Skip to main content
ClaudeWave

One gateway in front of every MCP server your agents can reach. A server that changes after you approved it is caught, the call is blocked before it runs, and nothing leaves your machine.

MCP ServersOfficial Registry0 stars0 forks● PythonApache-2.0Updated today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (Apache-2.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 10/6/2026
Install in Claude Code / Claude Desktop
Method: NPX · @modelcontextprotocol/server-filesystem
Claude Code CLI
claude mcp add mcpgawk -- npx -y @modelcontextprotocol/server-filesystem
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "mcpgawk": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-filesystem"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Use cases

MCP Servers overview

<p align="center">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/gawk-dev/mcpgawk/main/assets/brand/wordmark-dark.png">
    <img alt="mcpgawk by nativerse" src="https://raw.githubusercontent.com/gawk-dev/mcpgawk/main/assets/brand/wordmark-light.png" width="320">
  </picture>
</p>
<p align="center"><em>One gateway in the path. On your machine.</em></p>

# mcpgawk
<!-- mcp-name: io.github.gawk-dev/mcpgawk -->

[![PyPI](https://img.shields.io/pypi/v/mcpgawk.svg)](https://pypi.org/project/mcpgawk/)
[![Python](https://img.shields.io/pypi/pyversions/mcpgawk.svg)](https://pypi.org/project/mcpgawk/)
[![License](https://img.shields.io/badge/license-Apache--2.0-C8401F.svg)](LICENSE)
[![CI](https://github.com/gawk-dev/mcpgawk/actions/workflows/ci.yml/badge.svg)](https://github.com/gawk-dev/mcpgawk/actions/workflows/ci.yml)
[![Open VSX](https://img.shields.io/open-vsx/v/gawk-dev/mcpgawk?label=VS%20Code%20%2F%20Cursor)](https://open-vsx.org/extension/gawk-dev/mcpgawk)
[![GitHub Marketplace](https://img.shields.io/badge/GitHub%20Marketplace-Action-C8401F?logo=github)](https://github.com/marketplace/actions/mcpgawk-mcp-hygiene-gate)
[![No egress](https://img.shields.io/badge/inventory-never%20uploaded-brightgreen.svg)](#guarantees)

Your agents call [Model Context Protocol](https://modelcontextprotocol.io) servers that can
change what their tools do *after* you approved them, and the agent will call the new one without
noticing. mcpgawk reads every server your agents can reach, checks every call against a baseline
you approved, and blocks the ones that changed. It runs on your machine and uploads nothing.

The same engine powers **mcpgawk Platform**: `mcpgawk enforce` puts one endpoint in front of the
whole fleet with a key per caller, policy on every call and a hash-chained audit log, and
`mcpgawk monitor` watches the servers you approved around the clock and tells you when one drifts.
This free layer is the seeing and the blocking underneath it. mcpgawk Platform is one subscription
per person for up to 3 machines: start a free 7-day trial at https://mcp.gawk.dev/trial.html
(no card) or subscribe at https://mcp.gawk.dev/subscribe. Then `mcpgawk login <key>` on this same
install fetches the paid engine and turns those on — one more command, nothing else to set up.

<p align="center">
  <a href="https://mcp.gawk.dev/#watch"><img src="https://mcp.gawk.dev/assets/video/mcpgawk-launch-poster.jpg" width="720"
       alt="mcpgawk in 64 seconds: a tool you approved changes in an update, and mcpgawk refuses the call until you decide. Watch the video."></a>
</p>
<p align="center"><sub><b>Watch: mcpgawk in 64 seconds.</b> A tool you approved changes in an update; mcpgawk refuses the call until you decide.</sub></p>

<p align="center">
  <img src="https://raw.githubusercontent.com/gawk-dev/mcpgawk/main/assets/brand/demo.gif"
       alt="mcpgawk demo: a server is approved, changes afterwards, and the guard blocks the tool that appeared">
</p>
<p align="center"><sub><code>mcpgawk demo</code> — its own output, in a sandbox that touches nothing of yours.
Run the same command and you get the same thing.</sub></p>

## Why

A server you approved can change what its tools do afterwards. Nothing in MCP tells your agent that
happened — it just calls the new tool. That is the rug-pull, and it is the case mcpgawk is built for.

