CTRLRun/ctrlrun
Execution safety for AI agent actions. ctrlrun mcp-operator exposes the approval queue as tools (list_pending_approvals, approve, deny, resolve, plus receipts, effects, stats and inspect_action), so the human who has to answer a held action answers it from the assistant they are already in; read tools answer without a credential and write tools refuse without one that names a person. Separately, the gateway proxies any MCP server so every tool call is checked against a YAML policy before it runs: allow, hold for a human, or deny. Approvals are single-use and bound to the hash of the exact action, one logical effect runs at most once across processes and hosts, and an unknown outcome is recorded AMBIGUOUS rather than FAILED so a blind retry is refused. Every attempt leaves a hash-chained JSON receipt. Apache-2.0. pip install ctrlrun
Ads
Overview
<source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/CTRLRun/ctrlrun/main/docs/assets/wordmark-dark.
Installation
pip install ctrlrun
Configuration
{
"mcpServers": {
"ctrlrun": {
"url": "https://docs.ctrlrun.dev/mcp/overview"
}
}
}Paste into ~/.cursor/mcp.json or .cursor/mcp.json
Tags
- security
- local
- python
- awesome-list
Related MCP servers
Cryptography
ucsandman/DashClaw
Fail-closed approval layer for unattended agent runs: `guard` evaluates each declared action against org policy before it executes (allow/warn/block/require-approval with one-click human approval), records every decision to a causal ledger, and adds plan preflight, scoped delegation grants, and containment verdicts. `npx -y @dashclaw/mcp-server`
Cryptography
luiacuaniello/perspectivegraph
Attack-path engine for cloud and Kubernetes. Eight read-only tools let an agent list the reachable routes from internet exposure to sensitive assets, explain each hop and the evidence behind its probability, find choke points, and simulate cutting a relationship before recommending the fix. Connects to a running PerspectiveGraph: `perspectivegraph mcp --api http://localhost:8080`.
Cryptography
Gowthaman90/mcp-bastion
Reliability + security proxy that sits in front of MCP servers: TOFU tool-definition pinning against rug pulls, tool-poisoning and cross-server-exfiltration detection, argument/command-injection blocking, inline secret redaction, MCP 2026-07-28 header/body validation (`-32020`) and cache-policy clamping, and a compliance-mapped audit trail (NIST AI RMF / OWASP). Coverage measured on an open benchmark with a held-out corpus. `npx -y mcp-bastion`
Cryptography
elberacasa/umbra
Trust score and guardrails for AI-generated code: static security rules, Docker-verified build/boot checks, and claim receipts that catch agents lying about tests. Tools: `scan_repo`, `guard_content`, `get_score`. Run with `npx --yes -p @elberacasa/umbra umbra-mcp`.
Cryptography
M2M-Sentinel/m2m-sentinel-sdk
Deterministic EVM bytecode capability intelligence, EIP-1967 proxy resolution, gas recommendations, and preflight safety intelligence for autonomous agents on Base (`Chain ID: 8453`). Supports stdio and hosted SSE. `npx -y m2m-sentinel-sdk`
Cryptography
Drumworks/ssid-mcp
MAC-address (OUI) vendor lookup and router default-login directory for AI agents. Identify a device manufacturer from its MAC address, detect randomized/private (locally-administered) addresses instead of reporting "unknown", or fetch a router's default login IP and admin credentials — every router field cited to the manufacturer's own documentation. Free tier, no signup. `npx -y ssid-mcp`
Cryptography
aggrete/aggrete
Policy proxy that governs what AI assistants can reach and do: refuses forbidden tool calls before the upstream is contacted, with per-user memory and a tamper-evident audit. Stops prompt-injection exfiltration and forbidden data combinations across Slack, Drive, GitHub and more. `pip install aggrete`.
Cryptography
SaravananJaichandar/etch-mcp
Signed audit chain for AI agent decisions. Every event signed, Merkle-chained per project, anchored to public transparency logs, and offline-verifiable against a pinned public key without dependency on our infrastructure. Post-hoc evidence primitive, complementary to runtime enforcement (not a substitute). Zero-signup try-it-now: `curl -X POST https://etch.systems/v1/your-project` returns a bearer token you can drop into any MCP client.