{"_id":"@aiclude/mcp-guard","_rev":"4-b3677d5b73874e191099f03fbae2a5c8","name":"@aiclude/mcp-guard","dist-tags":{"latest":"0.2.3"},"versions":{"0.2.0":{"name":"@aiclude/mcp-guard","version":"0.2.0","keywords":["mcp","security","proxy","guard","tool-poisoning","prompt-injection","model-context-protocol"],"author":{"name":"AIclude","email":"dev@aiclude.com"},"license":"Apache-2.0","_id":"@aiclude/mcp-guard@0.2.0","maintainers":[{"name":"aiclude","email":"admdev@aiclude.com"}],"homepage":"https://github.com/aiclude/mcp-guard#readme","bugs":{"url":"https://github.com/aiclude/mcp-guard/issues"},"bin":{"mcp-guard":"dist/index.js"},"dist":{"shasum":"99cd8badd41328dacd36a21e46659ae99434045c","tarball":"https://registry.npmjs.org/@aiclude/mcp-guard/-/mcp-guard-0.2.0.tgz","fileCount":5,"integrity":"sha512-bNrMnvpPs83WQeF5/Cu9wPBe5j8Pg/ZjEaGelOeYRqyKgh0V3oHAPc1G8/GCA/C2A6upQ9fhJzjPUsaOFZd/mg==","signatures":[{"sig":"MEQCIAMbLVbhpqeQsAcXYtfBrJeeB7wC599RrJFxPXQwimHZAiAW4TP70X2y0/hO5OLbZ9SpkvC7MnakJUdQ6dUWK9ZuTA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75640},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"fd5f03c7347f2913748d49d356c82d4277bdfa73","scripts":{"dev":"tsup src/index.ts --format esm --dts --watch","test":"vitest run","build":"tsup src/index.ts --format esm --dts --shims","clean":"rm -rf dist","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"aiclude","email":"admdev@aiclude.com"},"repository":{"url":"git+https://github.com/aiclude/mcp-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"MCP runtime security proxy — intercepts and enforces security policies on MCP tool calls","directories":{},"_nodeVersion":"20.20.0","dependencies":{"yaml":"^2.4.0","commander":"^12.0.0","cross-spawn":"^7.0.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0","@types/cross-spawn":"^6.0.6"},"_npmOperationalInternal":{"tmp":"tmp/mcp-guard_0.2.0_1775102816178_0.024162431688677932","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@aiclude/mcp-guard","version":"0.2.1","keywords":["mcp","security","proxy","guard","tool-poisoning","prompt-injection","model-context-protocol"],"author":{"name":"AIclude","email":"dev@aiclude.com"},"license":"Apache-2.0","_id":"@aiclude/mcp-guard@0.2.1","maintainers":[{"name":"aiclude","email":"admdev@aiclude.com"}],"homepage":"https://vs.aiclude.com/mcp-guard","bugs":{"url":"https://github.com/mastergear4824/mcp-guard/issues"},"bin":{"mcp-guard":"dist/index.js"},"dist":{"shasum":"e26ba7c9f79e90eb5941ebacf057eca16f40e67c","tarball":"https://registry.npmjs.org/@aiclude/mcp-guard/-/mcp-guard-0.2.1.tgz","fileCount":5,"integrity":"sha512-+YCdX3E3hI3fh5CFpZ9MQ2Y7IG1BwxAnrzg5CM8qKZaHrIwlRvLXhKpQJ1IkHrCRHYw6ik+ZlgTLF73epXy0lw==","signatures":[{"sig":"MEUCIQDyF6oRe38N+tk7F/5YC3MaH7Dvb1B++jZGEbpiHmfy6gIgFuM0PSDYp0HBOTVFN3x04Gb/HxzivC4/vCZpcyAbQ7U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84975},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f0610c1e6caca9075f260452484509c84d9dbf9a","scripts":{"dev":"tsup src/index.ts --format esm --dts --watch","test":"vitest run","build":"tsup src/index.ts --format esm --dts --shims","clean":"rm -rf dist","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"aiclude","email":"admdev@aiclude.com"},"repository":{"url":"git+https://github.com/mastergear4824/mcp-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"MCP runtime security proxy — intercepts and enforces security policies on MCP tool calls","directories":{},"_nodeVersion":"20.20.0","dependencies":{"yaml":"^2.4.0","commander":"^12.0.0","cross-spawn":"^7.0.