New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

Defense

Unverified
NPMdefense-mcp-server
FRisk gradecritical blast radius
Catalogue entry updated 19 days ago
Auth postureNot probedno remote endpoint probed yet
Tools3114 Execute · 13 Write · 4 Read
Worst categoryExecutegrade tracks the peak, not the average
Capability mix
Execute 14Write 13Read 4
What it can reach
Ingests untrusted inputTouches secretsReaches networkRuns codeTouches filesChanges permissionsSends external commsPersistsDeletes dataMoves money
Lethal trifectaReads attacker-controllable content, holds secrets, and can run code + reach the network — a full exfiltration/RCE path if unconstrained.
Change history
No change history on record for this server.
Recommended policy
app_hardenrequire approval
access_controlrate limit
Read-only toolsallow
Full policy breakdown with enforcement rules →

This record as markdown: /tools/defense.md — append .md to any tool or server page.

DIRECT INSTALL npx -y defense-mcp-server

Installed this way, nothing enforces the recommended policy above — calls run exactly as the agent makes them.

// LOOK UP ANOTHER SERVER

Every MCP server has a record like this.

Type a name, get the same breakdown: verified identity, auth posture, risk grade, capabilities, recommended policy.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.