{"_id":"mcp-bastion","_rev":"15-6fc7dfacfef037766a969dd66347e637","name":"mcp-bastion","dist-tags":{"latest":"1.1.0"},"versions":{"0.1.0":{"name":"mcp-bastion","version":"0.1.0","keywords":["mcp","model-context-protocol","proxy","ai","llm","agent","agentic","security","reliability","reconnect"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.1.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"75e735df6689b610f720a0930fd13d3e459592fd","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.1.0.tgz","fileCount":11,"integrity":"sha512-FwpE1vvz9RxVVB95JhmzCRsy7hwkQw9jvK5f8AZ1D2nicaGnFpb/VzL2TwlOMqn0KSZz/8jLFMenJgKX3Z3n0w==","signatures":[{"sig":"MEUCID9aK8/OwL2EPXQwCisGumkeGoKSWoNih2pY3NsTZkqeAiEAq8Nv8tqcGcyAHWcdavTqJlAvpyLxbn3rbp6Y1JYK+kY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":257215},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"b3b8d59a04210861e99a147d133512923f0ce0a6","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): detect dead MCP servers, let the agent reconnect them, and (soon) catch tool poisoning and rug pulls at runtime.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.1.0_1783489113499_0.8827202460323931","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"mcp-bastion","version":"0.2.0","keywords":["mcp","model-context-protocol","proxy","ai","llm","agent","agentic","security","reliability","reconnect"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.2.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"541232458aa62f1bac00fb3158bba3628e7c829c","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.2.0.tgz","fileCount":11,"integrity":"sha512-2+Ed8T4zxAZCFYM5OL++s3MhrwK3X3EpjoDDrnKHYCp29D/vY38saRkkpWreTe2sKNN0l8oDc4TNnoBV7FpZ5A==","signatures":[{"sig":"MEQCIFGnidX2aaGKkRqT1kemaC/XUkyZ6sOruAdntKCbs3aRAiBWGFstl13eVyY1UWT1fWMscScx32sUCsU98jhecOYNuw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":274811},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"46291dda84be9c3f4ca64b1af7c66873338f0cfe","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.2.0_1783518932944_0.9126941985032293","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"mcp-bastion","version":"0.3.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.3.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"878b38b8dc5b4165ce238c48d1b25b39b4c4b6fa","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.3.0.tgz","fileCount":11,"integrity":"sha512-bq92+vG4HLtto0z1oO6Bgg9HprsCz8s2XlEEfRgNVthwg4d2+IRiuz1YJ6U41eQI/b/F0+3afxiuFRwkGwlbpA==","signatures":[{"sig":"MEQCIDs8PRWG8ULGRFgfvyqKUk9OI+A8U6eE2iHZMPBDDwSeAiBmJAG7MQXtOgEbu5PLghRAS5BSqZU01fqx6OYLwiqovQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":313557},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"ef45c377279c0b582599a51d02ca189ed1b55433","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.3.0_1783973929654_0.7286503331051675","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"mcp-bastion","version":"0.3.1","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.3.1","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"a4d940d1751164e7ffa05aa990e6b71a69adbe92","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.3.1.tgz","fileCount":11,"integrity":"sha512-JwRPhlZzZyntiyvd3isGIF3PL0OnGgh7jjb2lXHY49TFIg0cSjDL3Vbcee7OUWyC0c9oc/7GmK7M/RwMRgG6LQ==","signatures":[{"sig":"MEUCICIVMpTaBqHDx8jzEiA8REkZDlkMuSWRpIsulBUt65gHAiEA8OhsUzZUacP+acdgC1qatfN6xSCN+U5HYfsmuTDHFQ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":313609},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"e2167c24eedb7e0e3313744533c09247a1a45c80","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.3.1_1784003340693_0.8993782523460845","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"mcp-bastion","version":"0.4.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.4.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"b9dae9d218f4979f40f315ec6727ec9e1e644fb9","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.4.0.tgz","fileCount":11,"integrity":"sha512-gv8niFmLtsLy5bSYs6jbrX9XblC99rYrpHqmrKYxQ93/WWIoU6HixwLVeU7BJjQiTD+5DOjH5v08EhClTUe3Qg==","signatures":[{"sig":"MEUCIQDtuf6h8sUfQYEUrklR5/P7NrfeFpnzlONUH1bEquEJcwIgd5DqtkLHgFY6NsYHusV52evSAJdzjrF3HHnnuXL3OPg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":323093},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"950f52fe574be435089c566afbee50e74c28fb6e","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.4.0_1784139370847_0.40197818162740373","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"mcp-bastion","version":"0.5.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.5.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"f02dac3079c5e9b9adef96b2ea917daa1a782cc9","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.5.0.tgz","fileCount":11,"integrity":"sha512-e9Qt4LJp+WkMRd+PLIGaXAOHvJlQVZ9Tgk503U4M8OVUU1dlsuxpor2SQVRxtmuvWCpmzBsmBzdvm0MHfYHqFA==","signatures":[{"sig":"MEUCIQC1UKl3L5hDTJCF3kq+Wv955zoHORrh4IBJhb8JUSmoegIgZCPfINoIwW3Y1HscppZrcSi6SYuzG1aWW2DzjynYlOg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":386716},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"ca569b3125701cfcbf175aaa903a8f9d9b5455b5","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.5.0_1784150656539_0.20289163925337017","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"mcp-bastion","version":"0.6.