GuardBee MCP server monorepo — pnpm workspaces + Turborepo
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
- !No standard license detected
git clone https://github.com/GuardBee/guardbee-mcp{
"mcpServers": {
"guardbee-mcp": {
"command": "node",
"args": ["/path/to/guardbee-mcp/dist/index.js"]
}
}
}MCP Servers overview
# guardbee-mcp
**🇬🇧 English** | [🇹🇷 Türkçe](TR.md)
[guardbee.ai](https://guardbee.ai) — AI Security Copilot for websites.
GuardBee's family of MCP (Model Context Protocol) servers — a single monorepo, independent npm packages.
## Packages
| Package | npm | Description |
|---|---|---|
| [`packages/ai-code-scanner`](packages/ai-code-scanner) | `@guardbee/mcp-ai-code-scanner` | Scans a codebase for insecure LLM/AI integration patterns (client-exposed keys, unsafe output handling, excessive agency, PII→prompt, prompt injection) |
| [`packages/compliance-checker`](packages/compliance-checker) | `@guardbee/mcp-compliance-checker` | KVKK/GDPR/CCPA compliance checks |
| [`packages/dependency-auditor`](packages/dependency-auditor) | `@guardbee/mcp-dependency-auditor` | CVE scanning for npm/pip/cargo dependencies (OSV) |
| [`packages/dns-intelligence`](packages/dns-intelligence) | `@guardbee/mcp-dns-intelligence` | DNS record enumeration, misconfiguration and dangling-subdomain detection |
| [`packages/db-gateway`](packages/db-gateway) | `@guardbee/mcp-db-gateway` | KVKK/GDPR-compliant gateway between an LLM and a database (PII masking, RBAC, rate limiting, queryable audit log; Prisma/Postgres/MySQL/SQLite/MongoDB adapters; optional insert/update/delete support) |
| [`packages/mcp-server-auditor`](packages/mcp-server-auditor) | `@guardbee/mcp-server-auditor` | Scans other MCP servers' tool definitions for insecure patterns (excessive agency, shell/eval/SQL/SSRF sinks, loose schemas, hardcoded secrets, wildcard CORS) |
| [`packages/prompt-injection-scanner`](packages/prompt-injection-scanner) | `@guardbee/mcp-prompt-injection-scanner` | Scans RAG content/scraped pages for indirect prompt injection (instruction override, spoofed role/chat-template tokens, hidden text, "Dear AI" direct address, data-exfiltration instructions) |
| [`packages/llm-redteam`](packages/llm-redteam) | `@guardbee/mcp-llm-redteam` | Actively red-teams a live LLM endpoint/chatbot with canary-based jailbreak/extraction/obfuscation probes (OpenAI/Anthropic/webhook targets) |
| [`packages/model-scanner`](packages/model-scanner) | `@guardbee/mcp-model-scanner` | Scans ML model files (PyTorch, pickle, safetensors, Keras/H5, ONNX) for supply-chain risks — dangerous pickle deserialization globals, disguised/malformed safetensors headers, Keras Lambda-layer RCE, ONNX external-data path traversal |
| [`packages/vector-store-scanner`](packages/vector-store-scanner) | `@guardbee/mcp-vector-store-scanner` | Probes vector-database endpoints (Weaviate, Qdrant, Chroma, Elasticsearch/OpenSearch, Redis, Postgres/pgvector) for unauthenticated exposure of embeddings and RAG data |
| [`packages/prompt-leak-scanner`](packages/prompt-leak-scanner) | `@guardbee/mcp-prompt-leak-scanner` | Catches leaked credentials and PII (API keys, TC Kimlik No, credit cards, IBANs) in outbound LLM prompts — as MCP scan tools, and as a live reverse proxy in front of a real LLM API |
| [`packages/agent-graph-auditor`](packages/agent-graph-auditor) | `@guardbee/mcp-agent-graph-auditor` | Builds a reachability graph across multi-agent orchestration configs (LangGraph, CrewAI, AutoGen/ag2) to find transitive excessive agency — an agent that reaches a dangerous tool only through delegation to another agent |
| [`packages/tool-poisoning-scanner`](packages/tool-poisoning-scanner) | `@guardbee/mcp-tool-poisoning-scanner` | Scans MCP server tool definitions for tool poisoning (hidden instructions embedded in a tool's description) and confused-deputy mismatches (a read-only-sounding tool whose handler has a shell/eval/file-write/env-dump sink) |
| [`packages/rug-pull-detector`](packages/rug-pull-detector) | `@guardbee/mcp-rug-pull-detector` | Connects live to another MCP server (stdio/HTTP), baselines its tools/list response, and detects an "MCP rug pull" — a tool's description/schema/annotations silently changing after it was already approved |
