Developer · Local MCP server
agentguard
MCP policy proxy: spend caps, approvals for destructive tools, kill switch, dry-run, audit log.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.agentwares/agentguard- Version
- 0.1.3
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-08
- Updated
- 2026-09-08
- Publisher
- agentwares (GitHub) · 8 servers with pages here
- Website
- github.com/agentwares/agentguard/tree/main/apps/agentguard-cli
- Repository
- github.com/agentwares/agentguard (folder apps/agentguard-cli)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npmruntime: npx | @agentwares/agentguard | 0.1.3 | stdio |
How to connect agentguard
agentguard runs locally from a Node.js package published to the npm registry: @agentwares/agentguard version 0.1.3. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @agentwares/agentguard@0.1.3. It reads these environment variables: AGENTGUARD_CONFIG and AGENTGUARD_KILL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"agentguard": {
"command": "npx",
"args": [
"-y",
"@agentwares/agentguard@0.1.3"
],
"env": {
"AGENTGUARD_CONFIG": "<value>",
"AGENTGUARD_KILL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from agentwares (GitHub)
| Server | Runs |
|---|---|
| Agent Access IndexWhether an AI agent may fetch a URL, on what terms, and at what price. Free, no key, no signup. | Remote · HTTP |
| agentcheckSynthetic checks, nightly regression replay and model-drift alerts for AI agents. | Remote · HTTP |
| agentguard — policy proxy for agent tool callsFree spend report from an agent log, no key. Hosted proxies: caps, audit export, buy calls. | Remote · HTTP |
| MCP LivenessWhether a registry MCP server works for a stock client, and what changed in its tools. Free, no key. | Remote · HTTP |
| Readiness scorer — can an agent sign up to your SaaS?Probe a signup URL you own and score whether an AI agent can sign up unaided. | Remote · HTTP |
| Real estate deal memoReal estate deal memo from a US address: AVM, rent, comps, cap rate, cash-on-cash, DSCR, red flags. | Remote · HTTP |
| Stablecoin reserve attestationsStablecoin reserve attestations as JSON: reserves, composition, attestor, on-chain supply, ratio. | Remote & Local · HTTP, stdio |
More developer servers
| Server | Runs |
|---|---|
| Agentforce Action Audit13 rules on a Salesforce Agentforce topic file, before the deploy and before Article 50. | Local · stdio |
| AgentForgeTurn rough requests into rigorously structured prompts, for any coding agent. | Local · stdio |
| agentgateRead-only evidence for the tools agents run: MCP server records, coverage and policy. | Local · stdio |
| AgentglassScan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth. | Remote · HTTP |
| AgentguardAgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits. | Remote · HTTP |
| AgentGuard — security checks for AI agentsSecret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev). | Local · stdio |
| Agentguard47Read-only MCP server for coding-agent traces, alerts, costs, usage, and budget health. | Local · stdio |