Rce Guard
@studiomeyer-io
About Rce Guard
Foundation Pillar 9: Layer-3 RCE defense for MCP servers via policy synthesis + behavioral CVE replay + cross-server canary tracking. v0.1 descriptor-only; v0.2 ships native enforcement.
Config
Add this server to your MCP-compatible client using the configuration below.
{
"mcpServers": {
"mcp-rce-guard": {
"command": "npx",
"args": [
"-y",
"mcp-rce-guard",
"serve"
]
}
}
}Tools
No tools detected
Fetch the live tool list by running this server in a temporary sandbox using the button above.
Overview
What is Rce Guard?
Foundation Pillar 9: Layer-3 RCE defense for MCP servers via policy synthesis + behavioral CVE replay + cross-server canary tracking. v0.1 descriptor-only; v0.2 ships native enforcement.
How to use Rce Guard?
The README includes setup instructions such as npx -y mcp-rce-guard serve.
Key features of Rce Guard
- A typed, validated way to describe what an MCP subprocess is allowed to read, write, spawn, and talk to
- NFKC + zero-width strip + Bidi-block normalization shared with Pillar 8 (mcp-stdio-shellguard)
- Audit-log rotation has a TOCTOU window (src/audit/log.ts
- In-memory state lost on restart (src/state.ts). Registered
- mcp-protocol-validator CI step is not a hard gate
Use cases of Rce Guard
- Connect an MCP-compatible client to this repository's service.
- Review the README-backed setup before enabling it in production.
FAQ from Rce Guard
Where is the source code for Rce Guard?
The source code is linked from the repository URL on this page.
Does Rce Guard include a standard MCP config?
If the README contains a parseable MCP configuration block, it is shown in the Config tab.
Frequently asked questions
Where is the source code for Rce Guard?
The source code is linked from the repository URL on this page.
Does Rce Guard include a standard MCP config?
If the README contains a parseable MCP configuration block, it is shown in the Config tab.
Basic information
More MCP servers
Legion MCP
faulkjMCP-native LLM councils for debates, juries, blind panels, voting, refinement, and custom multi-model deliberation.
CoinLobster
CoinLobsterThe only MCP server with live whale trades across 15 exchanges plus on-chain DEX flow. Smart Money Radar, real liquidations and outcome-scored signals. No API key required.

q-ring
I4cTimeQuantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation — CLI + 44 MCP tools.
LocalCan
LocalCanGives AI agents public URLs (tunnels) for localhost, live HTTP traffic inspection, snapshot publishing, and access control. Part of LocalCan, the ngrok alternative for Mac, Windows and Linux. Free plan.

Kin
Troy Fortin, Jr. (Firelock, LLC)The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see what a change touches before it merges. Beside Git today.
Comments