Guardrail MCP

io.github.kadopiv0.0.1更新於 Oct 4, 2026

Deterministic preflight checks for credentials, fund transfers, writes, and prompt overrides.

已驗證Streamable HTTP可網頁執行Security & Monitoring

概覽

AI 產生的概覽

一個唯讀的遠端 MCP 伺服器,對擬執行的動作進行確定性預檢,辨識憑證、資金、寫入與提示覆寫風險。

功能
Guardrail MCP 提供兩個工具:get_guardrail_capabilities 與 assess_action_risk。風險檢查針對一組刻意保持很小的風險模式:憑證暴露、資金移動、外部寫入與指令覆寫,並回傳評估結果。它不執行動作、不保存請求、不驗證使用者、不收取付款、不呼叫 AI,也不存取外部 URL。
適用情境
當助理即將執行有後果的動作、而你希望在繼續之前取得快速且確定性的第二意見時使用,例如審查擬議的轉帳、對外部系統的寫入,或可能包含指令覆寫的文字。
執行需求
一個遠端 Streamable HTTP 端點;未宣告任何套件、帳號、API 金鑰或環境變數。此伺服器為無狀態且唯讀。
安裝前請注意
它只是資訊性預檢,不是安全保證,也不構成法律、財務或安全建議,且只偵測少量模式。它不執行、不保存、不驗證、不收費,因此本身無法強制執行任何限制。部署與任何公開端點都需要另行核准。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Guardrail MCP,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "guardrail-mcp": {
      "type": "http",
      "url": "https://guardrail-mcp.kadopi.workers.dev/mcp"
    }
  }
}

README

Guardrail MCP

Small, free, read-only Remote MCP for deterministic action preflight.

It exposes two tools:

  • get_guardrail_capabilities
  • assess_action_risk

The check detects a deliberately small set of high-risk patterns: credential exposure, fund movement, external writes, and instruction overrides. It does not execute an action, persist a request, authenticate a user, charge a payment, call AI, or fetch external URLs.

Local use

bash
npm run checknpm testnpm run dev

Endpoints: GET /, GET /health, and stateless Streamable HTTP POST /mcp.

Boundary

This is an informational deterministic preflight, not a safety guarantee or legal, financial, or security advice. Deployment and any public endpoint require separate approval.

來源:README.md,提交 5929454

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.0.1最新Sep 16, 2026