npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@securestamp/mcp-guard

v0.1.0

Published

SecureStamp MCP Guard — a local stdio + remote MCP wrapper for the SecureStamp Agent Trust Layer. Lets MCP hosts (Claude Desktop, Cursor, any @modelcontextprotocol/sdk client) ask SecureStamp for Proof-of-Intent before sensitive tool calls. Authorizes/ver

Readme

SecureStamp MCP Guard

SecureStamp MCP Guard is the local/distributable MCP wrapper for the SecureStamp Agent Trust Layer. It lets MCP-compatible hosts ask SecureStamp for Proof-of-Intent before sensitive tool calls.

The strategic product surface is now the Remote MCP Guard at mcp.securestamp.online; this package remains the local stdio option for clients that prefer running the guard inside their own agent environment.

Tools

  • authorize_action
  • analyze_message_intent
  • verify_counterparty
  • create_action_challenge
  • get_safe_next_step
  • issue_action_receipt

The Guard authorizes, challenges, blocks or emits receipts. It never executes payments, deletes data or performs external destructive actions.

Local stdio usage

Requires Node.js 20+. The wrapper speaks the MCP stdio transport (newline-delimited JSON-RPC) and has no runtime dependencies — it only proxies to the SecureStamp Action API over HTTPS.

SECURESTAMP_API_KEY=ss_live_... securestamp-mcp-guard

Optional (defaults to production):

SECURESTAMP_API_BASE=https://securestamp.online

Claude Desktop / Cursor / any stdio MCP host

Add the wrapper to your host's MCP config (example: Claude Desktop claude_desktop_config.json). Keep the key secret — never commit it:

{
  "mcpServers": {
    "securestamp-guard": {
      "command": "npx",
      "args": ["-y", "@securestamp/mcp-guard"],
      "env": {
        "SECURESTAMP_API_KEY": "ss_live_...",
        "SECURESTAMP_API_BASE": "https://securestamp.online"
      }
    }
  }
}

Until the package is published to npm, point command/args at a local build instead: "command": "node", "args": ["<repo>/packages/mcp-guard/dist/server.js"] (run pnpm --filter @securestamp/mcp-guard build first).

Security model

  • API key must include action:authorize.
  • Raw message text and plaintext monetary instructions should not be sent to tools.
  • Monetary instruction matching is fingerprinted by SecureStamp server-side.
  • Tool schemas are closed and intentionally small.
  • Every backing API call is tenant-scoped, rate-limited and audited by SecureStamp.

Remote MCP Guard

For always-on usage, configure compatible MCP hosts against:

https://mcp.securestamp.online/mcp

Use an MCP client created in the SecureStamp dashboard. Remote clients can restrict allowed tools, allowed client names, allowed origins and rate limits. The remote service accepts two auth modes: API key (ss_live_…) and delegated login sessions (ss_sess_…). Both staging (https://mcp-staging.securestamp.online/mcp) and production (https://mcp.securestamp.online/mcp) are live.

Distribution status

Package-ready, not yet published. bin → ./dist/server.js (built by tsc, shebang preserved); files ships only dist + README.md + package.json; publishConfig remaps exports/main/types to the built dist output at publish time (applied by pnpm publish — this is a pnpm workspace). Verified with pnpm pack (13.4 kB, 26 files, no source, no secrets). Licensed Apache-2.0 (LICENSE ships in the package). Publish with pnpm publish --filter @securestamp/mcp-guard when authorized. See docs/mcp-guard/MARKETPLACE-READINESS.md. Full distribution docs, connection examples and security model live under docs/mcp-guard/.