mm.tech
securityalphaTypeScript

MCP RCE Guard

Layer-3 RCE defense for MCP servers via policy synthesis

Foundation pillar 9. Closes the tool-injection-RCE class that sidecar scanners (mcp-armor) and stdio wrappers (mcp-stdio-shellguard) cannot catch. Synthesises per-tool policies from declared semantics and enforces them at execution time. MIT, TypeScript.

Stars

★ 0

Clones (14d)

⊟ 18

Language

TypeScript

Updated

2026-05-13