| [`packages/memory-poisoning-scanner`](packages/memory-poisoning-scanner) | `@guardbee/mcp-memory-poisoning-scanner` | Scans agent code for memory poisoning — untrusted input written into persistent, cross-session memory (MemGPT-style archival/core memory, or a long-term vector store) that later gets recalled and trusted as context |
| [`packages/oauth-auditor`](packages/oauth-auditor) | `@guardbee/mcp-oauth-auditor` | Scans an MCP server's own authorization code for OAuth 2.1 anti-patterns named in the MCP spec's Security Considerations — token passthrough, missing audience validation, OAuth/OIDC discovery SSRF, missing PKCE, loose redirect_uri validation, hardcoded client secrets |
| [`packages/a2a-auditor`](packages/a2a-auditor) | `@guardbee/mcp-a2a-auditor` | Scans an agent's Agent2Agent (A2A) protocol implementation (TypeScript and Python) for anti-patterns found in the reference SDKs' own source — unauthenticated push-notification webhook fetches (SSRF), Agent Cards with no authentication requirement, credentials embedded in publicly-served Agent Card metadata |
| [`packages/slopsquat-scanner`](packages/slopsquat-scanner) | `@guardbee/mcp-slopsquat-scanner` | Checks every dependency declared in a project's own manifest (package.json, requirements.txt, pyproject.toml) against the real npm/PyPI registry — flags names that don't exist at all (likely LLM-hallucinated, i.e. slopsquatting) and names that exist but were only very recently published |
| [`packages/unbounded-consumption-auditor`](packages/unbounded-consumption-auditor) | `@guardbee/mcp-unbounded-consumption-auditor` | Scans LLM/agent application code for Unbounded Consumption ("denial of wallet", OWASP LLM Top 10 2026 #6) — missing output token limits, missing timeouts on hand-rolled LLM HTTP calls, unbounded agent tool-calling/retry loops, explicitly disabled framework safety limits (LangChain max_iterations, openai-agents max_turns), and MCP tool handlers with no visible rate limiting |
| [`packages/secret-scanner`](packages/secret-scanner) | `@guardbee/mcp-secret-scanner` | Scans files for leaked secrets and API keys |
| [`packages/security-proxy`](packages/security-proxy) | `@guardbee/mcp-security-proxy` | Security proxy between an MCP client and server |
| [`packages/security-suite`](packages/security-suite) | `@guardbee/security-suite` | Bundle of secret-scanner + dependency-auditor + ssl-inspector + dns-intelligence |
| [`packages/ssl-inspector`](packages/ssl-inspector) | `@guardbee/mcp-ssl-inspector` | TLS certificate/cipher/protocol inspection |
| [`packages/vulnerability-scanner`](packages/vulnerability-scanner) | `@guardbee/mcp-vulnerability-scanner` | Triggers GuardBee scans, queries findings, AI-assisted remediation guidance |
| [`packages/telemetry`](packages/telemetry) | `@guardbee/mcp-telemetry` | (internal) Shared usage-telemetry client — not an MCP server on its own |
## Recent Changes (2026-09-27)
Completed and shipped work found sitting uncommitted in `ai-code-scanner` from an earlier session: **custom rule packs** (`0.2.2` → `0.3.0`, minor — new capability, no breaking change). Built-in patterns cover common AI/LLM integration mistakes, but field names and internal conventions (e.g. which prop carries KVKK-regulated data) are project-specific — rather than forking the package per customer, a project can now drop JSON rule files into `.guardbee/rules/` (configurable via a new `rules-dir` key in `guardbee.yml`) that get merged with the built-ins at scan time, for both the CLI and the MCP server (`list_patterns` marks loaded custom rules `(custom)`). A rule id colliding with a built-in or another custom rule is rejected — reported on stderr, scan keeps running rather than crashing. 8 new tests (36 total): valid single-rule and multi-rule files, a rule that actually matches, and four rejection paths (id collision, missing field, invalid regex, invalid JSON) plus a missing-rules-dir case. Verified beyond the unit tests with a real end-to-end run: a genuine `.guardbee/rules/kvkk.json` file scanned against a real target file via the actual CLI binary, confirming the custom rule fires alongside the built-in patterns in the same run. `tsc --noEmit` and `npm run build` both clean.
