Skip to main content
ClaudeWave

BLACK_WALL MCP server — a pre-action risk check your AI agent calls before any irreversible action (send email, move money, run SQL, delete data).

MCP ServersRegistry oficial0 estrellas0 forksJavaScriptActualizado today
ClaudeWave Trust Score
70/100
· OK
Passed
  • Actively maintained (<30d)
  • Clear description
  • Topics declared
  • Documented (README)
Flags
  • !No standard license detected
Last scanned: 8/26/2026
Install in Claude Code / Claude Desktop
Method: NPX · blackwall-mcp
Claude Code CLI
claude mcp add blackwall-mcp -- npx -y blackwall-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "blackwall-mcp": {
      "command": "npx",
      "args": ["-y", "blackwall-mcp"],
      "env": {
        "BLACKWALL_API_KEY": "<blackwall_api_key>"
      }
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
Detected environment variables
BLACKWALL_API_KEY
Casos de uso

Resumen de MCP Servers

# blackwall-mcp

[![Glama quality](https://glama.ai/mcp/servers/bluetieroperations-create/blackwall-mcp/badge)](https://glama.ai/mcp/servers/bluetieroperations-create/blackwall-mcp)

**A guardrail for AI agents, as an MCP server.** Your agent calls one tool — `forecast` — before any irreversible action (send email, move money, run SQL, delete data, post content). It gets back a risk score (0–100), a reversibility class, a `GO` / `CAUTION` / `STOP` recommendation, and named red flags in a few seconds (~4-8s).

Works in any MCP host: **Claude Desktop, Claude Code, Cursor, Windsurf**, and any agent framework with MCP support.

> The wall between your agent and disaster. A BLUETIER product.

---

## 1. Get an API key

Sign up free at **https://blackwalltier.com** → Dashboard → API keys → Create key.
Free tier: ~100 forecasts/month, no card. Your key looks like `bw_live_…`.

## 2. Add the server to your MCP host

### Claude Desktop

Edit `claude_desktop_config.json` (Settings → Developer → Edit Config):

```json
{
  "mcpServers": {
    "blackwall": {
      "command": "npx",
      "args": ["-y", "blackwall-mcp"],
      "env": { "BLACKWALL_API_KEY": "bw_live_your_key_here" }
    }
  }
}
```

Restart Claude Desktop. You'll see a `forecast` tool available.

### Cursor

`Settings → MCP → Add new global MCP server`, then in `mcp.json`:

```json
{
  "mcpServers": {
    "blackwall": {
      "command": "npx",
      "args": ["-y", "blackwall-mcp"],
      "env": { "BLACKWALL_API_KEY": "bw_live_your_key_here" }
    }
  }
}
```

### Claude Code

```bash
claude mcp add blackwall -e BLACKWALL_API_KEY=bw_live_your_key_here -- npx -y blackwall-mcp
```

### Run locally (any host / testing)

```bash
BLACKWALL_API_KEY=bw_live_your_key_here npx -y blackwall-mcp
```

## 3. Use it

Once added, instruct your agent: *"Before any irreversible action, call the `forecast` tool and stop if it returns STOP."* The model will call it automatically when it's about to do something risky.

---

## The `forecast` tool

| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `action` | string | ✅ | The action type, e.g. `send_email`, `make_payment`, `run_sql`, `delete_file`, `post_content` |
| `inputs` | object | ✅ | Concrete parameters: recipient, `amount_usd`, SQL `statement`, file path, message body, URL, etc. |
| `context` | object | — | Optional: `{ agent_role, user_intent, environment }` |
| `depth` | `standard` \| `deep` | — | Analysis depth. `standard` is the default. |

**Returns:** recommendation (`GO`/`CAUTION`/`STOP`), `risk_score` (0–100), `reversibility` (class + rollback cost), `gate` (proceed/confirm/human-required), `confidence`, `red_flags[]`, `predicted_result`, `alternative_actions[]`.

### Example

Agent about to run `DELETE FROM users;` (no WHERE clause) →

```
🛑 BLACK_WALL: STOP — risk 99/100
Red flags:
  • [CRITICAL] SQL_NO_WHERE — deletes the entire table, not one row
  • [CRITICAL] INTENT_MISMATCH — intent was "remove a single test row"
  • [CRITICAL] IRREVERSIBLE_NO_BACKUP — no recovery path
Guidance: DO NOT take this action. Surface the red flags to the user.
```

---

## Observe mode — try it with zero risk

Not ready to let a guardrail block your agents? Start in **observe mode**. It scores and logs every action but **never tells the agent to stop** — your agents behave exactly as they do today. After a week, review your dashboard and see what it *would* have caught.

```json
{
  "mcpServers": {
    "blackwall": {
      "command": "npx",
      "args": ["-y", "blackwall-mcp"],
      "env": {
        "BLACKWALL_API_KEY": "bw_live_your_key_here",
        "BLACKWALL_MODE": "observe"
      }
    }
  }
}
```

Then see *"what your agents almost did"* in your dashboard. Flip `BLACKWALL_MODE` to `enforce` (or just remove it — enforce is the default) when you're ready to actually block.

## Two tools

The server exposes **two MCP tools**:

- **`forecast`** — pre-action risk check. Returns `GO` / `CAUTION` / `STOP`, risk score, named red flags, reversibility class, and a verifiable receipt.
- **`observe`** — post-action outcome report. Tells BLACK_WALL what actually happened after the action ran (or after the agent obeyed a STOP verdict). Closes the loop so the system can track prediction accuracy over time. FREE — no tokens charged.

