Agentโ™ฅ๏ธŽAge
Catalog

Aguara MCP

Official

by garagon ยท Go

Scan skills, MCP configs, and agent content for injection and supply-chain risks. Offline, no LLM.

Aguara MCP (io.github.garagon/mcp-aguara)

Aguara MCP provides local security checks for AI agents to review untrusted agent content before using third-party tools. It scans skills, MCP configurations, and agent content for injection and supply-chain risks. The server runs offline and performs checks inside the MCP server, returning structured results.

๐Ÿ› ๏ธ Key Features

  • Scan skills, MCP configs, and agent content for injection and supply-chain risks
  • Local tool for reviewing untrusted agent content before acting
  • Structured verdict with findings, severity, remediation, and the triggered rule
  • No LLM calls, no network access, no subprocess to the aguara binary

๐Ÿš€ Use Cases

  • Inspect a skill before an agent trusts it
  • Review a plugin README
  • Validate tool configuration before installation
  • Gate MCP server installation through a local review step

โšก Developer Benefits

  • Provides deterministic, offline security checks
  • Integrates with Claude Code, Cursor, Windsurf, and any MCP-compatible agent

โš ๏ธ Limitations

  • Designed for local/offline inspection only (no network access, no LLM involvement)

Topics

ai-agentsai-securityclaudeclaude-codegolangmcpmcp-servermodel-context-protocolprompt-injectionsecuritystatic-analysisaguara

Related servers

More in Security