Two things follow from being able to see a server properly. You find out what each one can reach
before you trust it, and you find out what it costs: every tool is loaded into your context on every
request, used or not.

## How it's different

- **It blocks, it does not only report.** A scanner tells you afterwards. `mcpgawk guard` installs one
  pre-execution hook and a tool that appeared after you approved the server does not run.
- **It runs the server, not just reads it.** `mcpgawk verify` drives tools in a sandbox and reports
  what they actually did — exfiltration, SSRF, poisoning — reproduced before it is reported.
- **Nothing is uploaded.** Cloud scanners send your inventory to a server and gate the verdict there.
  Every decision here is made on your machine, with no account and nothing to sign in to.
- **It says what it did not check.** Skipped tools are named as skipped, never counted as clean.

## Features

- 🛑 **Block a changed tool before it runs** — `mcpgawk guard install` puts one pre-execution hook in
  your agent's loop. The decision is local, in about 10ms, with nothing to sign in to. Works on **6 of
  the 21 supported clients**; the rest have no hook point and are named, not glossed over.
- 🧪 **Run it, don't just read it** — `mcpgawk verify` drives tools in a sandbox and reports what they
  did: exfiltration, SSRF, tool poisoning, secret leaks. The sandbox is a proxy by default, so it
  needs no Docker; Docker adds full container isolation when you have it. Safe mode drives only
  provably read-only tools, and every tool it skips is named as skipped.
- 🧑‍⚖️ **Approval needs a person** — `mcpgawk decide` opens a local screen for what changed. The buttons
  live on the tokened link printed in your terminal, so an agent that opened the page cannot approve
  its own way past a block.
- 🖥️ **One local panel** — `mcpgawk panel`: every server, every decision, every piece of evidence.
- 📜 **The changelog no vendor publishes** — `mcpgawk changes` shows every change to a server's tool
  surface between the snapshots you have recorded: tools added or removed, input schemas widened,
  descriptions and annotations rewritten. It reads your local history, so it works for a server you
  approved weeks ago — the one thing a fresh scan can never tell you.
- 🔌 **Any transport** — stdio, streamable-HTTP, SSE, and OAuth remotes (via the `mcp-remote` bridge).
- 💸 **Token cost index** — exactly what each tool adds to your context at connect, plus the 3 heaviest tools.
- 🧾 **Capability facts** — write / exfil-capable / declared annotations, straight from the schema, plus a
  trust-surface summary (% write, % exfil-capable, destructive-declared count) and an annotation-completeness
  score.
- 📌 **Integrity pin + drift** — catch a server that silently rewrites its tools (`--track`).
- 🚩 **Bounded signals** — injection-shaped descriptions, cross-server shadowing, under-declaring Server Cards — pointers for a human, never verdicts.
- 🔒 **Zero egress, by construction** — the measurement layers import no network library. Enforced by a test.
  Two checks are opt-in and make an explicit exception (see [Guarantees](#guarantees)): `--supply-chain` and
  `--oauth-scopes`.

## Get it — three ways

**CLI** (any terminal):
```bash
uv tool install --force mcpgawk      # or: pipx install --force mcpgawk
mcpgawk                              # finds every agent config on the machine itself
```

Run it as an MCP server: `mcpgawk mcp` (stdio), or `uvx mcpgawk mcp`.

**Editor** (VS Code / Cursor): install **mcpgawk** from the marketplace ([Open VSX](https://open-vsx.org/extension/gawk-dev/mcpgawk)). It scans your workspace `mcp.json` and shows cost + capability flags inline. The extension drives this engine as a subprocess — it is built and released separately, so its source is not in this repository.