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.6.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"18a79b65ec729e1c12f899eec4605097bc2bbeab","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.6.0.tgz","fileCount":11,"integrity":"sha512-TJ9SBkjb8EiVhGfvLnA5cjz5YUTkvD7HE3e860wI9VzaH/CdmmAEm3nvhTzPBDkz+kioJpMN7uu+WgxhSIpDxw==","signatures":[{"sig":"MEQCIF9MIaNea8lT7ssSBW4V0zAQsWOMSHb1xZZ+41nUNeBuAiBUZd+NMNy1DTpTGZc2Zx9x7e5SpQBW0BJUXzuEpY94qg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":419866},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"0f66b620886557bc588f36850b0da709e041555a","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.6.0_1784161534388_0.788799077383014","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"mcp-bastion","version":"0.6.1","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"name":"mcp-bastion contributors"},"license":"Apache-2.0","_id":"mcp-bastion@0.6.1","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"227cd10bf308025927e2b75c262c52f5bd9b0b10","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.6.1.tgz","fileCount":11,"integrity":"sha512-fKmWrlcUQhloDsF0vfO3pe+zXQpXJas8ygeCSVZOAwmllobgyZ/c5b8DeqGnYHZSUoHqskLyaApbKW/Olllf7Q==","signatures":[{"sig":"MEQCIGweDpmwS/sYC7df3RZFNPcJQG9HY6k75zbYWArxZnVLAiB4gTWYwzTdcfkWTlggUaoi7uKqk9M8gy6AIu1gBD5y7g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":419916},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"b10bcc254fb5e118a4444a9d5d7d7fc8c0966a79","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.6.1_1784222074527_0.47779751839493856","host":"s3://npm-registry-packages-npm-production"}},"0.6.2":{"name":"mcp-bastion","version":"0.6.2","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@0.6.2","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"d34982d339762e458d1eb4920ea562d0f04679f9","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.6.2.tgz","fileCount":11,"integrity":"sha512-oXLbGxu03X1NC/rhTzKsN5NJzhWDfmE0T8jTj0UUIzvYwXkDLNibokuIzzhI1nLxTKcTZ5XSGW3mAB4eemkTjQ==","signatures":[{"sig":"MEYCIQCOMC1Pc/CPbmCw65xSVSvYbez9CUQYGsaGfD/2L2jx2AIhAMXro7bgamkBrVc2eRarZdW1aHOwOy+5jdlLhLvUPp8O","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":421385},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"e124e476e3029e0ffbf230407b4fa32d6fc133c0","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.6.2_1784310735747_0.12402471267485993","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"mcp-bastion","version":"0.6.3","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@0.6.3","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"7e0299e9b9ac81ead0e249be92c9ff12203ceb6e","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.6.3.tgz","fileCount":11,"integrity":"sha512-V0PX00appG903cSU4O3Tfur6LwawNA4yZ6jUbqlVpgk4bChWXiOo7b6yhqyAUaPC+VczwfAGHI5oeAs9L5nBpw==","signatures":[{"sig":"MEQCIG0HRDaOtgsh97zHsJC/Vepr2JUWvcjJhWF/ylQRhhmcAiA6dHOt5/lX7WWgWTSA2q06GWZJDG1nbti5SnlVl5TG4g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":423025},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"74b7e882bc3ed664997acfd06130ca269b2dacb4","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.6.3_1784313651996_0.12168913576637652","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"mcp-bastion","version":"0.7.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@0.7.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"671b4ac477eef36cbb03c8b41a49327bad34f5fe","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.7.0.tgz","fileCount":11,"integrity":"sha512-QJ4YgcF0soXqTrPqYkAGLLyMF2pXcnQEgmTSuuS6CJ+2bYifQuhOqnE0XmrblqtaC9tqFa2/3OkzYjNu3oKv2g==","signatures":[{"sig":"MEUCIDvBMUizqmbOKsSYZuZ+l4oEn2ne+cBHi8NdqzeWTLsYAiEAsGSvaSeitkqoTHpCnDrmhTY9KUQIYU1Kqyn2h1Iez8M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":431368},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"dfb516077fa6f0ff3f0bf7df2e42e3d6fc76e800","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.7.0_1785770409372_0.7860924753574454","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"mcp-bastion","version":"0.8.0","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@0.8.0","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"5e48635579787058a2deff74f4224c1ba3cad92d","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-0.8.0.tgz","fileCount":11,"integrity":"sha512-9AAJ6fTLEleKWNivLQdOpMQjDFznWp98/JpdPllQH775chkA9y//Q/6TBGuZ4jFt7HEVNipYdLd7Rm+w8GqTwg==","signatures":[{"sig":"MEUCIQDeg9COe3NKgZAh0IVINrRBGSOKP3pOMXnVpRLihA6bjAIgQFHE9zXeKHj+a7JS5bpWmU+SJfwUV47xEThWMVrqjLo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":449693},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"gitHead":"de982b4f849f3f5daadc31764735260f7ebcb1d3","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^3.23.8","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/sdk":"^1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_0.8.0_1785770827968_0.5802270297199537","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"mcp-bastion","version":"1.0.2","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@1.0.2","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"ed41