
Guardrail MCP
io.github.kadopiv0.0.1更新於 Oct 4, 2026
Deterministic preflight checks for credentials, fund transfers, writes, and prompt overrides.
概覽
一個唯讀的遠端 MCP 伺服器,對擬執行的動作進行確定性預檢,辨識憑證、資金、寫入與提示覆寫風險。
- 功能
- Guardrail MCP 提供兩個工具:get_guardrail_capabilities 與 assess_action_risk。風險檢查針對一組刻意保持很小的風險模式:憑證暴露、資金移動、外部寫入與指令覆寫,並回傳評估結果。它不執行動作、不保存請求、不驗證使用者、不收取付款、不呼叫 AI,也不存取外部 URL。
- 適用情境
- 當助理即將執行有後果的動作、而你希望在繼續之前取得快速且確定性的第二意見時使用,例如審查擬議的轉帳、對外部系統的寫入,或可能包含指令覆寫的文字。
- 執行需求
- 一個遠端 Streamable HTTP 端點;未宣告任何套件、帳號、API 金鑰或環境變數。此伺服器為無狀態且唯讀。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Guardrail MCP,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"guardrail-mcp": {
"type": "http",
"url": "https://guardrail-mcp.kadopi.workers.dev/mcp"
}
}
}README
Guardrail MCP
Small, free, read-only Remote MCP for deterministic action preflight.
It exposes two tools:
get_guardrail_capabilitiesassess_action_risk
The check detects a deliberately small set of high-risk patterns: credential exposure, fund movement, external writes, and instruction overrides. It does not execute an action, persist a request, authenticate a user, charge a payment, call AI, or fetch external URLs.
Local use
Endpoints: GET /, GET /health, and stateless Streamable HTTP POST /mcp.
Boundary
This is an informational deterministic preflight, not a safety guarantee or legal, financial, or security advice. Deployment and any public endpoint require separate approval.
來源:README.md,提交 5929454
工具
0版本歷史
1- v0.0.1最新Sep 16, 2026


