Overview
Aguara MCP is an MCP server that gives AI agents the ability to scan skills and configurations for security threats — before installing or running them. It imports Aguara as a Go library — onego install, no external binary needed.
Installation
Available Tools
Your agent gets 4 security scanning tools:scan_content
Scan inline content for security threats without writing to disk.
Parameters:
content(string): The content to scan (skill file, config, etc.)filename(string): Filename for context (e.g., “skill.md”)min_severity(optional): Minimum severity to report (info, low, medium, high, critical)
check_mcp_config
Scan MCP server configuration for security issues.
Parameters:
config_content(string): MCP config JSON contentmin_severity(optional): Minimum severity filter
list_rules
List all available detection rules, optionally filtered by category.
Parameters:
category(optional): Filter by category (prompt-injection, credential-leak, exfiltration, etc.)
explain_rule
Get detailed information about a specific rule including patterns, examples, and remediation.
Parameters:
rule_id(string): Rule identifier (e.g., “PROMPT_INJECTION_001”)
Features
No Network Required
All scanning happens locally with no external API calls
Millisecond Scans
Fast pattern matching and NLP analysis powered by Go
177+ Rules
Comprehensive detection across 13 security categories
No LLM Required
Deterministic static analysis without AI inference
Use Cases
Before Installing Skills
Ask your agent to scan a skill before adding it to your configuration:Before Running MCP Servers
Check MCP server configurations for security risks:Understanding Security Rules
Learn about specific security rules and how to fix them:Exploring Available Rules
Discover what security checks are available:How It Works
Aguara MCP imports the Aguara Go library directly, providing the full scanner capabilities through MCP tools. The agent can:- Scan first — Check content for threats before execution
- Decide intelligently — Review findings with severity and confidence scores
- Explain risks — Understand what each finding means and how to fix it
- Stay offline — No data leaves your machine
GitHub Repository
garagon/aguara-mcp
View source code, report issues, and contribute to Aguara MCP
Related
- Aguara Watch — Continuous monitoring of 28,000+ AI agent skills
- Go Library — Embed Aguara in your own tools
- Detection Rules — 177+ built-in security rules