**CI** (GitHub Action): gate every PR on token budget / drift ([Marketplace](https://github.com/marketplace/actions/mcpgawk-mcp-hygiene-gate)):
```yaml
- uses: gawk-dev/mcpgawk@v1
  with: { config: mcp.json, max-tokens: 8000, fail-on-flagged: true }
```

## When to run it

- **Once, then leave it on** — `mcpgawk guard install`. After that a tool that appears on a server
  you already approved does not get called.
- **Before you add a server** — see what it costs and what it can do, before you trust it.
- **When your agent feels slow or picks the wrong tool** — it's often MCP bloat (too many / too-heavy tools).
- **On every PR** — the CI gate catches drift and creeping token cost.
- **If you *publish* an MCP server** — see what it costs your users and how it reads to a client, and fix it (usually one line per tool). Lean + well-annotated is a differentiator.

## Use

```bash
mcpgawk                                  # first run: every agent config on this machine
mcpgawk demo                             # the whole arc in a sandbox — approve, drift, block
mcpgawk guard install                    # put the baseline in your agent's loop
mcpgawk guard status                     # is protection actually on?
mcpgawk decide                           # what changed, and approve it as a human
mcpgawk panel                            # the local page: servers, decisions, evidence
mcpgawk verify mcp.json                  # run the servers and watch what they do
mcpgawk changes                          # what changed on your servers since you approved them
mcpgawk login <key>                      # licence? one command fetches the paid engine (enforce, monitor)
```

Scanning on its own, if that is all you want:

```bash
mcpgawk scan mcp.json                                              # a whole config
mcpgawk scan --stdio "npx -y @modelcontextprotocol/server-filesystem@2026.8.31 /tmp"
mcpgawk scan --http https://host/mcp --header "Authorization: Bearer $TOKEN"
mcpgawk scan --sse  https://host/sse
mcpgawk scan mcp.json --track                                     # record + detect rug-pulls over time
mcpgawk scan mcp.json --json                                      # machine-readable labels
mcpgawk scan mcp.json --verbose                                   # full per-tool table, not just flagged tools
mcpgawk scan mcp.json --supply-chain                              # opt-in: npm/PyPI deprecation check (network)
mcpgawk scan mcp.json --oauth-scopes                              # opt-in: decode a supplied Bearer JWT's scope
```

## What it reports

- **Cost index** — tokens each tool adds at connect (named tokenizer; a comparable index, not an
  absolute Claude count), plus the 3 heaviest tools.
- 
agentic-aiai-securityclidevsecopsllmlocal-firstmcpmcp-gatewaymodel-context-protocolprompt-injectionsecuritysupply-chain-securitytokens

What people ask about mcpgawk

What is gawk-dev/mcpgawk?

+

gawk-dev/mcpgawk is mcp servers for the Claude AI ecosystem. One gateway in front of every MCP server your agents can reach. A server that changes after you approved it is caught, the call is blocked before it runs, and nothing leaves your machine. It has 0 GitHub stars and its last recorded update is dated 2026-10-05.

How do I install mcpgawk?

+

You can install mcpgawk by cloning the repository (https://github.com/gawk-dev/mcpgawk) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is gawk-dev/mcpgawk safe to use?

+

Our security agent has analyzed gawk-dev/mcpgawk and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.

Who maintains gawk-dev/mcpgawk?

+

gawk-dev/mcpgawk is maintained by gawk-dev. The last recorded GitHub activity is dated 2026-10-05, with 0 open issues.

Are there alternatives to mcpgawk?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy mcpgawk to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: gawk-dev/mcpgawk
[![Featured on ClaudeWave](https://claudewave.com/api/badge/gawk-dev-mcpgawk)](https://claudewave.com/repo/gawk-dev-mcpgawk)
<a href="https://claudewave.com/repo/gawk-dev-mcpgawk"><img src="https://claudewave.com/api/badge/gawk-dev-mcpgawk" alt="Featured on ClaudeWave: gawk-dev/mcpgawk" width="320" height="64" /></a>

More MCP Servers

mcpgawk alternatives