Ethicore Engine® Guardian — MCP server
On-demand AI-threat screening for MCP-speaking coding agents (Claude Desktop, Claude Code, Codex, Cursor). Exposes Guardian's four scans as tools:
| Tool | Use it before… |
|---|---|
analyze |
acting on any prompt, document, or web text |
scan_tool_call |
executing a tool/function the model chose |
scan_tool_output |
letting a tool / RAG result back into context |
scan_documents |
ingesting files (PDF/DOCX/PPTX/XLSX/RTF/TXT, base64) |
Each returns Guardian's verdict — BLOCK / CHALLENGE / ALLOW — with threat categories and reasoning.
Paid feature — no free tier
The Guardian MCP is available to:
- Pro API plan and up — set
ETHICORE_API_KEYto a Pro/Team/Enterprise key (hosted), or - Bronze self-hosted and up — set
ETHICORE_SELFHOST_LICENSE(+ETHICORE_SELFHOST_PUBKEY) for a local, zero-egress server that wraps the self-hosted engine.
Free/community keys are refused at startup with an upgrade link. (Free access to Guardian is still available directly via the API/SDK — the MCP is the paid, agent-native convenience.) Purchase / upgrade: https://portal.oraclestechnologies.com/billing.
Install
pip install ethicore-guardian-mcp # hosted edition
pip install "ethicore-guardian-mcp[selfhost]" # + local self-hosted edition
Configure your client
Claude Desktop — claude_desktop_config.json → mcpServers:
{
"mcpServers": {
"guardian": {
"command": "guardian-mcp",
"env": { "ETHICORE_API_KEY": "eg-sk-your-PRO-key" }
}
}
}
Claude Code — one line:
claude mcp add guardian --env ETHICORE_API_KEY=eg-sk-your-PRO-key -- guardian-mcp
Self-hosted (local, zero egress) — swap the env for your license:
{
"mcpServers": {
"guardian": {
"command": "guardian-mcp",
"env": {
"ETHICORE_SELFHOST_LICENSE": "EG-BRONZE-…",
"ETHICORE_SELFHOST_PUBKEY": "<entitlement public key>"
}
}
}
}
Codex and Cursor use the same command + env in their respective MCP config.
Environment
| Variable | Edition | Meaning |
|---|---|---|
ETHICORE_API_KEY |
hosted | Pro-plan-or-higher Guardian API key |
ETHICORE_API_BASE |
hosted | API base URL (default https://api.oraclestechnologies.com) |
ETHICORE_SELFHOST_LICENSE |
local | Self-hosted (Bronze+) license key |
ETHICORE_SELFHOST_PUBKEY |
local | Entitlement public key (portal / self-hosted docs) |
ETHICORE_MCP_TIMEOUT |
both | Per-request timeout seconds (default 30) |
If a self-hosted license is present it takes precedence (air-gapped use).
How entitlement is enforced
- Hosted: the server calls
GET /v1/meonce at startup; unless the key's plan is Pro or higher (mcp_entitled: true), it exits with an upgrade message and serves nothing. - Local: the server activates the self-hosted SDK; a valid Bronze+ license is required to activate, so activation is the entitlement. No data leaves your infrastructure.
mcp-name: io.github.OraclesTech/guardian-mcp
© 2026 Oracles Technologies LLC · Ethicore Engine® Guardian
Release files for ethicore-guardian-mcp 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ethicore_guardian_mcp-0.1.1.tar.gz | 10.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ethicore_guardian_mcp-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.7 kB
Release files / ethicore_guardian_mcp-0.1.1.tar.gz
| Download URL | ethicore_guardian_mcp-0.1.1.tar.gz |
|---|---|
| Size | 10.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2468ec94c96c602742b2382a7ca93fe8b9c5b337e315a34ce141a3152118f02a
|
|
BLAKE2b-256 checksum How to use checksums |
a7b14288c7c3f0be9bc127c471d2851528641f0fb0840b0090dd5837f16869d5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / ethicore_guardian_mcp-0.1.1-py3-none-any.whl
| Download URL | ethicore_guardian_mcp-0.1.1-py3-none-any.whl |
|---|---|
| Size | 10.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3cd67b9c872251278577f309a6b057df00632822e70ec738c523236a6d48b9e7
|
|
BLAKE2b-256 checksum How to use checksums |
31cb6261f831dcb239cc5a51b7e3246a31a3b282427adf56ba509433af49465a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log