MCP Safety Policy
Rules to start from for the tool calls an agent makes, and a way to test them. Each call gets one answer: allow, confirm or deny. Plain JSON, first match wins, edit them to fit your tools. Offline and deterministic.
Version 1.0.3 · A$12 · MIT licence · Node 20+ · no dependencies
What the rules stop, as shipped
- Shell:
rm -rf,sudo,mkfs,dd, piping a download into a shell, force push,git reset --hard, and commands that read.ssh,.awsor.envor upload data. A command not on a short read-only and test list asks first. - Files: SSH and cloud keys,
.env, wallet and seed-phrase files, shell profiles,.git/configand hooks,.claude/settings, and any path with a..part. Absolute paths ask. - Deletion: tools named delete, remove, drop, truncate, purge or wipe, and SQL that drops data or deletes without a WHERE clause.
- Payments: every payment asks. A missing amount, an amount over the cap or a recipient not on your list is denied.
- Network: plain http, and URLs whose query string carries a name such as
token,keyorpassword. https to a host you list is allowed; any other host is denied.
What is in the kit
- Five rule files (shell, filesystem, deletion, payments, network egress)
- An evaluator:
mcp-safety-policy checkdecides one call (exit 0 allow, 1 deny, 3 confirm) - A before-tool-call hook: generic JSON on stdin, exit 2 on deny, with a Claude Code
PreToolUseexample - A token estimate for a tool list (characters / 4), with an option to write a copy with shorter descriptions
- README, LIMITS.md, CHANGELOG, MIT licence, 128 automated tests
Limits
- This is a guard, not a guarantee. Review every rule before you rely on it.
- The patterns catch plain spellings. Quoting tricks, variables, encodings and scripts that run other scripts are not caught.
- A test runner on the allow list still runs your project's code, which can write anything.
- It sees one call at a time: not earlier calls, the user's intent, file contents or what a command does once it runs.
- The rules are written for common tool names. Until you edit them, your own tools fall through to the default, which asks. Broad names such as
read*,fetch*ordelete*also catch tools you did not mean. - The hook blocks only when it runs. A missing
node, a wrong path or a timeout lets the call through. - A Grep with no path can print lines from a
.envfile in the workspace. - An allowed host also admits its subdomains, and any allowed URL can still carry data in its path.
- Payment caps are per call. It does not total spend over time, and it never sends money.
- The code has not had an independent audit. It is a set of starting rules, not security advice.
The full list is in LIMITS.md inside the zip.
How to buy
Send this shop a Nostr DM: buy mcp-safety-policy. The reply is a quote in satoshis (from the AUD price and the mempool.space rate) and a one-use on-chain address. The quote holds for 30 minutes.
About this shop
Delivery: digital download by Nostr DM, within 24 hours after your payment is confirmed. Small files arrive inside the DM; larger ones arrive as a download link with a SHA-256 checksum.
Who it is for: businesses and developers. Not sold to consumers in the EU or UK.
Refunds: change-of-mind refunds are not offered; your rights under the Australian Consumer Law are not affected. See the refund policy and the terms.