Measure MCP servers, pin the approved tool surface, refuse calls to tools that changed. Local-first.
Your agents call Model Context Protocol servers that can change what their tools do after you approved them, and the agent will call the new one without noticing. mcpgawk reads every server your agents can reach, checks every call against a baseline you approved, and blocks the ones that changed. It runs on your machine and uploads nothing.
The same engine powers mcpgawk Platform: mcpgawk enforce puts one endpoint in front of the
whole fleet with a key per caller, policy on every call and a hash-chained audit log, and
mcpgawk monitor watches the servers you approved around the clock and tells you when one drifts.
This free layer is the seeing and the blocking underneath it. mcpgawk Platform is one subscription
per person for up to 3 machines: start a free 7-day trial at https://mcp.gawk.dev/trial.html
(no card) or subscribe at https://mcp.gawk.dev/subscribe. Then mcpgawk login <key> on this same
install fetches the paid engine and turns those on — one more command, nothing else to set up.
A server you approved can change what its tools do afterwards. Nothing in MCP tells your agent that happened — it just calls the new tool. That is the rug-pull, and it is the case mcpgawk is built for.
Two things follow from being able to see a server properly. You find out what each one can reach before you trust it, and you find out what it costs: every tool is loaded into your context on every request, used or not.
mcpgawk guard installs one
pre-execution hook and a tool that appeared after you approved the server does not run.mcpgawk verify drives tools in a sandbox and reports
what they actually did — exfiltration, SSRF, poisoning — reproduced before it is reported.mcpgawk guard install puts one pre-execution hook in
your agent's loop. The decision is local, in about 10ms, with nothing to sign in to. Works on 6 of
the 21 supported clients; the rest have no hook point and are named, not glossed over.mcpgawk verify drives tools in a sandbox and reports what they
did: exfiltration, SSRF, tool poisoning, secret leaks. The sandbox is a proxy by default, so it
needs no Docker; Docker adds full container isolation when you have it. Safe mode drives only
provably read-only tools, and every tool it skips is named as skipped.mcpgawk decide opens a local screen for what changed. The buttons
live on the tokened link printed in your terminal, so an agent that opened the page cannot approve
its own way past a block.mcpgawk panel: every server, every decision, every piece of evidence.mcpgawk changes shows every change to a server's tool
surface between the snapshots you have recorded: tools added or removed, input schemas widened,
descriptions and annotations rewritten. It reads your local history, so it works for a server you
approved weeks ago — the one thing a fresh scan can never tell you.mcp-remote bridge).--track).--supply-chain and
--oauth-scopes.CLI (any terminal):
uv tool install --force mcpgawk # or: pipx install --force mcpgawk
mcpgawk # finds every agent config on the machine itself
Run it as an MCP server: mcpgawk mcp (stdio), or uvx mcpgawk mcp.
Editor (VS Code / Cursor): install mcpgawk from the marketplace (Open VSX). It scans your workspace mcp.json and shows cost + capability flags inline. The extension drives this engine as a subprocess — it is built and released separately, so its source is not in this repository.
CI (GitHub Action): gate every PR on token budget / drift (Marketplace):
- uses: gawk-dev/mcpgawk@v1
with: { config: mcp.json, max-tokens: 8000, fail-on-flagged: true }
mcpgawk guard install. After that a tool that appears on a server
you already approved does not get called.mcpgawk # first run: every agent config on this machine
mcpgawk demo # the whole arc in a sandbox — approve, drift, block
mcpgawk guard install # put the baseline in your agent's loop
mcpgawk guard status # is protection actually on?
mcpgawk decide # what changed, and approve it as a human
mcpgawk panel # the local page: servers, decisions, evidence
mcpgawk verify mcp.json # run the servers and watch what they do
mcpgawk changes # what changed on your servers since you approved them
mcpgawk login <key> # licence? one command fetches the paid engine (enforce, monitor)
Scanning on its own, if that is all you want:
mcpgawk scan mcp.json # a whole config
mcpgawk scan --stdio "npx -y @modelcontextprotocol/server-filesystem@2026.8.31 /tmp"
mcpgawk scan --http https://host/mcp --header "Authorization: Bearer $TOKEN"
mcpgawk scan --sse https://host/sse
mcpgawk scan mcp.json --track # record + detect rug-pulls over time
mcpgawk scan mcp.json --json # machine-readable labels
mcpgawk scan mcp.json --verbose # full per-tool table, not just flagged tools
mcpgawk scan mcp.json --supply-chain # opt-in: npm/PyPI deprecation check (network)
mcpgawk scan mcp.json --oauth-scopes # opt-in: decode a supplied Bearer JWT's scope
--verbose for the full per-tool table).--track
turns it into rug-pull detection over time.--supply-chain) — checks the launched package against the public npm/PyPI
registry for deprecation/yank status.--oauth-scopes) — locally decodes a supplied Bearer JWT's scope claim.--supply-chain sends the launched package's name
(and pinned version, if any) — never your tool inventory — to the public npm registry or PyPI JSON
API. --oauth-scopes makes no network call at all; it locally decodes a Bearer JWT you already
supplied. Neither runs unless you pass the flag.mcp SDK, which negotiates the protocol version.uv run --extra dev --with mcp --with tiktoken --with httpx python -m pytest -q
Scan your MCP servers on every pull request and fail the build if one gets too heavy or trips a signal. It runs entirely in your runner — nothing is uploaded — and posts a per-server cost/flag table to the job summary.
- uses: gawk-dev/mcpgawk@v1
with:
config: mcp.json # or: stdio / http / sse — a single server
max-tokens: 8000 # fail if any server loads more than this at connect
fail-on-flagged: true # fail if any bounded signal fires
Available on the GitHub Marketplace.
Issues and PRs welcome. Please read CONTRIBUTING.md first, and see the design boundaries in THREAT-MODEL.md. Security reports go through SECURITY.md (privately, not a public issue).
Apache-2.0 — see LICENSE. Part of the nativerse · gawk.dev family. Site and docs: mcp.gawk.dev. The value is in the repo, not a cloud.
Let your coding agent run the checks itself — whenever it adds, upgrades or audits an MCP server:
# Claude Code (similar for other agents: copy the folder into their skills directory)
mkdir -p ~/.claude/skills && cp -r skills/mcpgawk ~/.claude/skills/mcpgawk
The skill teaches the agent to measure a server BEFORE trusting it, audit an MCP-2 upgrade as a baseline diff instead of blind re-trust, and relay every consent prompt to you verbatim.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx mcpgawkMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-gawk-dev-mcpgawk": {
"command": "uvx",
"args": [
"mcpgawk"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencemcpgawkpypimcpgawk works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.