Sviluppo · Server MCP locale
Security Proxy
MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.4hmetuyar/security-proxy- Versione
- 1.4.0
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 2 ottobre 2026
- Aggiornato
- 2 ottobre 2026
- Editore
- 4hmetuyar (GitHub) · 26 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/4hmetuyar) · come funziona
- Repository
- github.com/GuardBee/guardbee-mcp (cartella packages/security-proxy)
- Fonte
- Voce nell’API del registro
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npm | @guardbee/mcp-security-proxy | 1.4.0 | stdio |
Come collegare Security Proxy
Security Proxy viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @guardbee/mcp-security-proxy, versione 1.4.0. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @guardbee/mcp-security-proxy@1.4.0.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"security-proxy": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-security-proxy@1.4.0"
]
}
}
}Ricavato dalla voce del registro, non testato qui. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di 4hmetuyar (GitHub)
| Server | Esecuzione |
|---|---|
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Locale · stdio |
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Locale · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Locale · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Locale · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Locale · stdio |
| Secret ScannerScans files for leaked secrets and API keys. | Locale · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Locale · stdio |
| Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting. | Locale · stdio |
| Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks. | Locale · stdio |
| Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress. | Locale · stdio |
| Unbounded Consumption AuditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6) | Locale · stdio |
| Vector Store ScannerProbes vector-database endpoints for unauthenticated exposure of embeddings/RAG data. | Locale · stdio |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| Security Intel MCPCVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys. | Remoto · HTTPVerifica live: ✗ nessun handshake |
| Security MCPZero-key security toolkit: grade sites A+ to F, check CVE exploits, plain-English attack defenses. | Locale · stdio |
| Security OrchestraMulti-agent MCP platform for data centers and critical power. | Locale · stdio |
| Security PreflightStatic MCP, source-code and injection-indicator checks with redacted signed receipts. | Remoto · HTTPVerifica live: ✓ handshake |
| Security RecipesRead-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner. | Remoto · HTTPVerifica live: ✓ handshake |
| Security ToolsFree front-end security check for any website: a grade plus the secrets and keys it exposes. | Remoto · HTTPVerifica live: ✓ handshake |
| Security Txt Cra Lint13 rules that decide whether a vulnerability report ever reaches you. | Locale · stdio |