Latchpoint

io.github.robyrorov0.1.1更新於 Oct 9, 2026

Offline, read-only auditing of MCP client configuration files with redacted findings

概覽

AI 產生的概覽

讓助理以離線、唯讀方式稽核 MCP 用戶端設定檔,並回傳已去識別化的發現結果,可輸出為文字、JSON 或 SARIF。

功能
Latchpoint 會掃描 MCP 用戶端設定檔,但不會執行其中設定的伺服器。它提供 list_rules 與 scan 兩個工具,檢查的規則包括非回送位址端點使用明文 HTTP、shell 包裝器、未固定版本的 npx 或 uvx 套件、字面憑證、過寬的檔案系統範圍、萬用字元主機,以及無效的傳輸設定。每筆發現都帶有穩定的規則 ID、嚴重性、位置、修補建議、已去識別化的證據,以及當判讀取決於被啟動伺服器時提供的信心說明。結果可輸出為文字、JSON 或 SARIF。
適用情境
當你想在安裝伺服器前後檢查 MCP 用戶端設定檔中的風險模式,或把設定檢查加入建置流程時,可以使用它。它適合對本機設定做防禦性審查,而不是對伺服器做執行期測試。
執行需求
本機需要 Python 3.11 或更新版本;可從 PyPI 安裝 mcp-latchpoint,或以 uvx 執行。stdio 伺服器啟動時必須透過 --root 指定允許的根目錄,相對掃描路徑會在該根目錄下解析。未宣告需要帳號、API 金鑰或網路存取。
安裝前請注意
此伺服器為唯讀,只回傳發現結果與掃描中繼資料,不會回傳原始設定內容,也不會執行命令或連線端點。機密偵測旨在輸出欄位名稱與去識別化標記,而非實際值,但報告乾淨並不代表伺服器安全。--root 只應指向你明確信任的目錄,也不要把真實設定附加到公開 issue。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Latchpoint,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

mcp-latchpoint

mcp-latchpoint audits MCP client configuration files without running the configured servers. It works offline, reads only local files you select, and produces text, JSON, or SARIF results.

This is an early defensive tool. Review findings in context before changing a working configuration.

What it checks

The v0.1 rules cover:

  • plain HTTP for non-loopback remote endpoints
  • shell wrappers and inline shell control syntax
  • identifiable npx and uvx packages without exact versions
  • literal credentials in environment values, headers, arguments, or URLs
  • filesystem roots and home roots passed as recognizable access scopes
  • wildcard hosts and recognizable wildcard scopes
  • conflicting, missing, invalid, or unsupported transport settings

Every finding has a stable rule ID, severity, location, remediation, redacted evidence, and a confidence note when interpretation depends on the launched server.

Install

Python 3.11 or newer is required.

console
python -m pip install mcp-latchpoint

To install from a local checkout:

console
python -m venv .venv# Linux or macOS. .venv/bin/activate# Windows PowerShell.venv\Scripts\Activate.ps1python -m pip install .

For development:

console
python -m pip install -e ".[dev]"pytestruff check .mypy

The MCP server uses the official Python SDK v2 and the dependency is constrained to mcp>=2.3,<3.

CLI

Scan one or more explicit files:

console
mcp-latchpoint scan ~/.config/Code/User/mcp.jsonmcp-latchpoint scan examples/risky.json --format jsonmcp-latchpoint scan examples/risky.json --format sarif --fail-on high > results.sarif

Restrict every explicit path to an approved directory:

console
mcp-latchpoint scan ./configs --allowed-root ./configs

Directories are searched only for recognized MCP config filenames, up to 256 files. A file is limited to 1 MiB by default. Change these bounds with --max-files and --max-bytes.

Exit codes are 0 for a completed scan below the chosen threshold, 1 when a finding meets --fail-on, and 2 for input, containment, or parse errors. The default --fail-on none reports findings without failing a build.

List and explain rules:

console
mcp-latchpoint rulesmcp-latchpoint explain MCP004

Recognized layouts

Explicit files may use these structures:

Client layoutContainerAccepted file syntax
Claude Desktop, Cursor, portable .mcp.json, generic MCP JSONtop-level mcpServers objectJSON
Claude Code user/local settingstop-level mcpServers, plus projects.<path>.mcpServers in ~/.claude.jsonJSON
VS Codetop-level servers objectJSONC for .vscode/mcp.json
Codex[mcp_servers.<name>] tablesTOML

Files ending in .jsonc are also parsed as JSONC. Other .json files remain strict JSON so malformed input is not silently accepted.

--discover checks only the following paths when they exist. It does not search the rest of the home directory.

  • All systems: ~/.claude.json, ~/.cursor/mcp.json, ~/.codex/config.toml, $COPILOT_HOME/mcp-config.json with ~/.copilot/mcp-config.json as the fallback
  • Current project: .mcp.json, .codex/config.toml, .cursor/mcp.json, .vscode/mcp.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json, %APPDATA%\Code\User\mcp.json
  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json, ~/Library/Application Support/Code/User/mcp.json
  • Linux: $XDG_CONFIG_HOME/Code/User/mcp.json, falling back to ~/.config/Code/User/mcp.json

Read-only MCP server

The stdio server exposes two tools: list_rules and scan. It requires an allowed root at startup. Relative scan paths are resolved below that root; absolute paths, .. traversal, and symlinks cannot escape it.

console
mcp-latchpoint-server --root /absolute/path/to/reviewed-configsmcp-latchpoint serve --root /absolute/path/to/reviewed-configs

Example client entry:

json
{  "mcpServers": {    "latchpoint": {      "command": "/absolute/path/to/mcp-latchpoint-server",      "args": ["--root", "/absolute/path/to/reviewed-configs"]    }  }}

The server returns findings and scan metadata, never raw configuration content. Stdio is the only server transport exposed by the entry point, and stdout is reserved for MCP protocol messages.

The serve command is also the entry point advertised in the MCP Registry. Set --root to a directory you explicitly trust before connecting a client.

Glama build

The Glama listing builds a container from the repository. In its Dockerfile configuration, use Python 3.13, these build steps and command arguments:

json
["uv sync --no-dev"]
json
["mcp-proxy", "--", "/app/.venv/bin/mcp-latchpoint-server", "--root", "/app/examples"]

The root is an existing directory with synthetic sample configurations. It lets Glama start and inspect the tools without giving the server access to a user's files. The command uses the executable inside the virtual environment created by uv sync. For this demo, the environment-variable schema can be {"type":"object","properties":{}} and placeholder parameters can be {}.

To scan your own configurations, run the server locally with --root pointing to a directory you explicitly trust. Glama's demo root is only for the sample files in examples/.

Safety and limitations

The scanner never executes commands, installs packages, resolves referenced environment variables, or connects to endpoints. It does not follow configuration includes or inspect an MCP server's code or runtime behavior. Argument-based rules are intentionally limited to recognizable patterns, so custom flags can be missed. A clean report is not proof that a server is safe.

Secret detection is designed to emit field names and <redacted> markers rather than values. If you find a leak or a path-containment problem, follow SECURITY.md and do not attach a real configuration to a public issue.

License

MIT. See LICENSE.

來源:README.md,提交 b5f65df

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.1最新Oct 9, 2026