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0","@types/cross-spawn":"^6.0.6"},"_npmOperationalInternal":{"tmp":"tmp/mcp-guard_0.2.1_1775104988661_0.9769686221643679","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@aiclude/mcp-guard","version":"0.2.2","keywords":["mcp","security","proxy","guard","tool-poisoning","prompt-injection","model-context-protocol"],"author":{"name":"AIclude","email":"dev@aiclude.com"},"license":"Apache-2.0","_id":"@aiclude/mcp-guard@0.2.2","maintainers":[{"name":"aiclude","email":"admdev@aiclude.com"}],"homepage":"https://vs.aiclude.com/mcp-guard","bugs":{"url":"https://github.com/mastergear4824/mcp-guard/issues"},"bin":{"mcp-guard":"dist/index.js"},"dist":{"shasum":"46b27c98a894c1369cb267e220d897c9ba0b3792","tarball":"https://registry.npmjs.org/@aiclude/mcp-guard/-/mcp-guard-0.2.2.tgz","fileCount":5,"integrity":"sha512-bj99vh0rrMJCXwH5qeE2jakyi2Kr3+XqEc9wpONRNKhK2BM97qEzuO1nKYdJ6kKswOKXUvZuHx/mwP9UbV18HQ==","signatures":[{"sig":"MEUCIQD5nOGo3SqCejmBtfMS4Bq37gXijZfZgQbCA4FZOB3J2gIgehZIQOYGH06ODOLCEuDF418GemB8psgeOUsXwin+lk8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84693},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"32ae388e084f1aceac9bfc58326a4c94a0f0e4fa","scripts":{"dev":"tsup src/index.ts --format esm --dts --watch","test":"vitest run","build":"tsup src/index.ts --format esm --dts --shims","clean":"rm -rf dist","start":"node dist/index.js","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"aiclude","email":"admdev@aiclude.com"},"repository":{"url":"git+https://github.com/mastergear4824/mcp-guard.git","type":"git"},"_npmVersion":"10.8.2","description":"MCP runtime security proxy — intercepts and enforces security policies on MCP tool calls","directories":{},"_nodeVersion":"20.20.0","dependencies":{"yaml":"^2.4.0","commander":"^12.0.0","cross-spawn":"^7.0.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0","@types/cross-spawn":"^6.0.6"},"_npmOperationalInternal":{"tmp":"tmp/mcp-guard_0.2.2_1775105266289_0.03750302591332866","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@aiclude/mcp-guard","version":"0.2.3","description":"MCP runtime security proxy — intercepts and enforces security policies on MCP tool calls","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","bin":{"mcp-guard":"dist/index.js"},"exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"keywords":["mcp","security","proxy","guard","tool-poisoning","prompt-injection","model-context-protocol"],"license":"Apache-2.0","author":{"name":"AIclude","email":"dev@aiclude.com"},"homepage":"https://vs.aiclude.com/mcp-guard","repository":{"type":"git","url":"git+https://github.com/mastergear4824/mcp-guard.git"},"engines":{"node":">=20.0.0"},"publishConfig":{"access":"public"},"scripts":{"build":"tsup src/index.ts --format esm --dts --shims","dev":"tsup src/index.ts --format esm --dts --watch","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","clean":"rm -rf dist","prepublishOnly":"npm run