# Mcp Policy

> Enforce MCP server allowlists and blocklists against developer configs. CLI + GitHub Action.

- **Type:** MCP server
- **Install:** `agentstack add mcp-mattschaller-mcp-policy`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [mattschaller](https://agentstack.voostack.com/s/mattschaller)
- **Installs:** 0
- **Category:** [Developer Tools](https://agentstack.voostack.com/c/developer-tools)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [mattschaller](https://github.com/mattschaller)
- **Source:** https://github.com/mattschaller/mcp-policy

## Install

```sh
agentstack add mcp-mattschaller-mcp-policy
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# mcp-policy

Enforce MCP server allowlists and blocklists against developer configs. Catches unauthorized MCP servers before they reach production.

No MCP gateway or enterprise SaaS required — just a `policy.yml` and your existing `.mcp.json` or `claude_desktop_config.json`.

## Install

```bash
npm install -g mcp-policy
```

## Usage

### CLI

```bash
# Check .mcp.json against policy.yml in current directory
mcp-policy check

# Specify files explicitly
mcp-policy check .mcp.json claude_desktop_config.json --policy policy.yml

# Fetch policy from URL
mcp-policy check --policy-url https://example.com/mcp-policy.yml

# JSON output
mcp-policy check --format json
```

### GitHub Action

```yaml
- uses: mattschaller/mcp-policy@v0
  with:
    policy-path: policy.yml
    config-paths: .mcp.json
```

### Programmatic API

```typescript
import { checkPolicy, loadPolicy, parseConfig, extractAllServers, checkServersAgainstPolicy } from 'mcp-policy';

// High-level
const { results, pass } = await checkPolicy({
  policyPath: 'policy.yml',
  configPaths: ['.mcp.json'],
});

// Low-level
const policy = loadPolicy({ path: 'policy.yml' });
const config = parseConfig(fs.readFileSync('.mcp.json', 'utf-8'));
const servers = extractAllServers(config);
const result = checkServersAgainstPolicy(servers, policy);
```

## Policy Schema

```yaml
version: 1

# Servers that are allowed. Empty list = no restriction.
allowed:
  - name: "@modelcontextprotocol/*"
    maxVersion: "2.0.0"
  - name: mcp-server-sqlite

# Servers that are always blocked (takes priority over allowed).
blocked:
  - pattern: "evil-*"

# Require all servers to pin a version (e.g., @1.2.3)
requireVersionPin: false

# Require all servers to pin a SHA256 hash (future)
requireSHAPin: false
```

### Server Name Resolution

mcp-policy extracts the server name from each config entry:

| Command | Extracted Name |
|---------|---------------|
| `npx @scope/server@1.0` | `@scope/server` (version: `1.0`) |
| `npx -y mcp-server` | `mcp-server` |
| `pnpm dlx mcp-server` | `mcp-server` |
| `bunx mcp-server` | `mcp-server` |
| `node ./local.js` | `null` (warning) |
| `docker run img` | `img` |
| `/usr/bin/mcp-sqlite` | `mcp-sqlite` |
| `url: https://...` | URL (SSE transport) |

### Pattern Matching

Both `allowed[].name` and `blocked[].pattern` support `*` wildcards:

- `@modelcontextprotocol/*` — matches any package in the scope
- `mcp-*` — matches any package starting with `mcp-`
- `*-server` — matches any package ending with `-server`

## Exit Codes

| Code | Meaning |
|------|---------|
| 0 | All servers pass policy |
| 1 | One or more violations |
| 2 | Runtime error (bad config, missing policy) |

## See also

Pair with [eslint-plugin-mcp-security](https://github.com/mattschaller/eslint-plugin-mcp-security) to catch vulnerabilities *inside* MCP server code — 13 ESLint rules mapped to the OWASP MCP Top 10 and real CVEs.

## License

MIT

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [mattschaller](https://github.com/mattschaller)
- **Source:** [mattschaller/mcp-policy](https://github.com/mattschaller/mcp-policy)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** yes
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-mattschaller-mcp-policy
- Seller: https://agentstack.voostack.com/s/mattschaller
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
