Data changes need approval.
✘ BLOCK DROP TABLE users
Blocked: drop users. Schema changes are never allowed.
Explanations appear in the terminal, dashboard, and audit log.
Observe mode
Test your policies without blocking anything:
sidclaw-mcp-guard --observe --upstream npx --upstream-args "..."
The guard evaluates every call and logs what it would do, but forwards all calls regardless. Switch to enforce mode when ready.
Audit trail
Every decision is logged to .sidclaw/audit.jsonl:
{"timestamp":"...","tool":"query","args":{"sql":"SELECT * FROM users"},"decision":"allow","rule":"allow-reads","explanation":"Allowed: read query on users. Read-only queries are safe."}
{"timestamp":"...","tool":"query","args":{"sql":"DELETE FROM users WHERE id=42"},"decision":"approve","rule":"approve-writes","status":"approved","explanation":"Held for approval: delete from users. Data changes need approval."}
{"timestamp":"...","tool":"query","args":{"sql":"DROP TABLE users"},"decision":"deny","rule":"deny-destructive","explanation":"Blocked: drop users. Schema changes are never allowed."}
Works with any MCP server
| Server | What you're guarding | Example config |
|--------|---------------------|----------------|
| @modelcontextprotocol/server-postgres | SQL queries | examples/sql-demo |
| @modelcontextprotocol/server-filesystem | File operations | examples/filesystem-demo |
| Shell-execution servers | Shell commands | examples/shell-demo |
| @modelcontextprotocol/server-github | Repo operations | |
| Any custom MCP server | Any tool calls | |
CLI
# Get started
sidclaw-mcp-guard quickstart Set up a real guarded MCP server
sidclaw-mcp-guard demo Quick policy showcase
sidclaw-mcp-guard demo -i Interactive — try your own SQL
# Run
sidclaw-mcp-guard --upstream <cmd> Start the guard proxy
sidclaw-mcp-guard --ui Start proxy + approval dashboard
sidclaw-mcp-guard --observe Observe mode (log only)
# Approvals
sidclaw-mcp-guard ui Open the approval dashboard
sidclaw-mcp-guard approve <id> Approve a pending request
sidclaw-mcp-guard deny <id> Deny a pending request
sidclaw-mcp-guard list List pending approvals
sidclaw-mcp-guard clean Remove stale approval files
Full Platform
SidClaw Guard is the local-first entry point to SidClaw. When you need more:
| Need | SidClaw Guard (this) | SidClaw Platform | |------|---------------------|------------------| | Policy rules | YAML with semantic patterns | Visual policy editor | | Approvals | Local dashboard + CLI | Dashboard + Slack + Teams + Telegram | | Audit trail | Local JSONL | Hash-chained, exportable, compliance-ready | | Team workflows | Single user | Multi-reviewer, role-based access | | Integrations | MCP servers | 15+ SDKs (LangChain, Vercel AI, CrewAI...) |
Docs
Development
git clone https://github.com/sidclawhq/mcp-guard.git
cd mcp-guard
npm install
npm run build
npm test
Run locally:
node dist/cli.js demo
node dist/cli.js quickstart
License
Apache 2.0
Related Skills
Agent-Reach
86.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.1kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.5k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