build"},"dependencies":{"commander":"^12.0.0","cross-spawn":"^7.0.6","yaml":"^2.4.0"},"devDependencies":{"@types/cross-spawn":"^6.0.6","@types/node":"^22.0.0","tsup":"^8.0.0","typescript":"^5.5.0","vitest":"^2.0.0"},"_id":"@aiclude/mcp-guard@0.2.3","gitHead":"0577dcfb65d41eec3f4fcd972d9cc04fc440bd8c","bugs":{"url":"https://github.com/mastergear4824/mcp-guard/issues"},"_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-lRMRgx3CL+bkUuSklKlnGWAcHDW6EOe4C2oARz9V7nvJcXmhiXHrVAW+Cc2vg3wzJKxqenR3KEW78vmhRPTNtQ==","shasum":"928e1055860c78db2276c0c7e76c3142c3a25caa","tarball":"https://registry.npmjs.org/@aiclude/mcp-guard/-/mcp-guard-0.2.3.tgz","fileCount":5,"unpackedSize":85230,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAzAXeioSK/dA3UdGhbI36+QvhVIQENws00LnfBM4WV9AiAf6vkqD4Rl7A+AW5aF8ReI5/XbS3DNE/BrCqUPpUJWmA=="}]},"_npmUser":{"name":"aiclude","email":"admdev@aiclude.com"},"directories":{},"maintainers":[{"name":"aiclude","email":"admdev@aiclude.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-guard_0.2.3_1775109674020_0.3525840204844566"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-02T04:06:56.006Z","modified":"2026-04-02T06:01:14.322Z","0.2.0":"2026-04-02T04:06:56.362Z","0.2.1":"2026-04-02T04:43:08.812Z","0.2.2":"2026-04-02T04:47:46.424Z","0.2.3":"2026-04-02T06:01:14.188Z"},"bugs":{"url":"https://github.com/mastergear4824/mcp-guard/issues"},"author":{"name":"AIclude","email":"dev@aiclude.com"},"license":"Apache-2.0","homepage":"https://vs.aiclude.com/mcp-guard","keywords":["mcp","security","proxy","guard","tool-poisoning","prompt-injection","model-context-protocol"],"repository":{"type":"git","url":"git+https://github.com/mastergear4824/mcp-guard.git"},"description":"MCP runtime security proxy — intercepts and enforces security policies on MCP tool calls","maintainers":[{"name":"aiclude","email":"admdev@aiclude.com"}],"readme":"# MCP Guard\n\n**Real-time security firewall for AI agents**\n\nMCP Guard is an inline security proxy that sits between MCP clients and servers. It inspects every message in real-time and blocks malicious tool calls before they reach the server.\n\n[![npm version](https://img.shields.io/npm/v/@aiclude/mcp-guard.svg)](https://www.npmjs.com/package/@aiclude/mcp-guard)\n[![License](https://img.shields.io/badge/license-Apache%202.0-blue.svg)](LICENSE)\n\n---\n\n## Why MCP Guard?\n\nIn 2026, **MCP (Model Context Protocol)** has become the de facto standard for AI agents to interact with external systems. Claude, Cursor, Copilot, and other major AI tools use MCP to connect to databases, APIs, file systems, and cloud services.\n\n**But MCP communication is unprotected.**\n\n- **30+ CVEs** reported in Jan–Feb 2026 alone\n- **92% exploit probability** with just 10 MCP plugins installed ([VentureBeat](https://venturebeat.com))\n- **OWASP MCP Top 10** published — Tool Poisoning, Prompt Injection, Context Spoofing confirmed as real attack vectors\n\nExisting security tools (WAF, SAST, DAST) don't understand MCP protocol semantics. A WAF can see HTTP requests, but it cannot detect MCP-specific attacks like zero-width character hiding in tool descriptions, tool name spoofing, or prompt injection embedded in tool definitions. In stdio mode, traffic doesn't even use HTTP — it's completely off the radar.\n\n> **MCP Guard** inspects all messages in real-time and **blocks dangerous tool calls before they reach the server**.