@readystack/mcp-config-guard
v1.0.8
Published
Reads .mcp.json / .vscode/mcp.json / claude_desktop_config.json while you edit it and marks the lines that hand an AI agent more than you meant - unpinned servers, literal credentials, plaintext trans
Maintainers
Readme
MCP Config Guard - agent config lint
Reads .mcp.json / .vscode/mcp.json / claude_desktop_config.json while you edit it and marks the lines that hand an AI agent more than you meant - unpinned servers, literal credentials, plaintext transport, whole-home filesystem roots. 23 rules, offline, no server is ever started.
Install
npx @readystack/mcp-config-guard fileNode 18+. The same 23 rules as the VS Code extension, from a terminal or CI.
Free
- Check the MCP config file you have open against all 23 rules - the line number, one sentence on what goes wrong, and the line that replaces it - offline, no key, no limit.
--ruleslists every rule
With a licence ($29 once)
- Scale and hand-off: one sweep over every MCP config in the workspace and in the client config folders, a dated CSV/JSON/HTML report, and machine-readable output a CI step can fail on.
@readystack/mcp-config-guard --dir ./templates --report html --out report.htmlUpwork lists cybersecurity developers at a $60 median hourly rate, $40-$90 typical (Sept 2026).
Use from an AI agent (MCP)
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "mcp-config-guard": { "command": "npx", "args": ["-y", "@readystack/mcp-config-guard", "--mcp"] } } }Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.
Use in CI
- name: MCP Config Guard - agent config lint
run: npx -y @readystack/mcp-config-guard --dir . --ci(container: docker run --rm -v "$PWD:/work" getreadystack/mcp-config-guard --dir /work --ci)
The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.
