tomjwxf · MCP server
Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.
Not claimed by its maker. Is this yours? Prove it and answer the findings
From the README of protect-mcp 0.30.0
Receipt history: every signed receipt for every version of this listing, and what changed between them.
Cedar policy enforcement and signed receipts for AI agent tool calls, guided repository review, bounded coding work and exact human approvals. Built by ScopeBlind.
Static scanned
Its entry in the official MCP registry says the server is started with arguments this page cannot print without guessing, so there is no command here rather than one that would not start it. The maker's own instructions are at the source linked on this page.
5,731 installs last month · no published advisories · version current · checked 2026-10-03
No build provenance published. The repository above is the one the publisher declared, and nothing links it to the package you would install. That is not a mark against this listing, since most packages are published this way, but it is a check nobody can run.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/protect-mcp)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
Maintenance
MaintainedLast release 7 Oct 2026 (0.31.1), 0 days before this check on 7 Oct 2026.
Read from the npm registry's publish history, read by the nightly publisher check.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured