protect-mcp

PackSecurity

protect-mcp is a security plugin that adds Cedar policy enforcement and Ed25519 signed receipts to every Claude Code tool call. Each tool action is checked against security rules before it runs, and every decision produces a tamper-evident receipt that can be verified offline.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have Claude Code set up with the tool calls you want governed.

What your AI can do with it

  • Gates every tool call through Cedar policy rules before execution
  • Issues an Ed25519 signed receipt for each tool call decision
  • Produces tamper-evident logs of all decisions
  • Supports offline verification of receipts

Getting started

  1. Have Claude Code set up with the tool calls you want governed.
  2. Install the protect-mcp plugin.
  3. Define your Cedar security policies for tool actions.
  4. Run your agent; each tool call is policy-gated and generates a signed receipt.

Signals

GitHub stars
40k
Forks
4k
Last commit
Sep 2026

Questions

What does protect-mcp do?
It checks each of your agent's tool actions against Cedar security rules before they run and records an Ed25519 signed, tamper-evident receipt of every decision.
Can receipts be verified offline?
Yes. Every decision produces a tamper-evident receipt that can be verified offline.
When are policies enforced?
Before a tool call runs. Decisions are policy-gated before execution.
What signing does it use?
Ed25519 signatures on receipts for every tool call decision.
Advanced
Item type
plugin
Key
wshobson-agents-protect-mcp
Source
github.com/wshobson/agents