CodeGuard MCP Server

CodeGuard MCP Server

Provides centralized security instructions for AI-assisted code generation by matching context-aware rules to the user's programming language and file patterns. It ensures generated code adheres to security best practices without requiring manual maintenance of instruction files across individual repositories.

Category
Visit Server

README

CodeGuard MCP Server

Centralized security instruction server for AI-assisted code generation

🎯 Overview

Problem: Every repository needs .github/instructions/ files to enforce security rules with GitHub Copilot and AI assistants. This leads to:

  • Duplicated instruction files across repositories
  • Inconsistent rule versions
  • Difficult to update security policies organization-wide
  • Manual maintenance overhead

Solution: CodeGuard MCP Server provides centralized security instructions via the Model Context Protocol (MCP), eliminating per-repo instruction files while ensuring all AI-generated code follows security best practices.


πŸš€ Quick Start

Prerequisites

  • Node.js 18+

Installation

# Install dependencies
npm install

# Build the project
npm run build

# Test the server
npm start

Setup with Claude Desktop

  1. Build first: npm run build

  2. Configure Claude Desktop (%APPDATA%\Claude\claude_desktop_config.json):

    {
      "mcpServers": {
        "codeguard": {
          "command": "node",
          "args": ["C:\\repo\\contextpilot-server\\dist\\index.js"]
        }
      }
    }
    
  3. Restart Claude Desktop

  4. Test: Ask Claude to generate Python code with password hashing!

Setup with GitHub Copilot (VS Code)

Add to your project's .github/.mcp.json:

{
  "mcp": {
    "servers": {
      "codeguard": {
        "command": "node",
        "args": ["C:\\repo\\contextpilot-server\\dist\\index.js"]
      }
    }
  }
}

Note: GitHub Copilot MCP support is pending. Currently works best with Claude Desktop.


πŸ—οΈ How It Works

Current Approach (Per-Repository)

my-app/
  .github/
    instructions/
      codeguard-1-crypto.instructions.md          ❌ Duplicated
      codeguard-1-credentials.instructions.md     ❌ Duplicated
      codeguard-0-input-validation.instructions.md ❌ Duplicated
      ... (copy to every repo)

CodeGuard MCP Approach (Centralized + Smart)

User: "Generate Python code to hash passwords"
         ↓
AI Assistant (Copilot/Claude):
  - Connects to CodeGuard MCP Server
  - Sends context: language=python, keywords="hash password"
         ↓
CodeGuard MCP Server (Phase 2 Smart Matching):
  1. Auto-detects language: Python (.py files)
  2. Extracts keywords: "hash", "password"
  3. Scores & prioritizes rules:
     β€’ CRITICAL: codeguard-1-crypto-algorithms (score: 1000)
     β€’ CRITICAL: codeguard-1-hardcoded-credentials (score: 1000)
     β€’ HIGH: codeguard-0-authentication-mfa (score: 80)
  4. Returns top 15 most relevant rules
         ↓
AI generates code following prioritized rules:
  βœ… Uses bcrypt/Argon2 (not MD5) - from crypto-algorithms
  βœ… No hardcoded secrets - from hardcoded-credentials
  βœ… Proper salt generation - from authentication-mfa
  βœ… Secure defaults - from all combined rules

NO .github/instructions needed in the repo!
Smart context-aware rule delivery in < 10ms!

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  AI Assistants (GitHub Copilot, Claude, etc.)      β”‚
β”‚  Working in any repository/workspace                β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                     β”‚ MCP Protocol
                     β”‚ stdio/HTTP
                     β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚           CodeGuard MCP Server                      β”‚
β”‚                                                     β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  MCP Protocol Layer                       β”‚    β”‚
β”‚  β”‚  β€’ Resources (instruction delivery)       β”‚    β”‚
β”‚  β”‚  β€’ Prompts (dynamic injection)            β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β”‚                    β”‚                               β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  Rule Engine                              β”‚    β”‚
β”‚  β”‚  β€’ Load instruction files                 β”‚    β”‚
β”‚  β”‚  β€’ Parse frontmatter (applyTo, version)   β”‚    β”‚
β”‚  β”‚  β€’ Match language/file patterns           β”‚    β”‚
β”‚  β”‚  β€’ Context-aware rule selection           β”‚    β”‚
β”‚  β”‚  β€’ Priority scoring (Critical/High/Med/Low)β”‚   β”‚
β”‚  β”‚  β€’ Custom rule override support           β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β”‚                    β”‚                               β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  Centralized Rule Repository              β”‚    β”‚
β”‚  β”‚  /rules/codeguard-1-*.instructions.md     β”‚    β”‚
β”‚  β”‚  /rules/codeguard-0-*.instructions.md     β”‚    β”‚
β”‚  β”‚  /rules/custom/*.instructions.md ✨ NEW   β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“‹ Core Components

