Shellward
Shellward is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP. It has 140 GitHub stars, is released under the Apache-2.0 license and runs locally with npx -y shellward.
- Other
- Apache-2.0
- Actively maintained
Install Shellward
Generated from the server's MCP registry entry. Replace your-value with your own values.
Claude Desktop
{
"mcpServers": {
"shellward": {
"command": "npx",
"args": [
"-y",
"shellward"
],
"env": {
"SHELLWARD_MODE": "your-value",
"SHELLWARD_LOCALE": "your-value",
"SHELLWARD_THRESHOLD": "your-value"
}
}
}
}Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.
Claude Code
claude mcp add --env SHELLWARD_MODE=your-value --env SHELLWARD_LOCALE=your-value --env SHELLWARD_THRESHOLD=your-value --transport stdio shellward -- npx -y shellwardCursor
{
"mcpServers": {
"shellward": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"shellward"
],
"env": {
"SHELLWARD_MODE": "your-value",
"SHELLWARD_LOCALE": "your-value",
"SHELLWARD_THRESHOLD": "your-value"
}
}
}
}Project file; use ~/.cursor/mcp.json to enable it in every project.
VS Code
{
"servers": {
"shellward": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"shellward"
],
"env": {
"SHELLWARD_MODE": "your-value",
"SHELLWARD_LOCALE": "your-value",
"SHELLWARD_THRESHOLD": "your-value"
}
}
}
}Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).
Environment variables
Variables the server reads at startup.
| Name | Required | Description |
|---|---|---|
SHELLWARD_MODE | No | Security mode: enforce (block + log) or audit (log only) |
SHELLWARD_LOCALE | No | Locale: auto, zh, or en |
SHELLWARD_THRESHOLD | No | Injection detection threshold 0-100 (lower = stricter) |
About Shellward
scan 是确定性扫描:它能告诉你「项目里有境外模型端点」,但判断不了个人信息有没有真的流过去;14 个法规控制项里也有 11 个它只能标「需人工确认」。这一段交给你的编码 agent 来做——Claude Code、Cursor、Codex 等支持 Agent Skills 的工具都能用。
- openclaw
- prompt-injection
- security
- ai-agent
- ai-security
- llm-security
- shellward
- pii-detection
- agent-security
- cursor
Similar MCP servers
More other MCP servers
Reactive Resume
reactive-resume/reactive-resume
A one-of-a-kind resume builder that keeps your privacy in mind.
OtherTypeScriptN8n MCP
czlonkowski/n8n-mcp
A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you.
OtherTypeScriptXHS Downloader
JoeanAmier/XHS-Downloader
小红书(XiaoHongShu、RedNote)链接提取/作品采集工具.
OtherJavaScriptMCP Use
mcp-use/mcp-use
The fullstack MCP framework to develop MCP Apps for ChatGPT / Claude & MCP Servers for AI Agents.
OtherTypeScriptHa MCP
homeassistant-ai/ha-mcp
Comprehensive Model Context Protocol server for managing Home Assistant through AI assistants.
OtherPythonMCP Server Chart
antvis/mcp-server-chart
A Model Context Protocol server for generating charts using AntV.
OtherTypeScript
What is Shellward?
Shellward is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP. It has 140 GitHub stars, is released under the Apache-2.0 license and runs locally with npx -y shellward. The source code is at github.com/jnMetaCode/shellward.
How do I install the Shellward MCP server?
Add the command npx -y shellward to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.
Is Shellward free?
The server is open source under the Apache-2.0 license, so running it is free. It does not declare any required API key.
Is Shellward actively maintained?
The most recent commit was on Sep 28, 2026. The latest release is v0.7.21, published Jun 23, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.