MCPLow riskUnclaimed

mcp-airlock

Governance proxy for MCP servers: allowlist, forced dry run, human confirmation, blast radius, audit

Shalimov04shalimov04/mcp-airlock★ 18Updated Sep 16, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.Shalimov04/mcp-airlock",
  "description": "Governance proxy for MCP servers: allowlist, forced dry run, human confirmation, blast radius, audit",
  "title": "mcp-airlock",
  "repository": {
    "url": "https://github.com/Shalimov04/mcp-airlock",
    "source": "github"
  },
  "version": "0.2.0",
  "packages": [
    {
      "registryType": "pypi",
      "registryBaseUrl": "https://pypi.org",
      "identifier": "mcp-airlock",
      "version": "0.2.0",
      "runtimeHint": "uvx",
      "transport": {
        "type": "streamable-http",
        "url": "http://127.0.0.1:9000/mcp",
        "headers": [
          {
            "description": "Bearer JWT identifying the caller; the proxy refuses calls without a principal",
            "isRequired": true,
            "isSecret": true,
            "name": "Authorization"
          }
        ]
      },
      "packageArguments": [
        {
          "description": "Policy YAML: which tools are allowed and at which tier per environment",
          "isRequired": true,
          "format": "filepath",
          "type": "named",
          "name": "--policy",
          "valueHint": "policy.yaml"
        },
        {
          "description": "The MCP server being proxied",
          "isRequired": true,
          "type": "named",
          "name": "--upstream",
          "valueHint": "http://127.0.0.1:8080/mcp"
        },
        {
          "description": "Environment name, selects the tier column in the policy",
          "default": "prod",
          "type": "named",
          "name": "--env"
        }
      ],
      "environmentVariables": [
        {
          "description": "HS256 secret for verifying bearer tokens (or set AIRLOCK_JWKS_URL for OIDC)",
          "isSecret": true,
          "name": "AIRLOCK_JWT_SECRET"
        },
        {
          "description": "Key for signing confirmation tokens; set it when running more than one replica",
          "isSecret": true,
          "name": "AIRLOCK_SECRET"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—python
Installs—pypi:mcp-airlock@0.2.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsAIRLOCK_JWT_SECRETAIRLOCK_SECRETAuthorizationAIRLOCK_JWT_SECRETAIRLOCK_SECRETAuthorization
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.2.0latestOct 7, 2026