1. MCP Resources

AI assistants can query instructions as resources:

// Resource: All instructions
codeguard://instructions/all

// Resource: By language
codeguard://instructions/python
codeguard://instructions/javascript
codeguard://instructions/typescript

// Resource: By file pattern
codeguard://instructions/file?path=src/auth/handler.ts

2. MCP Prompts

Dynamic instruction injection based on context:

Prompt: get_security_instructions
Arguments:
  - language: "python" | "javascript" | "c" | ...
  - context: "auth" | "crypto" | "database" | ...
  - filepath: Optional file path for pattern matching

Returns: Concatenated instruction text for matched rules

3. Rule Matching Engine

Smart rule selection based on:

  • Language Detection: **/*.py β†’ Python rules (auto-detected from file extensions)
  • File Patterns: **/*.test.js β†’ Testing rules
  • Context Keywords: "authentication" β†’ Auth/MFA rules (50+ keywords)
  • Priority Scoring: 4-tier system (Critical/High/Medium/Low)
  • Custom Rules: Organization rules get priority boost
  • Critical Rules: Always include hardcoded credentials, weak crypto
  • Frontmatter Parsing: applyTo, version, description

🎨 Rule Structure

Each instruction file follows this format:

---
applyTo: '**/*.js,**/*.ts,**/*.jsx,**/*.tsx'
description: No Hardcoded Credentials
version: 1.0.1
---

rule_id: codeguard-1-hardcoded-credentials

# No Hardcoded Credentials

NEVER store secrets, passwords, API keys, tokens or any other 
credentials directly in source code.

[... detailed rules and examples ...]

Current Rules (21+ instruction files):

  • codeguard-1-hardcoded-credentials ⚠️ Critical
  • codeguard-1-crypto-algorithms ⚠️ Critical
  • codeguard-1-digital-certificates ⚠️ Critical
  • codeguard-0-authentication-mfa
  • codeguard-0-authorization-access-control
  • codeguard-0-input-validation-injection
  • codeguard-0-api-web-services
  • codeguard-0-client-side-web-security
  • codeguard-0-session-management-and-cookies
  • ... (and 12+ more)

πŸ’‘ Usage Examples

Example 1: Python Password Hashing

User Prompt:

"Generate Python code to hash user passwords"

What Happens:

  1. AI detects: language=python, context=crypto password
  2. MCP Server returns instructions:
    • codeguard-1-crypto-algorithms (no MD5/SHA-1)
    • codeguard-0-authentication-mfa
    • codeguard-1-hardcoded-credentials

Generated Code:

import bcrypt

def hash_password(password: str) -> bytes:
    """Hash password using bcrypt with secure defaults."""
    # βœ… Uses bcrypt (not MD5)
    # βœ… Automatic salt generation
    # βœ… Secure work factor
    salt = bcrypt.gensalt(rounds=12)
    return bcrypt.hashpw(password.encode('utf-8'), salt)

def verify_password(password: str, hashed: bytes) -> bool:
    """Verify password against hash."""
    return bcrypt.checkpw(password.encode('utf-8'), hashed)

Example 2: Node.js Database Query

User Prompt:

"Create a function to get user by email in TypeScript"

What Happens:

  1. AI detects: language=typescript, context=database
  2. MCP Server returns instructions:
    • codeguard-0-input-validation-injection
    • codeguard-0-data-storage
    • codeguard-0-authorization-access-control

Generated Code:

import { Pool } from 'pg';

async function getUserByEmail(email: string): Promise<User | null> {
  // βœ… Input validation
  if (!email || typeof email !== 'string') {
    throw new Error('Invalid email parameter');
  }
  
  // βœ… Parameterized query (no SQL injection)
  const query = 'SELECT * FROM users WHERE email = $1';
  const result = await pool.query(query, [email]);
  
  return result.rows[0] || null;
}

Example 3: React Authentication Component

User Prompt:

"Create a login form component in React"

What Happens:

  1. AI detects: language=typescript, context=auth, filepath=*.tsx
  2. MCP Server returns instructions:
    • codeguard-0-client-side-web-security (XSS, CSRF)
    • codeguard-0-authentication-mfa
    • codeguard-0-session-management-and-cookies

