zn-gate (local)

Protect MCP servers

Wrap existing MCP servers with zn automatically (init) or one by one (shield).

View .md

Automatic: zn-gate init

init finds the MCP configuration of supported environments (Claude Desktop, Claude Code, Cursor, Antigravity, Codex, OpenCode and others), backs it up and wraps each server with zn.

# Preview what would change
npx -y zn-gate init --dry-run

# Apply, in non-blocking shadow mode first (log only, nothing dropped)
npx -y zn-gate init --shadow

# Enforce
npx -y zn-gate init

# Restore the original configs from the backups
npx -y zn-gate init --revert

Start with --shadow, review the logs (npx -y zn-gate logs), then enforce.

One server: zn-gate shield

Put zn in front of any MCP server command. zn inspects outgoing tool arguments, sanitizes tool results and checks tools/list descriptions for poisoned instructions:

npx -y zn-gate shield -- uvx mcp-server-fetch
npx -y zn-gate shield -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/db

In a client config, replace the server command with npx and prefix the original arguments with -y zn-gate shield --.

Keep tool access narrow

zn stops hostile input; it does not decide which tools an agent should have. After wrapping, review each server and keep only the tools your agent needs. Put destructive operations behind explicit approval.