node9 · MCP Server

MCP-Server · 03a29449 · Quellenstand

MCP-Server für Google Gemini · lesen und schreiben und senden · Apache-2.0 · lokal (stdio)

Beschreibung des Anbieters

Access control for AI agents and MCP servers: allow, hold for approval, or block each tool call

Werkzeuge

node9_status
Show the current node9 protection status: mode, daemon state, pause state, active shields, and whether agent hooks are wired. Use this to understand what protection is active before doing risky work. Angabe des Anbieters · Beleg 5
node9_config_get
Read the current node9 configuration: security mode, approver channels, timeouts, DLP settings, and the number of active smart rules.… Angabe des Anbieters · Beleg 5
node9_shield_list
List all available node9 shields and which ones are currently active. Shields are pre-packaged rule sets for specific services (postgres, aws, github, filesystem). Angabe des Anbieters · Beleg 5
node9_shield_enable
Enable a node9 shield for a specific service. Shields only add protection — they cannot be used to weaken or bypass node9. Use node9_shield_list to see available shield names. Angabe des Anbieters · Beleg 5
node9_shield_disable
Disable a node9 shield. WEAKENING action — refused over MCP by default (a human must run "node9 shield disable <name>" from the CLI). Use node9_shield_list to see active shields. Angabe des Anbieters · Beleg 5
node9_approver_list
List all node9 approver channels and their current enabled/disabled state. Approvers are the channels through which node9 asks a human to approve risky tool calls.… Angabe des Anbieters · Beleg 5
node9_approver_set
Enable or disable a specific node9 approver channel in the global config (~/.node9/config.json). Use this to turn individual channels on or off without touching other settings.… Angabe des Anbieters · Beleg 5
node9_audit_get
Read recent entries from the node9 audit log (~/.node9/audit.log). Each entry shows timestamp, outcome, tool name, the command, and the rule that fired.… Angabe des Anbieters · Beleg 5
node9_policy_get
Show all active smart rules in detail — name, tool, verdict, conditions, and reason. Includes default rules, shield rules, and any custom project rules.… Angabe des Anbieters · Beleg 5
node9_scan
Scan all AI agent history (Claude + Gemini) and report what node9 would have blocked or flagged. Shows blocked operations, reviewed commands, credential leaks, and agent spend.… Angabe des Anbieters · Beleg 5
node9_report
Show an activity and security report: tool call counts, blocks, DLP findings, agent cost, and daily trends for a chosen period. Covers all AI agents (Claude, Gemini, etc.). Angabe des Anbieters · Beleg 5
node9_session
List recent AI agent sessions with per-session summaries: tool calls, cost, modified files, and any blocked operations. Pass a session_id to see the full tool trace for that session. Angabe des Anbieters · Beleg 5
node9_posture
Run the node9 security posture scorecard for the agent on this host — grades how exposed the machine is to a compromised agent across isolation, egress, secrets-on-disk, supply chain, and privilege,… Angabe des Anbieters · Beleg 5
node9_explain
Preview exactly how node9 would evaluate a tool call BEFORE running it — the full allow / review / block waterfall and step-by-step policy trace. Use this to self-check a command (e.g.… Angabe des Anbieters · Beleg 5
node9_rule_add
Add a new protective smart rule to the global node9 config (~/.node9/config.json). Rules can block or send dangerous commands for human review based on regex conditions.… Angabe des Anbieters · Beleg 5
node9_egress_status
Show egress (outbound network) control: whether it is enabled, the mode (off / review / block), and your allow + deny host lists.… Angabe des Anbieters · Beleg 5
node9_egress_protect
Turn on egress control (or strengthen it). mode="review" prompts on unknown hosts; mode="block" hard-blocks them.… Angabe des Anbieters · Beleg 5
node9_egress_deny
Add a host to the egress deny list (deny always wins over allow). Only adds protection, so it is always allowed over MCP. Host is an FQDN or wildcard glob (e.g. evil.com or *.evil.com). Angabe des Anbieters · Beleg 5

Voraussetzungen

  • npx · Paketmanager · erforderlich · Beleg 1
  • Node.js · Laufzeit · erforderlich · Beleg 6
  • NODE9_TESTING · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 7
  • SHELL · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 7
  • NODE9_API_KEY · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 8
  • NODE9_API_URL · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 8
  • NODE9_PROFILE · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 8
  • NODE_ENV · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 8
  • NODE9_MODE · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 8
  • NODE9_DEBUG · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 9
  • NODE9_WATCH_MODE · Umgebungsvariable · Pflichtigkeit nicht deklariert · Beleg 10

Installation

npx -y node9-ai@2.26.2 mcp-server

Angaben zum Baustein

—: Angabe nicht belegt.

Maintainer
node9-ai
Repository-Lizenz
Apache-2.0
Letzter Repository-Commit

Commit innerhalb 90 Tagen

Dienstanbieter
Offizielle Dienstherkunft nicht belegt
Dienste
Google Gemini
Bereiche
—
Plattformen
—
Version
2.26.2
Release
v2.26.2
Clients
Claude Code, Claude Desktop, Cursor, Codex, Windsurf, Gemini CLI
Repository-Themen
ai-safety, ai-security, claude-code, llm-agent, agent-security, dlp, github-actions, mcp-security, mcp-servers, prompt-injection

Zugriffe und Risiken

Regelbasiert abgeleitete Zugriffe
lesen, schreiben, senden
Authentifizierung
—
Transport
stdio
Technische Prüfung
Ungeprüft

Fehlende Angaben bedeuten unbekannte Zugriffe. Vor dem Einsatz Konten, Dateien, Netzwerkverbindungen und Ausführungsrechte im konkreten Paket prüfen. Eine frische Änderung am Repository belegt keine Wartung jeder einzelnen Datei.

Nur die für den Arbeitsablauf nötigen Berechtigungen vergeben und Schreibaktionen mit einem Freigabeschritt absichern. Lizenz und Wartungsdatum sind keine Sicherheitsfreigabe.

Der Lizenzbeleg betrifft das Quellcode-Repository. Einzelne Unterpakete und gehostete Dienste können eigene Bedingungen haben; prüfe sie beim konkreten Installations- oder Diensteangebot.

Belege und Datenstand

03A29449<MCPSERVE<20261004<<<<Q10<UNGEPRUEFT<<<<<<<<<<<<<<<<

Verbundenes