protect-mcp
Cedar policy enforcement plus Ed25519 signed receipts for every Claude Code tool call.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for protect-mcp, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Claude Code plugin that gates every tool call through Cedar authorization policies and emits Ed25519-signed receipts for each decision before it runs. It intercepts and policy-checks all tool invocations, making it a cryptographic governance layer directly on the agent's action path — one of the most security-central plugins in the marketplace.
Key features and capabilities
- Cedar policy-gated tool calls
- Ed25519 signed receipts
- Pre-execution decision enforcement
Use cases
- Policy-gate agent tool use
- Produce a cryptographic audit trail