Generated Code:

// βœ… No credentials in code
// βœ… CSRF protection
// βœ… Secure cookie handling
// βœ… XSS prevention via React defaults

export function LoginForm() {
  const handleSubmit = async (e: FormEvent) => {
    e.preventDefault();
    
    const formData = new FormData(e.target as HTMLFormElement);
    const response = await fetch('/api/auth/login', {
      method: 'POST',
      credentials: 'same-origin', // βœ… Secure cookies
      headers: {
        'Content-Type': 'application/json',
        'X-CSRF-Token': getCsrfToken(), // βœ… CSRF protection
      },
      body: JSON.stringify({
        email: formData.get('email'),
        password: formData.get('password'),
      }),
    });
    // ... handle response
  };
  
  return <form onSubmit={handleSubmit}>...</form>;
}

✨ Custom Organization Rules (Phase 3 βœ…)

Overview

CodeGuard supports custom organization-specific rules that extend or override default security rules.

Features

  • Override Default Rules: Replace any default rule with your organization's version
  • Add New Rules: Create organization-specific standards (API conventions, logging format, etc.)
  • Priority Boost: Custom rules automatically ranked higher than defaults
  • Automatic Loading: No configuration needed - just add files to rules/custom/

Quick Start

  1. Create custom rule file in rules/custom/:

    rules/custom/org-api-standards.instructions.md
    
  2. Use standard frontmatter format:

    ---
    applyTo: '**/*.ts,**/*.js,**/*.py'
    description: 'Organization API Standards'
    version: '1.0.0'
    ---
    
    # Organization API Standards
    Your organization-specific guidance...
    
  3. Restart MCP server - custom rules load automatically:

    Loaded 22 default + 3 custom = 24 total instruction files
    Custom rule 'org-api-standards' loaded
    

Examples

Example 1: Override Hardcoded Credentials Rule

Create rules/custom/codeguard-1-hardcoded-credentials.instructions.md:

  • Specifies your organization's approved secret managers (Azure Key Vault, HashiCorp Vault)
  • Documents rotation policies and incident response
  • Lists organization contacts

Example 2: API Standards

Create rules/custom/org-api-standards.instructions.md:

  • REST conventions (methods, status codes, pagination)
  • Error response format
  • Rate limiting headers
  • Authentication requirements

Example 3: Logging Format

Create rules/custom/org-logging-format.instructions.md:

  • Required log fields (timestamp, traceId, service, userId)
  • Log levels (DEBUG, INFO, WARN, ERROR, FATAL)
  • What NOT to log (passwords, PII)
  • Structured logging examples

See rules/custom/README.md for complete documentation.

Priority System

Custom rules get automatic advantages:

  • +25 baseline score boost
  • Elevated priority tier (LOWβ†’MEDIUM, MEDIUMβ†’HIGH)
  • Appear before equivalent default rules in results

πŸ› οΈ Technology Stack

  • Runtime: Node.js 18+ / TypeScript
  • Protocol: MCP SDK (@modelcontextprotocol/sdk)
  • Transport: stdio (standard MCP)
  • Parser: Gray-matter (frontmatter), micromatch (glob patterns)
  • Testing: Vitest (59 tests, 80-85% coverage)

🚦 Roadmap

See ROADMAP.md for detailed implementation plan.

Phase 1: Core MCP Server βœ… COMPLETED (January 16, 2026)

  • [x] MCP server setup with stdio transport
  • [x] Rule loader with frontmatter parsing
  • [x] Pattern matching engine (glob patterns, language detection)
  • [x] Basic resource handlers
  • [x] Prompt handlers for dynamic instruction injection
  • [x] 22 instruction files loaded and working
  • [x] TypeScript build system configured
  • [x] Basic tests implemented (37 tests)

Phase 2: Smart Matching βœ… COMPLETED (January 20, 2026)

  • [x] Enhanced language detection (30+ languages, auto-detection from file paths)
  • [x] Context keyword matching (50+ keywords with weighted scoring)
  • [x] Rule prioritization system (4-tier: Critical/High/Medium/Low)
  • [x] Advanced pattern matching (negative patterns, complex globs)
  • [x] Multi-factor scoring algorithm
  • [x] Response optimization (top 15 most relevant rules)
  • [x] Comprehensive test coverage (51 tests, 80-85%)

Current Status:

