
mcpcut
io.github.RostislavMatovv0.2.3更新于 Oct 1, 2026
Journals every MCP tool call with secrets redacted; with a policy, holds risky calls for approval
安装
在 SourceWeft 中
- 打开 控制台中的 mcpcut,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
mcpcut
[CI] [npm] [License: Apache-2.0]
See every tool call your AI agent makes over MCP, hold the risky ones for your approval, and keep a secret-redacted journal that is tamper-evident with an external anchor.
Self-hosted · Apache-2.0 · Node.js 24+ · two runtime dependencies. Start with one server on your laptop; grow into a control plane for many agents.
Quick start
Requires Node.js 24+ (node -v); on older Node, mcpcut prints one line and exits — install Node 24 with nvm, fnm or volta. Nothing else to install.
See. Put mcpcut in front of a server — here for Claude Code; in any other client, the server's command becomes npx -y [email protected] wrap -- <your server>:
The first start downloads mcpcut and the server; if your client gives up on it, start it once more. Let the agent work, then npx -y [email protected] sessions and npx -y [email protected] show <id>: every request and response, secrets redacted (with a policy, every decision too). --server fs names the server in the journal and the approval queue.
Stop. Save this as policy.json — reads pass, everything else waits for you (quarantine of new tools is off, so the first minute shows one gate: see Quarantine) — and re-add the server with --policy "$PWD/policy.json" right after wrap (claude mcp remove fs first):
A write now waits. Approve it from another terminal within the agent's wait (60 s; after it, the agent's retry passes) — no token needed until you add your first admin (Approvals):
Prove. Sign the history, export it, and check it offline — with nothing but the directory:
The last line signs the chain head: keep what it prints somewhere this host cannot rewrite — the out-of-band anchor is what makes the journal tamper-evident, not the hashes alone.
Grow. npm install -g mcpcut, then mcpcut: a setup wizard, then a server registry, per-agent keys and grants, a credential vault, a web UI, a terminal console and one address per agent (Install and first run).
What you get
- Journal — every request, response and decision, with secrets redacted before anything is written. Optionally fail-closed: no record, no call.
- Policy per tool —
allow,denyorrequire-approvalby server, tool name or tool class; read-only tools can pass on their own. - Approvals — a risky call waits until someone approves it from the CLI, the web UI or the terminal console.
- Quarantine — a new tool, or one whose description or schema changed after you trusted it, is held until reviewed, with a diff of what changed.
- Agents and grants — a registry of servers, a key per agent, per-tool grants, groups, and an encrypted vault, so server credentials never sit in an agent's config.
- One address per agent — every server an agent is granted behind one endpoint; grant or revoke without touching the client.
- Evidence — a hash chain with a signed head, and an audit report anyone can verify offline with a public key.
- Admin UI and terminal console — named admins with
owner,operatorandviewerroles; every change is attributed in the journal.
How it works
Three ways in, one gate:
wrap— in front of one server, with no setup and no identity: the Quick start above.connectandserve— named servers from the registry, a key per agent, credentials from the vault.- The pool (
/mcp) — one address per agent for every server it is granted;connect --urlbridges a stdio client on another machine to it.
The full picture, with the trust boundaries: docs/ARCHITECTURE.md.
Documentation
Status
mcpcut is 0.x. The core — proxy, policy, approvals, quarantine, journal, audit report, admin UI and console — is shipped and covered by tests; Status lists each capability with its evidence.
- Preview: the remote console (
mcpcut --remote) and theconnect --urlbridge. They work and are tested against a VPS over TLS, but they put a token on the network, have had only an internal security review, and may change within 0.x. - Tamper-evident means with an external anchor. A process running as the same OS user can rewrite the journal and re-sign it; only a chain head recorded somewhere this host cannot write exposes that. mcpcut is not tamper-proof, and whether a report satisfies an audit is the auditor's call.
- A brake for mistakes, not a sandbox. An agent that also has a shell as your user can reach the same
approvals approveyou run: an admin token records who approved, it does not stop the same OS user (Approvals). The error a held call returns tells the agent a human must approve and never names the command.
Security
Please report vulnerabilities privately — SECURITY.md says how. The whole product had an internal security audit in September 2026; no independent audit has been done yet.
Contributing
Issues and pull requests are welcome — see CONTRIBUTING.md.
License
Apache-2.0 — see NOTICE.
来源:README.md,提交 4682794
工具
0版本历史
1- v0.2.3最新Oct 1, 2026


