PlugMyPlugin
โ† Browse

protect-mcp

wshobson โ˜… 319

This plugin enforces Cedar-based authorization policies on every Claude Code tool call and generates Ed25519-signed audit receipts that are independently verifiable offline. It prevents unauthorized tool execution before it happens and maintains a hash-chained trail of all decisions with cryptographic proof.

Security DevOps free runs shell

Install

> /plugin marketplace add wshobson/agents/tree/HEAD/plugins/protect-mcp
> /plugin install protect-mcp

Source: https://github.com/wshobson/agents/tree/HEAD/plugins/protect-mcp

What it's made of

2 commands ยท 2 agents ยท 1 skill ยท 2 hooks

Commands
2
Agents
2
Skills
1
MCP servers
0
Hooks
2 ยท PostToolUse, PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
evaluate.sh sign.sh
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (wshobson).