\n\n---\n\n## Quick Start\n\n### Install\n\n```bash\nnpm install -g @aiclude/mcp-guard\n```\n\n### stdio mode — Protect a local MCP server\n\n```bash\nmcp-guard -- npx @modelcontextprotocol/server-fetch\n```\n\n### HTTP mode — Protect a remote MCP server\n\n```bash\nmcp-guard http --upstream http://mcp-server:8080/mcp --port 9090\n```\n\n### Claude Desktop Integration\n\nAdd to your `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"fetch-guarded\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiclude/mcp-guard\", \"--\", \"npx\", \"-y\", \"@modelcontextprotocol/server-fetch\"]\n    }\n  }\n}\n```\n\n### Cursor IDE Integration\n\nAdd to `.cursor/mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"my-server-guarded\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiclude/mcp-guard\", \"--\", \"npx\", \"-y\", \"@some/mcp-server\"]\n    }\n  }\n}\n```\n\n### Claude Code (CLI) Integration\n\n```bash\nclaude mcp add my-server-guarded -- npx -y @aiclude/mcp-guard -- npx -y @some/mcp-server\n```\n\nOr edit `~/.claude/claude_code_config.json` directly:\n\n```json\n{\n  \"mcpServers\": {\n    \"fetch-guarded\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiclude/mcp-guard\", \"--\", \"npx\", \"-y\", \"@modelcontextprotocol/server-fetch\"]\n    }\n  }\n}\n```\n\n---\n\n## Key Features\n\n### 3 Security Rule Engines\n\n| Rule | Inspects | Threats Addressed |\n|------|----------|-------------------|\n| **Tool Poisoning Detection** | Tool definitions from server | Zero-width steganography, prompt injection, homoglyph spoofing, name shadowing |\n| **Argument Injection Detection** | Tool call arguments from client | SQL / Command / XSS / Path Traversal / Template injection (21+ patterns) |\n| **Data Exfiltration Detection** | Tool responses from server | Credential leaks, system path exposure, stack trace disclosure |\n\n### Multilingual Threat Detection\n\nDetects prompt injection phrases in **English, Korean, Chinese, and Japanese**. Normalizes Cyrillic/Greek homoglyphs to block character-disguise bypass attacks.\n\n### Dual Protocol Support\n\n| Mode | Use Case | Target |\n|------|----------|--------|\n| **stdio** | Wrap local MCP server processes | Claude Desktop, Cursor, etc. |\n| **HTTP** | Reverse proxy for remote MCP servers | Streamable HTTP + Legacy SSE |\n\n### Zero Configuration\n\nWorks out of the box with built-in default policies. Customize with YAML policy files when needed.\n\n---\n\n## Protection Coverage\n\n| Tool Definitions (server → client) | Tool Call Arguments (client → server) | Tool Responses (server → client) |\n|:-----------------------------------|:--------------------------------------|:---------------------------------|\n| Zero-width steganography | SQL Injection | Credential exposure |\n| Prompt injection phrases | Command Injection | System path leaks |\n| Homoglyph spoofing | Path Traversal | Stack trace exposure |\n| HTML comment hiding | XSS | Command exec evidence |\n| Base64 encoding hiding | Template Injection | Template injection results |\n| Name shadowing | Prompt injection | Credential leaks |\n| Multilingual injection | Multilingual injection | |\n| Agent manipulation patterns | Zero-width char hiding | |\n| InputSchema validation | | |\n\n**CWE Coverage:** CWE-22, CWE-78, CWE-79, CWE-89, CWE-94, CWE-200, CWE-209\n\n**OWASP MCP Top 10:** Tool Poisoning, Prompt Injection, and more\n\n---\n\n## How It Works\n\nMCP Guard operates as a **transparent proxy** between client and server.\n\n### stdio Mode\n\n> **MCP Client** → *stdio* → **MCP Guard (Proxy)** → *stdio* → **MCP Server (Local)**\n>\n> All messages pass through the **Rule Engine** for real-time inspection.\n\n### HTTP Mode\n\n> **MCP Client** → *HTTP POST* → **MCP Guard (:9090)** → *HTTP POST* → **MCP Server (Remote)**\n>\n> Responses (JSON or SSE stream) are inspected before forwarding back to the client.\n\n**Default behavior: Fail-Close.** If the policy engine errors, all traffic is blocked for safety.