  • βœ… Server built and functional (dist/index.js)
  • βœ… Works with Claude Desktop (MCP supported)
  • βœ… Intelligent rule selection with priority scoring
  • βœ… Auto-detects language from file extensions
  • βœ… Context-aware matching (< 10ms response time)
  • ⏳ Waiting for GitHub Copilot MCP support

Phase 3: Enhanced Features (Week 3)

  • [ ] Custom organization rules support
  • [ ] Rule versioning and updates
  • [ ] Caching with TTL and invalidation
  • [ ] Configuration management (config.json)
  • [ ] Structured logging and metrics

Phase 4: Production Ready (Week 4+)

  • [ ] Docker containerization
  • [ ] HTTP transport option
  • [ ] Health check endpoint
  • [ ] Monitoring dashboard
  • [ ] GitHub Copilot integration (when available)

🎯 Success Metrics

  • βœ… Zero duplication: No .github/instructions in any repo
  • βœ… Centralized updates: Update once, apply everywhere
  • βœ… Automatic enforcement: AI follows rules without developer intervention
  • βœ… Fast response: < 10ms with priority scoring (target: < 100ms) βœ…
  • βœ… High accuracy: 90%+ correct rule matching with context awareness βœ…
  • βœ… Developer experience: Transparent, no workflow changes

🀝 Benefits

For Developers

  • No manual rule maintenance per repo
  • Consistent security standards across projects
  • AI generates secure code automatically
  • Clear, actionable security guidance

For Organizations

  • Centralized security policy management
  • Easy to update and enforce rules organization-wide
  • Audit trail of instruction versions
  • Reduced security vulnerabilities in AI-generated code

For Security Teams

  • Single source of truth for security rules
  • Version control for policy changes
  • Measurable compliance across all projects
  • Proactive security guidance at code generation time

πŸ—οΈ Architecture

Component Overview

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  AI Assistants (Copilot, Claude, etc.)             β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                     β”‚ MCP Protocol (stdio)
                     β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚           CodeGuard MCP Server                      β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  MCP Layer (Resources, Prompts, Tools)    β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  Rule Engine (Match & Prioritize)         β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”‚
β”‚  β”‚  Rules Repository (22+ instructions)      β”‚    β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

MCP Endpoints

Resources:

  • codeguard://instructions/all - All instructions
  • codeguard://instructions/{language} - Language-specific
  • codeguard://instructions/file?path={file} - File-specific

Prompts:

  • get_security_instructions - Context-aware instruction retrieval
    • Args: language, context, filepath

Tools:

  • get_security_instructions - Get rules for code generation
  • validate_code_security - Validate code against rules

Pattern Matching

The server intelligently matches rules based on:

  • File patterns: **/*.py, src/auth/**
  • Language: Detected from extensions or prompts
  • Context: Keywords like "auth", "crypto", "database"
  • Critical rules: Always included (credentials, crypto, certificates)

πŸ“¦ Project Structure

contextpilot-server/
β”œβ”€β”€ rules/                      # 22+ security instruction files
β”‚   β”œβ”€β”€ codeguard-1-*.md       # Critical rules
β”‚   └── codeguard-0-*.md       # Best practices
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ index.ts               # MCP server entry
β”‚   β”œβ”€β”€ handlers/              # Resource/Prompt/Tool handlers
β”‚   └── rules/                 # Loader & Matcher
β”œβ”€β”€ tests/
β”œβ”€β”€ dist/                      # Compiled output
└── package.json

πŸ§ͺ Development

# Development mode (hot reload)
npm run dev

# Run tests
npm test

# Build
npm run build

🚦 Current Status

βœ… Completed (Phase 1)

  • Core MCP server with stdio transport
  • Rule loader with frontmatter parsing
  • Pattern matching (glob, language, context)
  • Resource & Prompt handlers
  • 22 instruction files loaded
  • Works with Claude Desktop

⏳ Pending

  • GitHub Copilot MCP support (waiting on Microsoft)
  • Advanced caching & optimization
  • Custom organization rules

🀝 Benefits

For Developers:

  • No manual rule maintenance per repo
  • Consistent security across projects
  • AI generates secure code automatically

For Organizations:

  • Centralized security policy management
  • Easy organization-wide updates
  • Reduced security vulnerabilities

For Security Teams:

  • Single source of truth
  • Version control for policies
  • Proactive security at code generation time

πŸ“ License

MIT


πŸ”— Resources


Built with ❀️ for secure AI-assisted development

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
E2B

E2B

Using MCP to run code via e2b.

Official
Featured