b6317fd99ecbe1a78e0de2e82311111dda98","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-1.0.2.tgz","fileCount":11,"integrity":"sha512-O8dtdk18PdOEw6QZGtOZHayi0piwWskzA0MmP9eX1ozZFmJWc8VgrynEcaszsiXoaTmExYPD8mp/W7lJtd1GeQ==","signatures":[{"sig":"MEYCIQCE2HwOavhmuMg6un/q7vmrtUgz1QIpFF8YBXPIPz8kQQIhAOv7BCaUKvM0qFoL2w/zX/DxEBG1sBf/S7q8Af8ILsOj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":549445},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"b121c7197663507b38ccfde10e1a1b50a65c8ee8","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.5.4","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/core":"^2.0.0","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/client":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_1.0.2_1788880539741_0.1791276036382805","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"mcp-bastion","version":"1.0.3","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","_id":"mcp-bastion@1.0.3","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"bin":{"mcp-bastion":"dist/cli.js"},"dist":{"shasum":"692efb3c053db93b824cd2dda7df736372167cf0","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-1.0.3.tgz","fileCount":11,"integrity":"sha512-C95u7mdr5TvzbmIStTQyGEHNT1lkfh0imYQfc5cQn18pqtGAlsNoplzJL/VQrDMEZNuvmi0qJ5HUOCI59SeKWA==","signatures":[{"sig":"MEUCIQCTKuwgHMMykAC6rRYDlFyH76/zlo5kcdpb3NItRQ2nFAIgeE/vWgtz0cEp7qW9hQLZ2t/hsFCkS9mYWtCJfzNvDeQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIEwS8ShwBgwmsMCLDNYfXbBXQImdWV3lKy15VEMldonIAiBxDG8TCNzNKaNn9iMF1A5WJUo5KdqoaSdgvzSxJPU2uw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":549656},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"gitHead":"8fccb5991af5acb5e1a6b46706e958f6b344408c","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.5.4","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/core":"^2.0.0","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/client":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-bastion_1.0.3_1790383240063_0.6973024192817348","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"_id":"mcp-bastion@1.1.0","bin":{"mcp-bastion":"dist/cli.js"},"bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"dist":{"shasum":"8a9d0316a7464e5a4c6c237c45e3d1027d9ccefc","tarball":"https://registry.npmjs.org/mcp-bastion/-/mcp-bastion-1.1.0.tgz","fileCount":11,"integrity":"sha512-RGnEzGQj5ky+mIBmct8mIAwvXhnIVCmoU4YLU+b9pK/n7v1yQB2rGbZdS5F+kduP9AWRoxn3X4QCScMARgirSw==","signatures":[{"sig":"MEUCIHCRbN+O+g7lFfQBBrv5Gocro1JR3RbF1pj7WDd3wn1WAiEAzrzCt3VWNfLeMRy6/PmPAUDSbk5+WzOPTBYFF+mTINI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCJPzfKb61ErOaxzoJhOyyJG0nOj6BTuKuU2gaLVpoUiAIgEvlDUswahu3Snh2xiYHvyBo+iF/5BX56ynK9yaoXlqI="}],"unpackedSize":565558},"main":"dist/index.js","name":"mcp-bastion","type":"module","types":"dist/index.d.ts","author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"engines":{"node":">=20"},"gitHead":"bec246c4a41d1a62cfa2be6bd217a5586af8d35f","license":"Apache-2.0","mcpName":"io.github.Gowthaman90/mcp-bastion","scripts":{"dev":"tsx src/cli.ts","demo":"npm run build && node scripts/demo.mjs","lint":"eslint .","test":"vitest run","build":"tsup","check":"npm run format:check && npm run lint && npm run typecheck && npm test","start":"node dist/cli.js","format":"prettier --write .","lint:fix":"eslint . --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","prepublishOnly":"npm run build"},"version":"1.1.0","_npmUser":{"name":"agowthaman90","email":"agowthaman1990@outlook.com"},"homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"_npmVersion":"11.13.0","description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","directories":{},"maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.5.4","pino":"^9.5.0","commander":"^12.1.0","@modelcontextprotocol/core":"^2.0.0","@modelcontextprotocol/node":"^2.0.0","@modelcontextprotocol/client":"^2.0.0","@modelcontextprotocol/server":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","tsup":"^8.3.5","eslint":"^9.15.0","vitest":"^2.1.8","prettier":"^3.4.1","@eslint/js":"^9.15.0","typescript":"^5.6.3","@types/node":"^20.14.0","typescript-eslint":"^8.16.0","eslint-config-prettier":"^9.1.0","@modelcontextprotocol/sdk":"^1.30.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-bastion_1.1.0_1790778918251_0.12752146312672696"}}},"time":{"created":"2026-07-08T05:38:33.394Z","modified":"2026-09-30T14:35:18.539Z","0.1.0":"2026-07-08T05:38:33.657Z","0.2.0":"2026-07-08T13:55:33.089Z","0.3.0":"2026-07-13T20:18:49.943Z","0.3.1":"2026-07-14T04:29:00.826Z","0.4.0":"2026-07-15T18:16:11.017Z","0.5.0":"2026-07-15T21:24:16.686Z","0.6.0":"2026-07-16T00:25:34.559Z","0.6.1":"2026-07-16T17:14:34.677Z","0.6.2":"2026-07-17T17:52:15.974Z","0.6.3":"2026-07-17T18:40:52.121Z","0.7.0":"2026-08-03T15:20:09.521Z","0.8.0":"2026-08-03T15:27:08.114Z","1.0.2":"2026-09-08T15:15:39.880Z","1.0.3":"2026-09-26T00:40:40.233Z","1.1.0":"2026-09-30T14:35:18.361Z"},"bugs":{"url":"https://github.com/Gowthaman90/mcp-bastion/issues"},"author":{"url":"https://github.com/Gowthaman90","name":"Gowthaman Arumugam","email":"agowthaman90@gmail.com"},"license":"Apache-2.0","homepage":"https://github.com/Gowthaman90/mcp-bastion#readme","keywords":["mcp","model-context-protocol","mcp-server","mcp-proxy","mcp-gateway","mcp-security","proxy","gateway","ai","llm","agent","agentic","ai-security","llm-security","security","guardrails","reliability","reconnect","audit","audit-log","observability","compliance","nist-ai-rmf","owasp","tool-poisoning"],"repository":{"url":"git+https://github.com/Gowthaman90/mcp-bastion.git","type":"git"},"description":"Reliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-security (rug-pull/poisoning detection), and a compliance-mapped audit trail.","maintainers":[{"name":"agowthaman90","email":"agowthaman1990@outlook.com"}],"readme":"<div align=\"center\">\n\n# 🛡️ mcp-bastion\n\n**A reliability &amp; security proxy for the Model Context Protocol (MCP).