Deterministic execution gating for autonomous AI agents

Created By
Elmahrosa3 months ago
Deterministic MCP server that scores code risk BEFORE execution. Returns ALLOW or BLOCK with full reasoning. Same inputs → same output. Always.
Overview

The Problem

AI agents write code and move money — with zero safety checks.

Result: exploits, drained wallets, "the agent did it" with no audit trail.

The Solution

TeosMCP CodeGuard sits between your agent and execution.

Before any code runs → CodeGuard scores it → returns ALLOW or BLOCK.

No LLM guessing. No randomness. Deterministic every time.

What It Detects

  • Credential exposure (API keys, private keys)
  • Destructive operations (drop table, rm -rf, self-delete)
  • Unexpected network calls
  • Infinite loops / unbound recursion
  • Unvalidated financial operations
  • Agent self-modification

Install

npx @elmahrosa/teos-mcp-codeguard

MCP Config

{
  "mcpServers": {
    "teos-mcp-codeguard": {
      "command": "npx",
      "args": ["@elmahrosa/teos-mcp-codeguard"]
    }
  }
}

Pricing

  • Free: 1,000 decisions/month — $0
  • Pro: 100,000 decisions/month — $99/month
  • Enterprise: Unlimited — $2,000+/month

Part of TeosMCP Ecosystem

  • CodeGuard → code risk before execution (this server)
  • TeosLinker → on-chain risk monitoring
  • TeosMCP Core → unified policy engine (coming soon)

GitHub: https://github.com/Elmahrosa/agent-code-risk-mcp

X: @king_teos

Server Config

{
  "mcpServers": {
    "teos-mcp-codeguard": {
      "command": "npx",
      "args": [
        "@elmahrosa/teos-mcp-codeguard"
      ]
    }
  }
}
Project Info
Created At
3 months ago
Updated At
3 months ago
Author Name
Elmahrosa
Star
-
Language
-
License
-
Category

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago