Guard Core Mcp

io.github.Guard-Corev1.4.5更新於 Oct 8, 2026

Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.

概覽

AI 產生的概覽

讓編碼助理根據已安裝的 Guard 函式庫回答安全問題:設定驗證、文件檢索與請求內容威脅偵測。

功能
Guard Core MCP 提供面向 Guard 安全生態系的工具。它能回報已安裝的 Guard 函式庫與版本、驗證設定檔(包括 pydantic 默默忽略的拼字錯誤鍵)、說明設定欄位與預設值、檢索並回傳文件頁面,以及判斷某個請求內容是否會被攔截、由哪條規則攔截。它也提供生態系資料:各語言引擎、框架轉接器、遙測代理與 SaaS 擷取契約,以及轉接器安裝與代理接入指引。
適用情境
當助理處理 Guard 函式庫或其 Go、TypeScript、PHP、Rust 對應實作,且需要根據已安裝套件而非模型記憶回答時使用。它最適合排查設定問題、判斷內容是否會被攔截,以及尋找某個框架轉接器經過驗證的整合片段。
執行需求
以 PyPI 套件 guard-core-mcp 透過 stdio 在本機執行,通常用 uv 安裝到專案環境中,以便內省已安裝的 Guard 函式庫。未宣告驗證、環境變數或標頭。生態系工具不需安裝 Python 函式庫即可使用;遠端託管版本是另一套服務。
安裝前請注意
若安裝到隔離環境而非專案環境,回答只能來自內建文件,可能與實際出貨的版本不一致。遠端託管版本需要用 guard-core 帳號登入,並透過託管偵測引擎執行內容,使用的是已發佈版本而非本機版本。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Guard Core Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Guard Core MCP

[PyPI version] [License: MIT] [CI] [Release] [CodeQL] [Docs] [Downloads] [smithery badge]

Website · Docs · Playground · Dashboard

An MCP server that lets AI coding agents answer questions about the Guard security ecosystem from the libraries themselves, instead of from memory.

Covers the whole family: the Python trio (fastapi-guard, guard-core, guard-agent) by live introspection, and the Go, TypeScript, PHP and Rust engines, their twenty framework adapters, their telemetry agents, and the guard-core-app SaaS ingestion contract from a verified registry and knowledge corpus.

Why

Your agent can already read the docs. What it cannot do is tell you that the redis_failopen in your config is silently doing nothing because the real field is redis_fail_open, or that the flag you are reaching for did not exist until guard-core 3.5.0, or whether a given request would actually be blocked and by which pattern.

This server answers those from the installed package: real pydantic validation, real field metadata, and the real detection engine. It also answers the cross-language questions the libraries cannot answer: which package guards a Gin, Fastify, Laravel or Rocket app, whether it is tagged or still path-dependent, how to wire its telemetry agent, and what response codes the SaaS ingest endpoint returns.

Install

Install it into your project's environment, not as an isolated tool:

bash
uv add --dev guard-core-mcpclaude mcp add guard-core -- uv run guard-core-mcp

uvx guard-core-mcp will start, but an isolated environment contains no guard-core or fastapi-guard for it to introspect, so it can only answer from bundled documentation. Running it inside your own environment is what makes the answers match the versions you actually ship.

Tools

ToolAnswers
versionsWhich Guard libraries are installed here, and at what version
validate_configIs this config valid, including typo'd keys pydantic silently ignores
config_fieldsWhat is this setting, what does it default to, does a setting for X exist
search_docsWhere do the docs cover this
get_docThe full text of one documentation page
check_payloadWould this request be blocked, and by which pattern
ecosystemThe full registry matrix: 5 languages, engines, adapters, agents, conformance, SaaS contract
adapter_setupInstall plus a verified minimal integration for one adapter (e.g. go + gin)
wire_agentHow to set up the telemetry agent for a language, including the ingestion contract

The ecosystem tools are pure data, so they work everywhere, with or without the Python libraries installed. Every quick-start snippet is copied verbatim from the sibling repo READMEs, and release_status tells you honestly whether a package is published, tagged, or still untagged (source, main, or path dependency only).

ChatGPT plugin

The same tools are also served remotely at https://mcp.guard-core.com/mcp and packaged as a ChatGPT plugin: sign in with a guard-core account, and ChatGPT can validate configs, search the docs and run payloads through the hosted detection engine (the latest published releases, not your local versions). The packaging lives in plugin/, the hosted server in guard_core_mcp.hosting, and the full story (env vars, Docker image, developer-mode test loop, submission checklist) in the ChatGPT plugin guide.

Licence

MIT

mcp-name: io.github.Guard-Core/guard-core-mcp

來源:README.md,提交 dd1fd84

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.4.5最新Oct 8, 2026