A lightweight, sub-millisecond security shim that prevents AI agents from accessing sensitive files (.env, SSH keys) and executing destructive commands via MCP.
Rust
0
2 commits
updated Oct 5, 2026
argos)Zero-overhead policy enforcement gateway and runtime guardrail for Model Context Protocol (MCP) servers.
argos acts as a transparent security pipe between AI clients (Claude Desktop, Cursor) and underlying MCP tool servers. Inspired by the zero-friction philosophy of Quad9/Pi-hole, it inspects raw JSON-RPC traffic on the fly and deterministically blocks unauthorized file access, path traversal attacks, and destructive commands before they reach your system.
../ stripping..env, private keys (id_rsa, id_ed25519), and cloud credentials.rm -rf, disk formatters, fork bombs).argos-audit.log) without cloud telemetry.argos.toml.Download the latest pre-compiled binary for your system from the Releases page:
argos.exe (or unpack argos-windows-x86_64.zip).argos-linux-x86_64.tar.gz:
tar -xvf argos-linux-x86_64.tar.gz
chmod +x argos
If you are running macOS (Apple Silicon / Intel) or prefer compiling locally:
git clone [https://github.com/JUSICK/Argos-mcp-guardrail.git](https://github.com/JUSICK/Argos-mcp-guardrail.git)
cd Argos-mcp-guardrail
cargo build --release
The compiled binary will be located at:
Create and place argos.toml next to the argos executable or in your workspace root:
[filesystem]
# Enforce workspace boundary checks
block_path_traversal = true
# Block access to sensitive files and credentials
blocked_patterns = [".env", ".ssh", "id_rsa", "id_ed25519", "credentials"]
# Explicit exceptions allowed through the policy
allowed_patterns = [".env.example", ".env.sample", ".env.template"]
[commands]
# Block destructive terminal commands
blocked_commands = [
"rm -rf",
"mkfs",
":(){ :|:& };:",
"chmod -R 777",
"dd if="
]
[audit]
enabled = true
# Allows to log ALLOWED processes
log_allowed = false
# Just a file name to create one in the same directory where argos is, or full dir
log_file = "argos-audit.log"
Update your claude_desktop_config.json:
{
"mcpServers": {
"Argos": {
"command": "C:\\path\\to\\argos.exe",
"args": [
"--",
"npx.cmd",
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\\Users\\username\\projects\\my-workspace"
]
}
}
}
{
"mcpServers": {
"Argos": {
"command": "/usr/local/bin/argos",
"args": [
"--",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/projects/my-workspace"
]
}
}
}
Restart Claude Desktop, and Argos will actively guard your tool calls against unauthorized filesystem traversal and credential exposure.
[ AI Client (Claude / Cursor) ]
│
│ stdin / stdout (JSON-RPC)
▼
┌───────────────────────┐
│ argos │ <── Inspects tools/call in <0.2ms
└───────────────────────┘
│ │
(If Allowed) (If Blocked) ──> Returns JSON-RPC Error & logs event
│
▼
[ Real MCP Tool Server ]
You are able to have as many Argos as you want, change their names e.g. "Argos-Backend", "Argos-Frontend" for a big project that has 2 or more AI agents.
MIT License. Free for personal and commercial use.
A lightweight, sub-millisecond security shim that prevents AI agents from accessing sensitive files (.env, SSH keys) and executing destructive commands via MCP.
Rust
0
2 commits
updated Oct 5, 2026
argos)Zero-overhead policy enforcement gateway and runtime guardrail for Model Context Protocol (MCP) servers.
argos acts as a transparent security pipe between AI clients (Claude Desktop, Cursor) and underlying MCP tool servers. Inspired by the zero-friction philosophy of Quad9/Pi-hole, it inspects raw JSON-RPC traffic on the fly and deterministically blocks unauthorized file access, path traversal attacks, and destructive commands before they reach your system.
../ stripping..env, private keys (id_rsa, id_ed25519), and cloud credentials.rm -rf, disk formatters, fork bombs).argos-audit.log) without cloud telemetry.argos.toml.Download the latest pre-compiled binary for your system from the Releases page:
argos.exe (or unpack argos-windows-x86_64.zip).argos-linux-x86_64.tar.gz:
tar -xvf argos-linux-x86_64.tar.gz
chmod +x argos
If you are running macOS (Apple Silicon / Intel) or prefer compiling locally:
git clone [https://github.com/JUSICK/Argos-mcp-guardrail.git](https://github.com/JUSICK/Argos-mcp-guardrail.git)
cd Argos-mcp-guardrail
cargo build --release
The compiled binary will be located at:
Create and place argos.toml next to the argos executable or in your workspace root:
[filesystem]
# Enforce workspace boundary checks
block_path_traversal = true
# Block access to sensitive files and credentials
blocked_patterns = [".env", ".ssh", "id_rsa", "id_ed25519", "credentials"]
# Explicit exceptions allowed through the policy
allowed_patterns = [".env.example", ".env.sample", ".env.template"]
[commands]
# Block destructive terminal commands
blocked_commands = [
"rm -rf",
"mkfs",
":(){ :|:& };:",
"chmod -R 777",
"dd if="
]
[audit]
enabled = true
# Allows to log ALLOWED processes
log_allowed = false
# Just a file name to create one in the same directory where argos is, or full dir
log_file = "argos-audit.log"
Update your claude_desktop_config.json:
{
"mcpServers": {
"Argos": {
"command": "C:\\path\\to\\argos.exe",
"args": [
"--",
"npx.cmd",
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\\Users\\username\\projects\\my-workspace"
]
}
}
}
{
"mcpServers": {
"Argos": {
"command": "/usr/local/bin/argos",
"args": [
"--",
"npx",
"-y",
"@modelcontextprotocol/server-filesystem",
"/Users/username/projects/my-workspace"
]
}
}
}
Restart Claude Desktop, and Argos will actively guard your tool calls against unauthorized filesystem traversal and credential exposure.
[ AI Client (Claude / Cursor) ]
│
│ stdin / stdout (JSON-RPC)
▼
┌───────────────────────┐
│ argos │ <── Inspects tools/call in <0.2ms
└───────────────────────┘
│ │
(If Allowed) (If Blocked) ──> Returns JSON-RPC Error & logs event
│
▼
[ Real MCP Tool Server ]
You are able to have as many Argos as you want, change their names e.g. "Argos-Backend", "Argos-Frontend" for a big project that has 2 or more AI agents.
MIT License. Free for personal and commercial use.