**\n\n_Self-healing connections, runtime tool-security, and a compliance-mapped audit trail for your MCP servers._\n\n[![npm version](https://img.shields.io/npm/v/mcp-bastion.svg?color=cb3837&logo=npm)](https://www.npmjs.com/package/mcp-bastion)\n[![npm downloads](https://img.shields.io/npm/dm/mcp-bastion.svg?color=cb3837)](https://www.npmjs.com/package/mcp-bastion)\n[![MCP Registry](https://img.shields.io/badge/MCP_Registry-listed-6f42c1)](https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.Gowthaman90/mcp-bastion)\n[![Measured coverage](<https://img.shields.io/badge/mcp--defense--bench-62%25_coverage_(32_vectors)-2ea44f>)](https://github.com/Gowthaman90/mcp-defense-bench)\n[![mcp-bastion MCP server – quality and maintenance score on Glama](https://glama.ai/mcp/servers/Gowthaman90/mcp-bastion/badges/score.svg)](https://glama.ai/mcp/servers/Gowthaman90/mcp-bastion)\n[![CI](https://github.com/Gowthaman90/mcp-bastion/actions/workflows/ci.yml/badge.svg)](https://github.com/Gowthaman90/mcp-bastion/actions/workflows/ci.yml)\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](./LICENSE)\n[![Node](https://img.shields.io/badge/node-%3E%3D20-brightgreen.svg)](https://nodejs.org)\n[![TypeScript](https://img.shields.io/badge/TypeScript-strict-3178c6.svg)](https://www.typescriptlang.org/)\n[![PRs welcome](https://img.shields.io/badge/PRs-welcome-brightgreen.svg)](#contributing)\n\n<br/>\n\n<img src=\"./assets/demo.svg\" alt=\"mcp-bastion: an MCP server crashes mid-session and the agent recovers it automatically\" width=\"760\">\n\n</div>\n\n---\n\n`mcp-bastion` sits between your MCP client (Claude Code, Cursor, Cline, Windsurf, Zed, Claude\nDesktop, or any MCP-compliant agent) and your MCP servers. It is **client-agnostic** — it works with\nany compliant client through configuration alone, with zero client-specific code — and **non-invasive**:\nyour servers run unchanged, and removing Bastion is a one-line config revert.\n\n📦 **Package:** [`mcp-bastion` on npm](https://www.npmjs.com/package/mcp-bastion) · 🗂️ **Official MCP Registry:** `io.github.Gowthaman90/mcp-bastion`\n\n🔒 **Security, measured:** on the open, vendor-neutral [mcp-defense-bench](https://github.com/Gowthaman90/mcp-defense-bench), Bastion covers **63% of the MCP attack surface (15.0/24 vectors; 11 enforced)** at zero false positives — the broadest of the proxies measured.\n\n📖 **Launch story:** [Medium](https://medium.com/p/e74f638e9e15) · [dev.to](https://dev.to/gowthaman90/the-mcp-reliability-security-gap-and-an-open-source-proxy-that-fills-it-3ppo)\n\n👤 **Created & maintained by [Gowthaman Arumugam](https://github.com/Gowthaman90)** — Independent Researcher. Companion benchmark: [mcp-defense-bench](https://github.com/Gowthaman90/mcp-defense-bench).\n\n## Contents\n\n- [Why](#why)\n- [How it works](#how-it-works)\n- [Features](#features)\n- [Quick start](#quick-start)\n- [Demo](#demo)\n- [Control tools](#control-tools)\n- [Configuration](#configuration)\n- [Transports](#transports)\n- [Runtime security](#runtime-security)\n- [Audit & compliance](#audit--compliance)\n- [Client setup](#client-setup)\n- [Architecture](#architecture)\n- [Development](#development)\n- [Roadmap](#roadmap)\n- [Contributing](#contributing)\n- [Security](#security)\n- [License](#license)\n\n## Why\n\nWhen an MCP server disconnects mid-session, the agent only sees a generic _\"No such tool available\"_\nerror — **indistinguishable from a tool that never existed** — and it cannot reconnect; only a human\ncan. Long agent sessions silently lose capabilities and fail in confusing ways.\n\nBastion closes that gap. It health-checks every server, auto-reconnects with backoff, and — crucially —\nexposes control tools so the **agent itself** can inspect connection health and recover a dropped\nserver without human intervention.\n\n> Bastion now spans three layers: **reliability** (v0.1), **runtime security** (v0.2 — tool pinning /\n> rug-pull & poisoning detection), and **audit & compliance** (v0.3 — pluggable sinks mapped to NIST\n> AI RMF / OWASP LLM Top 10). See the [roadmap](#roadmap).\n\n## How it works\n\nToday your client connects **directly** to each server. With Bastion, your client connects to\n**Bastion**, which connects to those same servers on your behalf — so it sits in the tool-call path\nand can add reliability (and, later, security) transparently.\n\n```\nBefore:   Client ─▶ server A / server B / server C\n\nAfter:    Client ─▶ mcp-bastion ─▶ server A\n                                  ─▶ server B\n                                  ─▶ server C\n```\n\nBastion is a standard MCP **server** to your client and a standard MCP **client** to each upstream.