
Guard Core Mcp
io.github.Guard-Corev1.4.5Updated Oct 8, 2026
Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.
Overview
Lets coding agents answer Guard security questions from installed libraries: config validation, docs search, and payload threat checks.
- What it does
- Guard Core MCP exposes tools for the Guard security ecosystem. It reports installed Guard library versions, validates configuration files including silently ignored typo'd keys, describes config fields and defaults, searches and returns documentation pages, and checks whether a request payload would be blocked and by which pattern. It also serves ecosystem data: language engines, framework adapters, telemetry agents, and the SaaS ingestion contract, plus adapter setup and agent wiring guidance.
- When to use it
- Use it when an assistant is working with Guard libraries or their Go, TypeScript, PHP and Rust counterparts and needs answers grounded in the installed package rather than model memory. It is most useful for debugging configuration, checking whether a payload would be blocked, and finding verified integration snippets for a specific framework adapter.
- Requirements
- Runs locally over stdio as the PyPI package guard-core-mcp, typically installed into the project environment with uv so it can introspect the installed Guard libraries. No authentication, environment variables, or headers are declared. The ecosystem tools work without the Python libraries installed; the remote hosted variant is separate.
Installation
In SourceWeft
- Open Guard Core Mcp in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Guard Core MCP
[PyPI version] [License: MIT] [CI] [Release] [CodeQL] [Docs] [Downloads] [smithery badge]
Website · Docs · Playground · Dashboard
An MCP server that lets AI coding agents answer questions about the Guard security ecosystem from the libraries themselves, instead of from memory.
Covers the whole family: the Python trio (fastapi-guard, guard-core, guard-agent) by live introspection, and the Go, TypeScript, PHP and Rust engines, their twenty framework adapters, their telemetry agents, and the guard-core-app SaaS ingestion contract from a verified registry and knowledge corpus.
Why
Your agent can already read the docs. What it cannot do is tell you that the redis_failopen in your config is silently doing nothing because the real field is redis_fail_open, or that the flag you are reaching for did not exist until guard-core 3.5.0, or whether a given request would actually be blocked and by which pattern.
This server answers those from the installed package: real pydantic validation, real field metadata, and the real detection engine. It also answers the cross-language questions the libraries cannot answer: which package guards a Gin, Fastify, Laravel or Rocket app, whether it is tagged or still path-dependent, how to wire its telemetry agent, and what response codes the SaaS ingest endpoint returns.
Install
Install it into your project's environment, not as an isolated tool:
uvx guard-core-mcp will start, but an isolated environment contains no guard-core or fastapi-guard for it to introspect, so it can only answer from bundled documentation. Running it inside your own environment is what makes the answers match the versions you actually ship.
Tools
The ecosystem tools are pure data, so they work everywhere, with or without the Python libraries installed. Every quick-start snippet is copied verbatim from the sibling repo READMEs, and release_status tells you honestly whether a package is published, tagged, or still untagged (source, main, or path dependency only).
ChatGPT plugin
The same tools are also served remotely at https://mcp.guard-core.com/mcp and packaged as a ChatGPT plugin: sign in with a guard-core account, and ChatGPT can validate configs, search the docs and run payloads through the hosted detection engine (the latest published releases, not your local versions). The packaging lives in plugin/, the hosted server in guard_core_mcp.hosting, and the full story (env vars, Docker image, developer-mode test loop, submission checklist) in the ChatGPT plugin guide.
Licence
MIT
mcp-name: io.github.Guard-Core/guard-core-mcp
Source: README.md at commit dd1fd84
Tools
0Version history
1- v1.4.5LatestOct 8, 2026