## Recent Changes (2026-09-26, cont'd 4)
Follow-up to the dogfooding pass below: went further on `secret-scanner`'s doc/placeholder noise, since the first suppression-comment fix alone only cut findings 28% (1,623 → 1,162) against `IBM/mcp-context-forge` — the fork's own report had flagged this as still noisy, and sampling the actual remaining findings turned up three more concrete, fixable patterns rather than vague "noise":
- **`bearer_token`** required no minimum length at all, so test fixtures like `"Bearer alpha"` and `"Bearer test-token"` (from that repo's own Rust test suite) matched just as readily as a real OAuth token — and turned out to be nearly the entire problem: 1,008 of 1,149 remaining findings, from a handful of literal test strings reused across hundreds of call sites. Real bearer tokens (JWTs, OAuth2 opaque tokens) are essentially never under 20 characters; added that floor to the pattern.
- Added a value-shape placeholder filter, applied across all patterns except connection strings (which have their own allowlist and can legitimately contain "example" in a hostname, e.g. `example.com`): an 8+ run of one repeated character, an 8+ ascending sequential run (`abcdefgh`, `01234567` — the exact shape this package's own test fixtures used as filler, which needed rewriting to realistic pseudo-random values as a result), or a dictionary placeholder word embedded in the value (`EXAMPLE`, `PLACEHOLDER`, `CHANGEME`, etc. — this is exactly why AWS's own officially-published example key, `AKIAIOSFODNN7EXAMPLE`, is a famous universal false positive across every secret scanner; it's now correctly recognized here too).
- Broadened the existing `<UPPER_CASE>` bracket-placeholder allowlist (already present in the connection-string and generic-secret patterns) to any bracketed text, sinceWhat people ask about guardbee-mcp
What is GuardBee/guardbee-mcp?
+
GuardBee/guardbee-mcp is mcp servers for the Claude AI ecosystem. GuardBee MCP server monorepo — pnpm workspaces + Turborepo It has 1 GitHub stars and its last recorded update is dated 2026-09-28.
How do I install guardbee-mcp?
+
You can install guardbee-mcp by cloning the repository (https://github.com/GuardBee/guardbee-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is GuardBee/guardbee-mcp safe to use?
+
Our security agent has analyzed GuardBee/guardbee-mcp and assigned a Trust Score of 62/100 (tier: OK). See the full breakdown of passed checks and flags on this page.
Who maintains GuardBee/guardbee-mcp?
+
GuardBee/guardbee-mcp is maintained by GuardBee. The last recorded GitHub activity is dated 2026-09-28, with 0 open issues.
Are there alternatives to guardbee-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy guardbee-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/guardbee-guardbee-mcp)<a href="https://claudewave.com/repo/guardbee-guardbee-mcp"><img src="https://claudewave.com/api/badge/guardbee-guardbee-mcp" alt="Featured on ClaudeWave: GuardBee/guardbee-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.