\nBecause it speaks the protocol faithfully, it works with every compliant client automatically — the\nonly per-client difference is where you put a few lines of config.\n\n## Features\n\n- 🔌 **Client-agnostic** — one binary, config-only integration; no per-client plugins.\n- ♻️ **Self-healing** — health checks + capped exponential-backoff auto-reconnect for stdio servers.\n- 🧭 **Agent-recoverable** — `bastion__status` and `bastion__reconnect` let the agent detect and fix\n  drops itself, instead of hitting an opaque \"no such tool\" wall.\n- 🧩 **Transparent aggregation** — merges many servers into one, with per-server tool namespacing to\n  prevent collisions and tool-shadowing.\n- 💬 **Legible failures** — a dropped server yields an actionable message, not a crash.\n- 🛡️ **Runtime security** _(new in v0.2)_ — pins each tool's definition and blocks \"rug pulls\" (a\n  server changing a tool after approval); heuristically inspects descriptions for poisoning; detects\n  cross-server shadowing. See [Runtime security](#runtime-security).\n- 📝 **Audit & compliance** _(new in v0.3, opt-in)_ — structured, integrity-hash-chained audit events to\n  pluggable sinks (console / file / webhook), mapped to NIST AI RMF & OWASP LLM Top 10. See\n  [Audit & compliance](#audit--compliance).\n- 🪶 **Non-invasive & reversible** — your servers run unchanged; uninstall is a config revert.\n- 🧱 **Enterprise-grade codebase** — strict TypeScript, layered architecture, ESLint + Prettier, and\n  unit + end-to-end tests.\n\n## Quick start\n\nBastion is published on npm as [`mcp-bastion`](https://www.npmjs.com/package/mcp-bastion) — the\n`npx` command below fetches it automatically, so there's nothing to install first.\n\n**1. Add Bastion to your client**, pointing it at a config file:\n\n```jsonc\n// your client's mcpServers config\n{\n  \"mcpServers\": {\n    \"bastion\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"mcp-bastion\", \"--config\", \"bastion.config.json\"],\n    },\n  },\n}\n```\n\n**2. List your real servers in `bastion.config.json`** (moved verbatim from the client):\n\n```jsonc\n{\n  \"servers\": {\n    \"github\": { \"command\": \"npx\", \"args\": [\"-y\", \"@modelcontextprotocol/server-github\"] },\n    \"filesystem\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@modelcontextprotocol/server-filesystem\", \"/path/to/dir\"],\n    },\n  },\n  \"reconnect\": { \"auto\": true },\n  \"healthCheck\": { \"enabled\": true },\n}\n```\n\n**3. Restart your client.** Your tools now appear namespaced (e.g. `github__create_issue`) alongside\nBastion's control tools. See [`bastion.config.example.json`](./bastion.config.example.json) for the\nfull set of options.\n\n> 🔒 **Security is on by default.** Out of the box, Bastion runs the `balanced` enforcement profile:\n> it **blocks** high-confidence attacks (rug-pulls, argument/command injection, cross-server\n> exfiltration) and **warns** on heuristic ones (description/response\n> poisoning), while redacting leaked secrets from tool results. Set `security.enforcementProfile` to\n> `observe` (warn-only) or `strict` (block-all), or tune any individual control — see\n> [Runtime security](#runtime-security).\n\n## Demo\n\nSee the whole thing in action — a server crashing mid-session and healing itself:\n\n```bash\nnpm run demo\n```\n\nIt boots Bastion in front of a server that crashes on command, shows the agent getting an actionable\n\"reconnect\" message instead of a cryptic error, and then the connection auto-recovering with no human\ninvolved. To record it as a GIF: `asciinema rec demo.cast -c \"npm run demo\" && agg demo.cast assets/demo.gif`.\n\n## Control tools\n\nBastion injects control tools so the agent can manage connections and review security itself, using\nonly standard MCP calls:\n\n| Tool                  | Purpose                                                                                                    |\n| --------------------- | ---------------------------------------------------------------------------------------------------------- |\n| `bastion__status`     | Health of every proxied server: connected / disconnected / reconnecting / failed, tool counts, last error. |\n| `bastion__reconnect`  | Reconnect a named server (argument: `{ \"server\": \"<name>\" }`) without human intervention.                  |\n| `bastion__security`   | Per-tool security report: pin status (approved vs changed), poisoning findings, and shadowing.             |\n| `bastion__compliance` | Audit summary of recent activity mapped to NIST AI RMF / OWASP LLM Top 10 (requires `audit.enabled`).      |\n\n> **Re-approval is operator-only.** Clearing a rug-pull block is a security authority, so it is **not** an\n> agent-callable tool — a prompt-injected agent must not be able to re-approve the very tool it was blocked\n> from. A changed tool stays blocked until an operator clears it out-of-band; `bastion__approve` is not\n> advertised and a client call to it is refused.