Wire your agent to call `forecast` before any irreversible action, then call `observe` afterwards with the `forecast_id` from the original response. `observe` accepts an `outcome_class` (`matched` / `over_scope` / `under_scope` / `no_op` / `diverged` / `aborted`) and optional `divergence_severity` and `details`. See the `forecast` example below; the same wiring applies to `observe`.

## Use it in code — the `gate()` control (any JS/TS agent)

Running an agent in Node (LangChain, a custom loop, ElizaOS, a cron job)? You don't need an MCP host — call BLACK_WALL straight from the library, and let **`gate()`** make the check *impossible to skip*. One wrap forecasts the action, enforces the verdict (**fails closed** on `STOP` / unknown / unreachable), runs your side effect only when allowed, and reports the real outcome with `observe` automatically.

```bash
npm i blackwall-mcp
```

```js
import { gate, BlackWallBlocked } from 'blackwall-mcp/lib/gate';

// Wrap ANY risky action in a few lines. BLACKWALL_API_KEY lives in the env.
try {
  const { result } = await gate(
    { action: 'run_sql', inputs: { statement: sql }, context: { user_intent } },
    () => db.query(sql),                        // your real side effect — only runs if allowed
    { onCaution: (v) => confirmWithHuman(v) },  // CAUTION needs a yes; default = block
  );
  // ...use result
} catch (e) {
  if (e instanceof BlackWallBlocked) {
    // STOP, unconfirmed CAUTION, or forecast unavailable → the action NEVER ran
    console.error('Blocked:', e.reason, e.verdict?.red_flags);
  } else throw e; // a real error thrown by your action
}
```

**Fails closed by design.** If no verdict can be obtained (network / auth / timeout), the action does **not** run unless you explicitly pass `failOpen: true`. A risk gate that fails open is not a risk gate. The loop closes itself — `gate()` calls `observe` with the actual outcome (`matched` / `diverged` / `aborted`), so your forecasts sharpen over time.

Prefer the lower-level pieces? They're exported too:

```js
import { forecast, observe } from 'blackwall-mcp/lib';

const v = await forecast({ action: 'make_payment', inputs: { amount_usd: 50000 } });
if (v.recommendation === 'STOP') throw new Error('halt');
// ... take the action ...
await observe(v.id, { outcome_class: 'matched' });
```

Runnable demo: [`examples/gate-quickstart.mjs`](examples/gate-quickstart.mjs).

## Decision receipts (cryptographic, verifiable offline)

Every `forecast` response now includes a `receipt` field — an Ed25519 signature over canonical SHA-256 hashes of the request + response. Anyone with the published public key can verify offline that BLACK_WALL signed off on a specific (request, response) pair, without trusting our servers.

- Published keys: **https://blackwalltier.com/.well-known/blackwall-signing-keys.json** (stable, cacheable)
- Stateless verify endpoint: **`POST https://blackwalltier.com/api/v1/receipts/verify`** with `{ envelope, request_body, response_body }`
- Hashes only — BLACK_WALL never stores the raw request/response bodies, so receipts give cryptographic audit without payload exposure
- Free-tier retention: 90 days. Paid: indefinite.

The MCP server surfaces the receipt id in its tool output so your agent can log it for later replay / audit.

## Config reference

| Env var | Required | Default | Notes |
|---------|----------|---------|-------|
| `BLACKWALL_API_KEY` | ✅ | — | `bw_live_…` from your dashboard |
| `BLACKWALL_BASE_URL` | — | `https://blackwalltier.com` | |
| `BLACKWALL_MODE` | — | `enforce` | `observe` = log only, never block |

## Links

- Site & docs: https://blackwalltier.com
- Get a key: https://blackwalltier.com/dashboard/keys

MIT licensed.
agent-safetyai-agentsai-safetyblackwallclaude-desktopcursorguardrailsmcpmcp-servermodel-context-protocol

Lo que la gente pregunta sobre blackwall-mcp

¿Qué es bluetieroperations-create/blackwall-mcp?

+

bluetieroperations-create/blackwall-mcp es mcp servers para el ecosistema de Claude AI. BLACK_WALL MCP server — a pre-action risk check your AI agent calls before any irreversible action (send email, move money, run SQL, delete data). Tiene 0 estrellas en GitHub y su última actualización registrada es del 2026-08-25.

¿Cómo se instala blackwall-mcp?

+

Puedes instalar blackwall-mcp clonando el repositorio (https://github.com/bluetieroperations-create/blackwall-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar bluetieroperations-create/blackwall-mcp?

+

Nuestro agente de seguridad ha analizado bluetieroperations-create/blackwall-mcp y le ha asignado un Trust Score de 70/100 (tier: OK). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene bluetieroperations-create/blackwall-mcp?

+

bluetieroperations-create/blackwall-mcp es mantenido por bluetieroperations-create. La última actividad registrada en GitHub es del 2026-08-25, con 1 issues abiertos.

¿Hay alternativas a blackwall-mcp?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega blackwall-mcp en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: bluetieroperations-create/blackwall-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/bluetieroperations-create-blackwall-mcp)](https://claudewave.com/repo/bluetieroperations-create-blackwall-mcp)
<a href="https://claudewave.com/repo/bluetieroperations-create-blackwall-mcp"><img src="https://claudewave.com/api/badge/bluetieroperations-create-blackwall-mcp" alt="Featured on ClaudeWave: bluetieroperations-create/blackwall-mcp" width="320" height="64" /></a>

Más MCP Servers

Alternativas a blackwall-mcp