\n\n---\n\n## CLI Reference\n\n### stdio mode (default)\n\n```bash\nmcp-guard [options] -- <server-command> [server-args...]\n```\n\n| Option | Short | Description | Default |\n|--------|-------|-------------|---------|\n| `--config <path>` | `-c` | YAML policy file path | Built-in defaults |\n| `--verbose` | `-v` | Enable debug-level logging | `false` |\n| `--fail-open` | | Allow traffic on policy engine error (not recommended) | `false` |\n| `--dry-run` | | Log violations without blocking | `false` |\n| `--version` | `-V` | Print version | |\n| `--help` | `-h` | Print help | |\n\n### HTTP mode\n\n```bash\nmcp-guard http [options] --upstream <url>\n```\n\n| Option | Short | Description | Default |\n|--------|-------|-------------|---------|\n| `--upstream <url>` | `-u` | Upstream MCP server URL **(required)** | |\n| `--port <number>` | `-p` | Listen port | `9090` |\n| `--host <host>` | `-H` | Bind host | `127.0.0.1` |\n| `--config <path>` | `-c` | YAML policy file path | Built-in defaults |\n| `--verbose` | `-v` | Enable debug-level logging | `false` |\n| `--fail-open` | | Allow traffic on policy engine error | `false` |\n| `--dry-run` | | Log violations without blocking | `false` |\n\n---\n\n## Policy File\n\nPolicy files are written in YAML. Without a policy file, built-in defaults apply.\n\n### Basic Structure\n\n```yaml\nversion: 1\nfailMode: closed    # closed (recommended) | open\n\nlogging:\n  level: info       # debug | info | warn | error\n  destination: stderr\n\nrules:\n  - id: tool-poisoning\n    enabled: true\n    severity: critical\n    action: block       # block | warn\n    type: tool-poisoning\n\n  - id: argument-injection\n    enabled: true\n    severity: critical\n    action: block\n    type: argument-injection\n\n  - id: data-exfiltration\n    enabled: true\n    severity: high\n    action: warn        # warn recommended — blocking may break normal flow\n    type: data-exfiltration\n```\n\n### Tool Poisoning Config\n\n```yaml\nconfig:\n  checkZeroWidth: true\n  checkInjectionPhrases: true\n  checkHtmlComments: true\n  checkBase64: true\n  checkShadowing: true\n  checkInstructionPatterns: true\n  maxDescriptionLength: 5000\n```\n\n### Argument Injection Config\n\n```yaml\nconfig:\n  checkPromptInjection: true\n```\n\nSQL, Command, Path Traversal, XSS, and Template Injection checks are always active.\n\n### Data Exfiltration Config\n\n```yaml\nconfig:\n  checkCredentials: true\n  checkPathExposure: true\n  checkStackTraces: true\n```\n\n---\n\n## Usage Scenarios\n\n### Evaluate a new MCP server safely\n\n```bash\n# Step 1: Dry-run to observe\nmcp-guard --dry-run --verbose -- npx @unknown/mcp-server 2>guard.log\n\n# Step 2: Review findings\ncat guard.log | grep \"DRY-RUN\"\n\n# Step 3: Enable blocking if clean\nmcp-guard -- npx @unknown/mcp-server\n```\n\n### Protect multiple servers in Claude Desktop\n\n```json\n{\n  \"mcpServers\": {\n    \"fetch-guarded\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiclude/mcp-guard\", \"--\", \"npx\", \"-y\", \"@modelcontextprotocol/server-fetch\"]\n    },\n    \"github-guarded\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@aiclude/mcp-guard\", \"--\", \"npx\", \"-y\", \"@modelcontextprotocol/server-github\"]\n    }\n  }\n}\n```\n\n### HTTP security gateway\n\n```bash\nmcp-guard http \\\n  -u http://internal-mcp:8080/mcp \\\n  -p 9090 -H 0.0.0.0 \\\n  -c /etc/mcp-guard/policy.yaml\n```\n\n### Custom policy with selective rules\n\n```bash\nmcp-guard -c my-policy.yaml -- npx @some/mcp-server\n```\n\n---\n\n## Understanding Logs\n\nAll logs are written to **stderr** in JSON format. stdout is reserved for MCP JSON-RPC communication.