\n\n## Configuration\n\n| Key                               | Type                           | Default              | Description                                                                            |\n| --------------------------------- | ------------------------------ | -------------------- | -------------------------------------------------------------------------------------- |\n| `servers`                         | map                            | —                    | Upstream servers to proxy (required, at least one).                                    |\n| `servers.<name>.command`          | string                         | —                    | Executable to launch (e.g. `npx`, `node`).                                             |\n| `servers.<name>.args`             | string[]                       | `[]`                 | Arguments to `command`.                                                                |\n| `servers.<name>.env`              | map                            | —                    | Env overrides merged over the process env.                                             |\n| `servers.<name>.cwd`              | string                         | —                    | Working directory for the spawned process.                                             |\n| `reconnect.auto`                  | boolean                        | `true`               | Auto-reconnect after an unexpected disconnect.                                         |\n| `reconnect.maxRetries`            | number                         | `10`                 | Max attempts before giving up (`-1` = unlimited).                                      |\n| `reconnect.initialBackoffMs`      | number                         | `500`                | Initial backoff, doubled each attempt.                                                 |\n| `reconnect.maxBackoffMs`          | number                         | `30000`              | Backoff ceiling.                                                                       |\n| `healthCheck.enabled`             | boolean                        | `true`               | Enable periodic liveness probing.                                                      |\n| `healthCheck.intervalMs`          | number                         | `30000`              | Interval between probes.                                                               |\n| `healthCheck.timeoutMs`           | number                         | `5000`               | Per-probe timeout.                                                                     |\n| `namespace.strategy`              | `prefix` \\| `passthrough`      | `prefix`             | How upstream tool names are exposed.                                                   |\n| `namespace.separator`             | string                         | `__`                 | Separator used by the `prefix` strategy.                                               |\n| `security.pinTools`               | boolean                        | `true`               | Pin tool definitions and detect later changes.                                         |\n| `security.onRugPull`              | `block` \\| `warn`              | `block`              | Action when a pinned tool's definition changed.                                        |\n| `security.inspectDescriptions`    | boolean                        | `true`               | Run poisoning heuristics on tool descriptions.                                         |\n| `security.onPoisoning`            | `block` \\| `warn`              | `warn`               | Action on a high-severity poisoning finding.                                           |\n| `audit.enabled`                   | boolean                        | `false`              | Record an audit event for every tool call.                                             |\n| `audit.includeArgs`               | `none`\\|`redacted`\\|`full`     | `none`               | How tool arguments are recorded.                                                       |\n| `audit.tamperEvident`             | boolean                        | `false`              | Hash-chain events so tampering is detectable.                                          |\n| `audit.sinks`                     | array                          | console              | Destinations: `console`, `file`, `webhook`, `otlp`.                                    |\n| `servers.<name>.transport`        | `stdio` \\| `http`              | `stdio`              | Local subprocess or remote endpoint.                                                   |\n| `servers.<name>.url`              | string                         | —                    | Remote MCP URL (required for `http`).                                                  |\n| `servers.<name>.headers`          | map                            | —                    | Headers for `http` upstreams (e.g. `Authorization`).                                   |\n| `listen.mode`                     | `stdio` \\| `http`              | `stdio`              | Serve Bastion over stdio or Streamable HTTP.                                           |\n| `listen.host` / `listen.port`     | string / number                | `127.0.0.1` / `3000` | Bind address for `http` mode.                                                          |\n| `listen.validateRoutingHeaders`   | boolean                        | `true`               | Reject `Mcp-*` routing headers that disagree with the body (`-32020`, MCP 2026-07-28). |\n| `security.maxCacheTtlMs`          | number (ms)                    | `3600000`            | Ceiling on upstream `ttlMs` cache hints forwarded downstream (MCP 2026-07-28).         |\n| `servers.<name>.protocol`         | `auto`\\|`legacy`\\|`2026-07-28` | `auto`               | Era negotiation per upstream (probe 2026-07-28, fall back; or pin).                    |\n| `listen.legacy`                   | `stateless` \\| `reject`        | `stateless`          | Serve pre-2026-07-28 clients statelessly, or refuse them (`-32022`).                   |\n| `security.inspectInputRequests`   | boolean                        | `true`               | Gate `input_required` rounds (credential phishing, model steering).                    |\n| `security.onInputRequired`        | `block` \\| `warn`              | `block`              | Action on a high-severity MRTR finding (`warn` strips the request).                    |\n| `security.requestStateKey`        | string (≥16)                   | random per process   | HMAC key sealing `requestState` envelopes; or `MCP_BASTION_REQUEST_STATE_KEY`.         |\n| `security.requestStateTtlSeconds` | number                         | `300`                | Lifetime of a sealed `requestState` envelope.                                          |\n\n## Transports\n\nBastion runs on the MCP TypeScript SDK **2.0** and speaks **both protocol eras** — the stateless\n2026-07-28 revision and the pre-2026 `initialize` handshake — on both faces, per upstream and per\nclient. When the protocol is stateless, the gateway is the only component that can still hold security\nstate, which is why v1.0 adds `requestState` custody and an `input_required` consent gate (see\n`CHANGELOG.md`).\n\nBastion speaks two transports on **both** faces:\n\n- **stdio** (default) — the client spawns Bastion, and Bastion spawns local servers.\n- **Streamable HTTP** — connect to **remote** MCP servers (`servers.<name>` with `transport: \"http\"`,\n  a `url`, and optional auth `headers`), and/or **serve** Bastion over HTTP to multiple/remote clients\n  (`listen.mode: \"http\"`, or `--http <port>`).\n\nHTTP upstreams configured without an authentication header are flagged (`authenticated: false`) in\n`bastion__status` and warned at connect time.\n\n## Runtime security\n\n_New in v0.2._ Bastion adds a security layer in the tool-call path (an interceptor pipeline), enabled\nby default:\n\n- **Rug-pull detection (tool pinning).** Each tool's definition is pinned on first use. If a server\n  later changes that definition, the tool is blocked (`onRugPull: \"block\"`) until an operator reviews it\n  and re-approves it out-of-band (operator-only — not an agent-callable tool). This catches a server that\n  looks benign at install time and turns malicious afterward.\n- **Poisoning inspection.** Tool names and descriptions are scanned for manipulation heuristics\n  (instruction override, secret access, data exfiltration, covert instructions, embedded directives,\n  hidden/zero-width characters). Because heuristics can false-positive, the default is `warn` (logged\n  and reported, not blocked); set `onPoisoning: \"block\"` to enforce.\n- **Shadowing.** When two servers expose a tool with the same name, it's surfaced in the report.\n\nReview everything with the `bastion__security` tool. These checks apply to local stdio servers today;\nauthentication checks for remote servers arrive with HTTP transport support.\n\n## Audit & compliance\n\n_New in v0.3, opt-in._ Enable `audit` to record a structured, versioned event for every tool call —\nincluding calls blocked by the security layer:\n\n```jsonc\n\"audit\": {\n  \"enabled\": true,\n  \"includeArgs\": \"redacted\",     // none | redacted | full\n  \"tamperEvident\": true,          // integrity hash-chain (detects naive edits; unkeyed, not signed)\n  \"sinks\": [\n    { \"type\": \"file\", \"path\": \"./bastion-audit.jsonl\" },\n    { \"type\": \"webhook\", \"url\": \"https://collector.example/v1/audit\" }\n  ]\n}\n```\n\n- **Pluggable sinks.** `console` (stderr JSONL), `file` (JSONL append), `webhook` (batched POST), and\n  `otlp` (native OpenTelemetry logs export — point it at an OTel Collector to fan out to any SIEM/cloud\n  backend). The sink interface makes new destinations additive.\n- **Compliance mapping.** Each event is mapped to **NIST AI RMF** functions and **OWASP LLM Top 10**\n  categories; `bastion__compliance` returns an aggregate report of recent activity.\n- **Integrity hash chain.** With `tamperEvident`, events are linked by a SHA-256 hash chain, and the\n  exported `verifyChain` helper detects naive or partial edits within an intact log. The chain is\n  **unkeyed**: a party who can rewrite the log file can recompute a consistent chain, and truncating the\n  most-recent events links cleanly — so treat this as corruption-detection, **not** cryptographic\n  tamper-proofing. For stronger guarantees, ship events to an append-only external sink (webhook / OTLP →\n  a WORM store or SIEM). Keyed/signed attestation is on the roadmap.\n- **Redaction (best-effort).