1. Conduid
  2. Security
  3. Guardmcp
MCP server · Security

Guardmcp

Security scanner for MCP (Model Context Protocol) servers and configs — tool poisoning, secret leaks, rug-pull detection, excessive permissions, insecure transport.

37Low

Scored 2 days ago · breakdown

About Guardmcp

Guardmcp is an MCP server published by BerkantACUN in the Security category: security scanner for MCP (Model Context Protocol) servers and configs — tool poisoning, secret leaks, rug-pull detection, excessive permissions, insecure transport. It has been installed 0 times through Conduid.

Install

Claude Code
claude mcp add guardmcp -- npx -y guardmcp
npx
npx -y guardmcp

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Guardmcp

Powered by Claude · Grounded in docs

I know everything about Guardmcp. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • ·Scoped permissionsNot checked yet.

Releases

v0.13.0v0.13.0 — resource templates (MCPG-210) and MCP08 from the protocol (MCPG-702) · 7 Sep 2026[0.13.0] — 2026-09-07 Closes the three gaps this project's own docs had been listing as uncovered. Added — MCPG-210, resource templates A resource points at one URI, so a reviewer can look at it. A resource template* names a shape the…
v0.12.0v0.12.0 — three defects found by attacking the tool, not by the test suite · 7 Sep 2026[0.12.0] — 2026-09-07 Three defects found by adversarial testing, not by the test suite. Fixed — a mistyped flag looked like a crash and exited 1 Nine of thirteen argument-validation paths printed a raw Node stack trace and exited **1**.…
v0.11.0v0.11.0 — MCPG-404 was wrong about most servers it reported · 7 Sep 2026[0.11.0] — 2026-09-07 Fixed — MCPG-404 was wrong about most of the servers it reported The rule read the config alone: a remote server with no `Authorization` header was reported as unauthenticated. Measured against the official MCP…
v0.10.0v0.10.0 — remote rug-pull coverage, and a test that was passing for the wrong reason · 7 Sep 2026[0.10.0] — 2026-09-07 Fixed The HTTP test fixture accepted only one session per process**, answering every connection after the first with "Server already initialized". A real Streamable HTTP server builds a transport per session; this one…
v0.9.0v0.9.0 — remote servers, and the request guardmcp will not make · 7 Sep 2026[0.9.0] — 2026-09-06 Added `--live` now scans remote servers.** Until now every HTTP server was skipped with a warning, which meant the servers you trust least — third-party hosted, the enterprise deployment model — were the ones guardmcp…
Questions

About Guardmcp

How do I install Guardmcp?

Run claude mcp add guardmcp -- npx -y guardmcp, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Guardmcp safe to use with an AI agent?

Its trust score is 37 out of 100 (low). Conduid hasn't run static security checks on this repository yet, so review the source yourself before granting it credentials. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Guardmcp still maintained?

Conduid hasn't recorded a commit date for this repository yet. Check the repository directly for recent activity.