ZeroXLauren/scopeblind-gateway

Security gateway for MCP servers. Shadow-mode logs, per-tool policies, optional Ed25519-signed receipts. npx protect-mcp -- node server.js

★ 0Forks 0GitHub ↗Compare

Project website ↗

README

ScopeBlind

Security gateway for MCP servers.
Shadow-mode logs. Per-tool policies. Optional signed receipts.

Website · MCP Docs · npm · Verify a Receipt · The Stack

License npm protect-mcp Tests


Progressive Adoption

Start with visibility. Add control when ready. Sign when you want proof. Each step is independently valuable.

# 1. Shadow — see what's happening (blocks nothing)
npx protect-mcp -- node your-server.js

# 2. Simulate — test a policy against recorded tool calls
npx protect-mcp simulate --policy strict.json

# 3. Enforce — apply the policy
npx protect-mcp --policy strict.json --enforce -- node your-server.js

# 4. Sign — generate keys, produce signed receipts
npx protect-mcp init

# 5. Report — generate a compliance report
npx protect-mcp report --period 30d --format md --output report.md

# 6. Verify — prove it to anyone, offline
npx @veritasacta/verify --self-test

What ships today

  • Shadow mode (default) — logs every tool call, blocks nothing
  • Enforce mode — per-tool policies: block, rate_limit, min_tier, require_approval
  • Approval gates — high-risk tools pause for human approval (non-blocking, request_id scoped)
  • Optional local signing — Ed25519-signed receipts for every decision
  • Simulate — dry-run a policy against your recorded log before enforcing
  • Report — compliance report from receipts (JSON or Markdown)
  • Bundle export — self-contained audit bundles with embedded verification keys
  • Demo — npx protect-mcp demo runs a built-in MCP server with the gateway
  • Verification — npx @veritasacta/verify --self-test (MIT, offline, no accounts)

Capability boundaries

  • Bare npx protect-mcp -- ... logs decisions without signing. Run protect-mcp init for signed receipts.
  • Trust tiers are live but manifest admission defaults to unknown unless set programmatically.
  • External PDP adapters (OPA, Cerbos) and credential vault are exported as programmatic hooks.

Policy file

{
  "tools": {
    "delete_database": { "block": true },
    "send_email": { "require_approval": true },
    "write_file": { "min_tier": "signed-known", "rate_limit": "10/minute" },
    "*": { "rate_limit": "100/hour" }
  },
  "signing": {
    "key_path": "./keys/gateway.json",
    "enabled": true
  }
}

Claude Desktop / Cursor config

{
  "mcpServers": {
    "my-server": {
      "command": "npx",
      "args": ["protect-mcp", "--policy", "protect-mcp.json", "--enforce", "--", "node", "my-server.js"]
    }
  }
}

Works with Claude Desktop, Cursor, VS Code, OpenClaw — any client that speaks MCP over stdio.


The Trust Stack

ScopeBlind is part of a three-layer evidence infrastructure. Each layer is independently useful and survives the failure of every other layer.

Layer What License
BlindLLM Coordination lab — blind AI battles, agent studio blindllm.com
ScopeBlind Commercial enforcement — policies, receipts, approval gates FSL-1.1-MIT
Veritas Acta Open evidence protocol — format, verifier, constitution MIT

See the full stack →

Packages

Package npm Purpose
protect-mcp npm MCP security gateway
@scopeblind/passport npm Agent identity + pack builder
@scopeblind/red-team npm Policy benchmark runner
@veritasacta/protocol npm Evidence protocol (12 receipt types)
@veritasacta/verify npm MIT offline verifier
@scopeblind/verify-mcp npm MCP server for verification

License

Source-available under the Functional Source License (FSL-1.1-MIT). Free to use, modify, and self-host. You may not offer a competing hosted service. After 2 years, each version converts to MIT. Verification tools (@veritasacta/verify, @veritasacta/protocol) are MIT from day one.


Built by tomjwxf

Contributors

ZeroXLaurentomjwxfpunkpeye

Issues