Skip to content
SmitheryListed

cerbereag-mcp

๐Ÿ•โ€๐Ÿฆบ CerbereAG MCP Server Runtime security for AI agents โ€” as an MCP server. CerbereAG MCP lets any MCP-compatible AI agent (Claude, Cursor, Cline, custom agents built on the Anthropic API) check its own prompts and tool calls for security risk in real time, using the Model Context Protocol. It wraps the cerbere-ag SDK's policy engine and exposes it as MCP tools, so an agent can call check_prompt_security or authorize_tool_call the same way it would call any other tool โ€” no separate API integration required. ๐Ÿš€ Quick start (30 seconds) 1. Install pip install cerbere-ag-mcp 2. Configure your MCP client Claude Desktop โ€” add to claude_desktop_config.json: { "mcpServers": { "cerbereag": { "command": "cerbere-ag-mcp", "env": { "AGENTGUARD_MCP_COLLECTOR_URL": "https://YOUR_AGENTGUARD_HOST", "AGENTGUARD_API_KEY": "ag-your-key", "AGENTGUARD_AGENT_ID": "my-agent" } } } } Cursor โ€” add to .cursor/mcp.json in your project: { "mcpServers": { "cerbereag": { "command": "cerbere-ag-mcp", "env": { "AGENTGUARD_MCP_COLLECTOR_URL": "https://YOUR_AGENTGUARD_HOST", "AGENTGUARD_API_KEY": "ag-your-key", "AGENTGUARD_AGENT_ID": "my-agent" } } } } Restart the client. The tools below become available to the agent automatically โ€” no code changes needed on your side. ๐Ÿ› ๏ธ Available tools Tool Purpose check_prompt_security(text) Checks a text for prompt injection patterns or PII leakage before it's sent onward. authorize_tool_call(tool_name, params_json, agent_id?) Checks whether a planned tool call is allowed under the active policy and remaining budget. redact_pii(text) Replaces detected PII (emails, phone numbers, card numbers, SSNs, API keys) with [REDACTED_TYPE] placeholders. get_audit_trail(limit?) Fetches the most recent entries from the security audit log on the Collector. calculate_token_cost(model, text) Estimates token count and USD cost for a piece of text against a given model's pricing. ๐Ÿ“š Available resource Resource Purpose cerbereag://policies/summary Returns a summary of the currently active tool allowlist and detection settings. โš™๏ธ Configuration Environment variable Required Default Description AGENTGUARD_MCP_COLLECTOR_URL No http://localhost:8080 URL of your CerbereAG Collector instance. AGENTGUARD_API_KEY Recommended โ€” API key used to authenticate against the Collector. AGENTGUARD_AGENT_ID No cerbereag_mcp_client Identifier used to scope policy and budget checks. AGENTGUARD_MAX_BUDGET No 10.0 Max USD spend before authorize_tool_call starts blocking on budget. ๐Ÿงฉ Running it manually (for testing) AGENTGUARD_MCP_COLLECTOR_URL=http://localhost:8080 \ AGENTGUARD_API_KEY=ag-your-key \ cerbere-ag-mcp The server starts on stdio, as expected by MCP clients โ€” it is not meant to be run as a standalone HTTP service. ๐Ÿ”— Related Core SDK (decorator-based integration for Python agents): cerbere-ag Dashboard, policy docs, other framework integrations (LangGraph, CrewAI, Composio, HTTP gateway): app.cerbereag.site Source: github.com/chrismsmr-celcom/agentguard

First seen 2 Oct 2026. Evidence as of 5 Oct 2026.

-
Tools
No tool list captured yet
1
Source listings
Each with its own history
0
Recorded changes
Since first seen

Tools

No tool list captured yet.

Change history

No changes since the first observation. The first snapshot is the baseline.

Source listings
SourceListingFirst seenLast seenVersions
Smitherychrismsmr/cerbereag-mcp2 Oct 20265 Oct 20261