Guard Core Mcp

io.github.Guard-Corev1.4.5更新于 Oct 8, 2026

Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.

概览

AI 生成的概览

让编码助手基于已安装的 Guard 库回答安全问题:配置校验、文档检索和请求载荷威胁检测。

功能
Guard Core MCP 提供面向 Guard 安全生态的工具。它可以报告已安装的 Guard 库及其版本,校验配置文件(包括 pydantic 静默忽略的拼写错误键),说明配置字段及其默认值,检索并返回文档页面,并判断某个请求载荷是否会被拦截以及由哪条规则拦截。它还提供生态数据:各语言引擎、框架适配器、遥测代理和 SaaS 接入契约,以及适配器安装和代理接入指引。
适用场景
当助手处理 Guard 库或其 Go、TypeScript、PHP、Rust 对应实现,并需要基于已安装包而非模型记忆给出答案时使用。它最适合排查配置问题、判断载荷是否会被拦截,以及查找某个框架适配器经过验证的集成片段。
运行要求
以 PyPI 包 guard-core-mcp 通过 stdio 在本地运行,通常用 uv 安装到项目环境中,以便内省已安装的 Guard 库。未声明认证、环境变量或请求头。生态工具无需安装 Python 库即可使用;远程托管版本是另一套服务。
安装前请注意
若安装到隔离环境而非项目环境,回答只能来自内置文档,可能与实际发布的版本不一致。远程托管版本需要用 guard-core 账号登录,并通过托管检测引擎运行载荷,使用的是已发布版本而非本地版本。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Guard Core Mcp,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

Guard Core MCP

[PyPI version] [License: MIT] [CI] [Release] [CodeQL] [Docs] [Downloads] [smithery badge]

Website · Docs · Playground · Dashboard

An MCP server that lets AI coding agents answer questions about the Guard security ecosystem from the libraries themselves, instead of from memory.

Covers the whole family: the Python trio (fastapi-guard, guard-core, guard-agent) by live introspection, and the Go, TypeScript, PHP and Rust engines, their twenty framework adapters, their telemetry agents, and the guard-core-app SaaS ingestion contract from a verified registry and knowledge corpus.

Why

Your agent can already read the docs. What it cannot do is tell you that the redis_failopen in your config is silently doing nothing because the real field is redis_fail_open, or that the flag you are reaching for did not exist until guard-core 3.5.0, or whether a given request would actually be blocked and by which pattern.

This server answers those from the installed package: real pydantic validation, real field metadata, and the real detection engine. It also answers the cross-language questions the libraries cannot answer: which package guards a Gin, Fastify, Laravel or Rocket app, whether it is tagged or still path-dependent, how to wire its telemetry agent, and what response codes the SaaS ingest endpoint returns.

Install

Install it into your project's environment, not as an isolated tool:

bash
uv add --dev guard-core-mcpclaude mcp add guard-core -- uv run guard-core-mcp

uvx guard-core-mcp will start, but an isolated environment contains no guard-core or fastapi-guard for it to introspect, so it can only answer from bundled documentation. Running it inside your own environment is what makes the answers match the versions you actually ship.

Tools

ToolAnswers
versionsWhich Guard libraries are installed here, and at what version
validate_configIs this config valid, including typo'd keys pydantic silently ignores
config_fieldsWhat is this setting, what does it default to, does a setting for X exist
search_docsWhere do the docs cover this
get_docThe full text of one documentation page
check_payloadWould this request be blocked, and by which pattern
ecosystemThe full registry matrix: 5 languages, engines, adapters, agents, conformance, SaaS contract
adapter_setupInstall plus a verified minimal integration for one adapter (e.g. go + gin)
wire_agentHow to set up the telemetry agent for a language, including the ingestion contract

The ecosystem tools are pure data, so they work everywhere, with or without the Python libraries installed. Every quick-start snippet is copied verbatim from the sibling repo READMEs, and release_status tells you honestly whether a package is published, tagged, or still untagged (source, main, or path dependency only).

ChatGPT plugin

The same tools are also served remotely at https://mcp.guard-core.com/mcp and packaged as a ChatGPT plugin: sign in with a guard-core account, and ChatGPT can validate configs, search the docs and run payloads through the hosted detection engine (the latest published releases, not your local versions). The packaging lives in plugin/, the hosted server in guard_core_mcp.hosting, and the full story (env vars, Docker image, developer-mode test loop, submission checklist) in the ChatGPT plugin guide.

Licence

MIT

mcp-name: io.github.Guard-Core/guard-core-mcp

来源:README.md,提交 dd1fd84

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.4.5最新Oct 8, 2026