** Arguments are omitted by default; `includeArgs: \"redacted\"` keeps structure\n  while masking values under known credential key-names and common secret patterns. It is a heuristic, not\n  a guarantee — a secret under an unrecognized key can still be recorded, so prefer `none` for\n  high-sensitivity deployments.\n\n## Standards alignment\n\nEvery security check maps to recognized frameworks — the **NIST AI Risk Management Framework** (a U.S.\nfederal standard), the **OWASP Top 10 for LLM (2025)** and **Agentic (2026)** Applications, and\n**STRIDE**. The full per-check mapping (with reference links to the MCP-security literature the checks\nare drawn from) is in **[docs/CHECKS-MAPPING.md](docs/CHECKS-MAPPING.md)**.\n\nCoverage is measured independently — bastion is scored against a 22-vector attack surface by the\nvendor-neutral [mcp-defense-bench](https://github.com/Gowthaman90/mcp-defense-bench) benchmark, with a\npublic [leaderboard and framework mapping](https://gowthaman90.github.io/mcp-defense-bench/).\n\n## Client setup\n\nThe steps are identical for every client — only the **config file location** differs:\n\n| Client         | Where to add the `bastion` entry                   |\n| -------------- | -------------------------------------------------- |\n| Claude Code    | project `.mcp.json` (or `claude mcp add`)          |\n| Cursor         | `~/.cursor/mcp.json` or project `.cursor/mcp.json` |\n| Claude Desktop | `claude_desktop_config.json`                       |\n| Cline          | `cline_mcp_settings.json`                          |\n| Windsurf       | `~/.codeium/windsurf/mcp_config.json`              |\n\n> **Gradual adoption:** you don't have to route every server through Bastion — put only your flaky or\n> untrusted servers behind it and leave the rest connected directly.\n\n## Architecture\n\nBastion is organized into clear layers with a one-directional dependency flow, so each concern is\nindependently testable and easy to evolve:\n\n```\nsrc/\n├── cli.ts              # thin CLI entrypoint (parse → wire → serve)\n├── index.ts            # public library API\n├── errors.ts           # error hierarchy (BastionError, …)\n├── config/             # schema (Zod) + loader\n├── core/               # domain: upstream connection lifecycle, aggregation & routing\n├── proxy/              # client-facing MCP server + control tools\n├── observability/      # logging (audit sinks in v0.3)\n└── internal/           # small cross-cutting utilities\n```\n\nDesign details — including the client-agnostic rationale, the interceptor pipeline, and the audit-sink\nstrategy — live in the project's design docs.\n\n## Development\n\n```bash\nnpm install\nnpm run check      # format:check + lint + typecheck + test (the full gate)\nnpm test           # unit + end-to-end (in-memory transport) tests\nnpm run build      # bundle to dist/ (CLI + library)\nnpm run dev -- --config bastion.config.json\n```\n\n| Script                    | Does                                |\n| ------------------------- | ----------------------------------- |\n| `build`                   | Bundle CLI + library with `tsup`.   |\n| `dev`                     | Run the CLI from source with `tsx`. |\n| `typecheck`               | `tsc --noEmit` (strict).            |\n| `lint` / `lint:fix`       | ESLint (flat config).               |\n| `format` / `format:check` | Prettier.                           |\n| `test` / `test:watch`     | Vitest.                             |\n| `check`                   | Everything above, as one gate.      |\n\n## Roadmap\n\n| Version     | Theme                  | Highlights                                                                                |\n| ----------- | ---------------------- | ----------------------------------------------------------------------------------------- |\n| **v0.1** ✅ | **Reliability**        | Aggregating proxy, auto-reconnect, `bastion__status` / `__reconnect`.                     |\n| **v0.2** ✅ | **Runtime security**   | Tool-definition pinning (rug-pull detection), poisoning inspection, shadowing detection.  |\n| **v0.3** ✅ | **Audit & compliance** | Pluggable audit sinks (console / file / webhook), NIST AI RMF / OWASP LLM Top 10 mapping. |\n\nBoth **stdio** and **Streamable HTTP** transports are supported (see [Transports](#transports)).\n\n## Contributing\n\nContributions are very welcome — this project is built to be community-owned. Please read\n**[CONTRIBUTING.md](./CONTRIBUTING.md)** for the dev setup, project layout, and PR workflow, and our\n**[Code of Conduct](./CODE_OF_CONDUCT.md)**.\n\nIn short: open an issue for non-trivial changes, keep PRs focused with tests, and make sure\n`npm run check` passes (CI runs it on Node 18/20/22). Good first areas: additional client setup\nrecipes, more upstream test fixtures, and Streamable HTTP transport support.\n\n## Security\n\n`mcp-bastion` is security-adjacent software, so we hold it to a high bar. Please report\nvulnerabilities privately — **do not open a public issue**. See **[SECURITY.md](./SECURITY.md)** for\nthe disclosure process.\n\n## License\n\n[Apache-2.0](./LICENSE) © Gowthaman Arumugam and mcp-bastion contributors\n","readmeFilename":"README.md"}