
Product
Microsoft Teams Notifications Are Now Available in Socket
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.
@sidclaw/mcp-tools
Advanced tools
MCP server that exposes SidClaw governance as tools — any MCP-compatible agent gets policy checks, approvals, and audit traces.
MCP server that exposes SidClaw governance as callable tools — the
complement to the transparent MCP proxy shipped with @sidclaw/sdk.
Where the proxy wraps an upstream MCP server and gates its tools, this server provides governance primitives (evaluate, record, approve, policies) that any MCP-aware agent can call directly. Use it with Claude Code, Claude Desktop, or any MCP host.
MIT licensed.
npx @sidclaw/mcp-tools --version
Add to your MCP config:
{
"mcpServers": {
"sidclaw": {
"command": "npx",
"args": ["-y", "@sidclaw/mcp-tools"],
"env": {
"SIDCLAW_BASE_URL": "https://api.sidclaw.com",
"SIDCLAW_API_KEY": "ai_your_key_here",
"SIDCLAW_AGENT_ID": "claude-code"
}
}
}
}
Restart your MCP host. The agent can now call:
| Tool | What it does |
|---|---|
sidclaw_evaluate | Pre-action policy check. Returns allow / approval_required / deny. |
sidclaw_record | Log an action outcome (success/error + token usage). |
sidclaw_approve | Block until a human decides on a flagged action. |
sidclaw_policies | List active policies. |
sidclaw_session_start | Register a session. |
sidclaw_session_end | Close a session. |
Plus three resources:
sidclaw://policies — active rulessidclaw://status — instance healthsidclaw://agent/{agent_id}/history — last 50 traces for an agent| Variable | Required | Default |
|---|---|---|
SIDCLAW_BASE_URL | yes | — |
SIDCLAW_API_KEY | yes | — |
SIDCLAW_AGENT_ID | no | claude-code |
SIDCLAW_MCP_NAME | no | sidclaw-mcp-tools |
| Scenario | Pick |
|---|---|
| Wrap an existing MCP server (Postgres, filesystem, GitHub) | @sidclaw/sdk → sidclaw-mcp-proxy |
| Give the agent explicit governance tools to call | @sidclaw/mcp-tools (this) |
| You want both — agent self-governs AND downstream MCPs are gated | Load both servers |
Both approaches are complementary and can run side-by-side.
npm install
npm test # vitest unit tests
npm run build # tsup → dist/
npm run typecheck
FAQs
MCP server that exposes SidClaw governance as tools — any MCP-compatible agent gets policy checks, approvals, and audit traces.
The npm package @sidclaw/mcp-tools receives a total of 12 weekly downloads. As such, @sidclaw/mcp-tools popularity was classified as not popular.
We found that @sidclaw/mcp-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.