\n\n### Startup\n\n```json\n{\"ts\":\"...\",\"level\":\"info\",\"msg\":\"mcp-guard starting\",\"rules\":[\"tool-poisoning\",\"argument-injection\",\"data-exfiltration\"],\"failMode\":\"closed\"}\n```\n\n### Blocked\n\n```json\n{\"ts\":\"...\",\"level\":\"warn\",\"msg\":\"BLOCKED server->client\",\"rule\":\"tool-poisoning\",\"severity\":\"critical\",\"reason\":\"Tool \\\"search\\\": Zero-width characters detected in description\"}\n```\n\n### Warning\n\n```json\n{\"ts\":\"...\",\"level\":\"warn\",\"msg\":\"WARNING server->client\",\"rule\":\"data-exfiltration\",\"severity\":\"critical\",\"reason\":\"Sensitive Data Exposure in tool response (CWE-200)\"}\n```\n\n### Dry-Run\n\n```json\n{\"ts\":\"...\",\"level\":\"warn\",\"msg\":\"DRY-RUN WOULD BLOCK client->server\",\"rule\":\"argument-injection\",\"severity\":\"critical\",\"reason\":\"SQL Injection detected (CWE-89)\"}\n```\n\n---\n\n## Troubleshooting\n\n**\"Failed to spawn MCP server\"**\n— Verify the command after `--` runs independently: `npx @some/mcp-server`\n\n**Legitimate tools being blocked**\n1. Run with `--dry-run --verbose` to identify which rule triggers\n2. Disable the specific check in a policy file, or change the rule action to `warn`\n\n**No logs visible**\n— Logs go to stderr. Redirect: `mcp-guard --verbose -- ... 2>/tmp/guard.log`\n\n**HTTP \"Upstream connection failed\"**\n— Verify upstream is reachable: `curl -v http://mcp-server:8080/mcp`\n\n**SSE stream disconnecting**\n— If behind nginx, disable buffering:\n```nginx\nproxy_buffering off;\nproxy_cache off;\n```\n\n---\n\n## FAQ\n\n**Does it affect MCP communication speed?**\nBarely. Synchronous pattern matching adds microsecond-level latency per message.\n\n**Can I use it without a policy file?**\nYes. Built-in defaults apply: tool-poisoning (block), argument-injection (block), data-exfiltration (warn).\n\n**What is fail-close?**\nIf the policy engine itself errors, all traffic is blocked for safety. Use `--fail-open` to override (not recommended).\n\n**Does it work on Windows?**\nYes. Uses `cross-spawn` for Windows compatibility.\n\n**Does it support HTTP/SSE MCP servers?**\nYes. Both Streamable HTTP and Legacy HTTP+SSE are supported since v0.2.0.\n\n**How is authentication handled in HTTP mode?**\n`Authorization` headers are forwarded to upstream as-is. MCP Guard does not store or modify tokens.\n\n---\n\n## Technical Specifications\n\n| Spec | Details |\n|------|---------|\n| Language | TypeScript (strict mode, ESM-only) |\n| Runtime | Node.js 20+ |\n| Bundle Size | ~60KB (single file) |\n| Dependencies | 3 (commander, cross-spawn, yaml) |\n| Transport | stdio + HTTP (Streamable HTTP, Legacy SSE) |\n| Security Rules | 3 engines, 7 detector modules |\n| Injection Patterns | 21+ fuzz patterns, 33+ prompt injection phrases (EN/KO/ZH/JA) |\n| CWE Coverage | CWE-22, CWE-78, CWE-79, CWE-89, CWE-94, CWE-200, CWE-209 |\n| OS | macOS, Linux, Windows |\n\n---\n\n## Related\n\n- **[AIclude ASVS](https://vs.aiclude.com)** — AI Agent Security Vulnerability Scanner platform\n- **[OWASP MCP Top 10](https://owasp.org/www-project-mcp-top-10/)** — MCP security threat classification\n\n---\n\n## License\n\nApache License 2.0 — see [LICENSE](LICENSE) for details.\n\nCopyright 2026 AIclude Inc.\n","readmeFilename":"README.md"}