
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@stlw/warden-mcp-gateway
Advanced tools
MCP proxy gateway with policy enforcement, server allowlist, and lateral movement detection
Policy enforcement for custom MCP integrations. MCPRegistry defines which servers and tools may be reached; WardenGateway checks each call for allowlist, path, OAuth, rate-limit, lateral-movement, and policy violations before your MCP client executes it.
npm install @stlw/warden-mcp-gateway @stlw/warden
Create a registry, construct the gateway with a ledger and context manager, then wrap an allowed server:
import { ContextManager, MemoryLedgerStore, TrustLevel } from "@stlw/warden";
import { MCPRegistry, WardenGateway } from "@stlw/warden-mcp-gateway";
const registry = new MCPRegistry([
{
name: "filesystem",
type: "local",
transport: "stdio",
allowedTools: ["read_file"],
authRequired: false,
},
]);
const gateway = new WardenGateway({
config,
ledger: new MemoryLedgerStore(),
contextManager: new ContextManager(),
registry,
});
const filesystem = gateway.wrapMCP("filesystem", {
serverName: "filesystem",
allowedTools: ["read_file"],
trustLevel: TrustLevel.TOOL,
maxCallsPerMinute: 120,
});
const decision = await filesystem.onToolCall(
"read_file",
{ path: "./README.md" },
"session-1",
"task-1",
);
if (decision.action !== "ALLOW") throw new Error(decision.reason);
config is the PolicyConfig loaded from your Warden configuration. Keep the registry restrictive: an unlisted server or tool is denied before policy evaluation. Use allowedPaths for filesystem boundaries and authRequired: true for servers that need OAuth credentials.
Use gateway.listTools(serverName, upstreamTools) (or the wrapped server's
listTools) when proxying MCP tools/list. It retains only tools allowed by
the registry whose policy result is ALLOW. A client must still pass normal
call-time authorization; discovery is not an authorization grant.
Gateway policy evaluation, rate limits, and ledger entries use the canonical
action ID mcp.<server>.<tool> (for example,
mcp.filesystem.read_file). Existing <server>__<tool> policy rules remain
supported during migration.
For a multi-step approval UX, call requestApprovalGrant from a trusted
gateway-side approval adapter after the configured approval channel is
available. The returned grant can be supplied as the final onToolCall
argument. It is valid for 60 seconds and is single-use, bound to the session,
task, canonical action, and exact tool input. Never expose the approval API to
an unauthenticated MCP client.
If you do not need a custom MCP client, @stlw/warden-cli provides the ready-to-run warden proxy stdio server. See the public manual for client configuration and the CLI package.
FAQs
MCP proxy gateway with policy enforcement, server allowlist, and lateral movement detection
The npm package @stlw/warden-mcp-gateway receives a total of 164 weekly downloads. As such, @stlw/warden-mcp-gateway popularity was classified as not popular.
We found that @stlw/warden-mcp-gateway demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.