Developer · Local MCP server
Security Proxy
MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/security-proxy- Version
- 1.4.0
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-10-02
- Updated
- 2026-10-02
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/security-proxy)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-security-proxy | 1.4.0 | stdio |
How to connect Security Proxy
Security Proxy runs locally from a Node.js package published to the npm registry: @guardbee/mcp-security-proxy version 1.4.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-security-proxy@1.4.0.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"security-proxy": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-security-proxy@1.4.0"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Local · stdio |
| Oauth AuditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. | Local · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Local · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Local · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Local · stdio |
| Secret ScannerScans files for leaked secrets and API keys. | Local · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Local · stdio |
| Slopsquat ScannerChecks declared npm/PyPI dependencies against real registries to catch slopsquatting. | Local · stdio |
| Tool Poisoning ScannerScans MCP tool definitions for hidden instructions and confused-deputy sinks. | Local · stdio |
| Toxic Flow AuditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress. | Local · stdio |
| Unbounded Consumption AuditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6) | Local · stdio |
| Vector Store ScannerProbes vector-database endpoints for unauthenticated exposure of embeddings/RAG data. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| Security Intel MCPCVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys. | Remote · HTTP |
| Security MCPZero-key security toolkit: grade sites A+ to F, check CVE exploits, plain-English attack defenses. | Local · stdio |
| Security OrchestraMulti-agent MCP platform for data centers and critical power. | Local · stdio |
| Security PreflightStatic MCP, source-code and injection-indicator checks with redacted signed receipts. | Remote · HTTP |
| Security ToolsFree front-end security check for any website: a grade plus the secrets and keys it exposes. | Remote · HTTP |
| Security Txt Cra Lint13 rules that decide whether a vulnerability report ever reaches you. | Local · stdio |
| SecurityScanScan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10. | Remote · HTTP |