iridium-mcp-server
MCP server for AI agent security guardrails — blocks vulnerable imports at generation time.
Install
pip install iridium-mcp-server
Cursor setup
Add to your MCP config (see src/iridium_mcp/cursor_config.json):
{
"mcpServers": {
"iridium": {
"command": "iridium-mcp-server",
"env": {
"IRIDIUM_API_URL": "https://api.iridium.example.com"
}
}
}
}
No API key required for anonymous tier (rate-limited).
Tools (Phase 2)
| Tool | Purpose |
|---|---|
validate_dependency_addition |
Check if adding a package creates reachable CVE risk |
get_reachability_context |
Return entrypoint → sink path + rewrite hints for agents |
refresh_workspace_graph |
Re-index workspace after agent saves files |
Behavior
- Fail-open: API 429/5xx never blocks the agent — returns
degraded: true - Background warm-index: indexes workspace on startup before first tool call
- Parent heartbeat: exits cleanly when MCP parent process dies
- Audit log: writes to
.iridium/audit.log
Development
uv sync
uv run pytest packages/iridium-mcp-server/tests -v
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file iridium_mcp_server-0.2.0.tar.gz.
File metadata
- Download URL: iridium_mcp_server-0.2.0.tar.gz
- Upload date:
- Size: 5.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
82906269efe1153632ecfffc5af8f3fe3a012231763800d5546bd118a29c8083
|
|
| MD5 |
821d9a427172444963914cd07a01e2d6
|
|
| BLAKE2b-256 |
e7624e509f57b93ed8603d158b63eb2b0c24d86ffd670094b058e5bb4bad4f65
|
Provenance
The following attestation bundles were made for iridium_mcp_server-0.2.0.tar.gz:
Publisher:
publish-mcp.yml on mziqudhd92/Iridium
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
iridium_mcp_server-0.2.0.tar.gz -
Subject digest:
82906269efe1153632ecfffc5af8f3fe3a012231763800d5546bd118a29c8083 - Sigstore transparency entry: 2609652117
- Sigstore integration time:
-
Permalink:
mziqudhd92/Iridium@dfaef1e9be33a096cbe358937aa1c1dfb4997102 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/mziqudhd92
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-mcp.yml@dfaef1e9be33a096cbe358937aa1c1dfb4997102 -
Trigger Event:
push
-
Statement type:
File details
Details for the file iridium_mcp_server-0.2.0-py3-none-any.whl.
File metadata
- Download URL: iridium_mcp_server-0.2.0-py3-none-any.whl
- Upload date:
- Size: 8.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0d812aa724556db44e1a929fb9db4a27aabf60f3023bf56d02f9921c9d56d6ca
|
|
| MD5 |
9277388cb1f32cfe41f2e1c500e49680
|
|
| BLAKE2b-256 |
152d310ab424306eeae4b2ac1a3a4a772854c8d7ef6d3c3a56d7d0b10bb4c300
|
Provenance
The following attestation bundles were made for iridium_mcp_server-0.2.0-py3-none-any.whl:
Publisher:
publish-mcp.yml on mziqudhd92/Iridium
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
iridium_mcp_server-0.2.0-py3-none-any.whl -
Subject digest:
0d812aa724556db44e1a929fb9db4a27aabf60f3023bf56d02f9921c9d56d6ca - Sigstore transparency entry: 2609652353
- Sigstore integration time:
-
Permalink:
mziqudhd92/Iridium@dfaef1e9be33a096cbe358937aa1c1dfb4997102 -
Branch / Tag:
refs/tags/v0.2.0 - Owner: https://github.com/mziqudhd92
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-mcp.yml@dfaef1e9be33a096cbe358937aa1c1dfb4997102 -
Trigger Event:
push
-
Statement type: