{"slug": "argos-a-1mb-rust-security-shim-for-model-context-protocol-servers", "title": "Argos –- A 1MB Rust Security Shim for Model Context Protocol Servers", "summary": "A developer released Argos, a ~1 MB single-binary Rust security shim that sits between AI clients such as Claude Desktop and Cursor and Model Context Protocol (MCP) tool servers, inspecting raw JSON-RPC traffic to block unauthorized file access, path traversal, and destructive commands. Argos enforces workspace boundaries via OS path canonicalization and '../' stripping, shields files including .env, id_rsa, id_ed25519, and cloud credentials, intercepts commands such as 'rm -rf', 'mkfs', and fork bombs, and writes blocked and allowed actions to a local JSON-lines log (argos-audit.log) with no cloud telemetry, configured through argos.toml. The project claims sub-millisecond overhead, with the inspection of tools/call shown at under 0.2ms, and ships pre-compiled binaries for Windows and Linux plus source builds via cargo build --release.", "body_md": "Zero-overhead policy enforcement gateway and runtime guardrail for Model Context Protocol (MCP) servers.\n\n`argos` acts as a transparent security pipe between AI clients (Claude Desktop, Cursor) and underlying MCP tool servers. Inspired by the zero-friction philosophy of Quad9/Pi-hole, it inspects raw JSON-RPC traffic on the fly and deterministically blocks unauthorized file access, path traversal attacks, and destructive commands before they reach your system.\n\n- **Sub-millisecond Overhead:** Built with pure Rust and Tokio asynchronous streams. Zero perceptible lag for the agent or developer.\n- **Path Traversal Sandboxing:** Enforces strict workspace boundaries via OS path canonicalization and`../` stripping.\n- **Secret & Sensitive File Shield:** Block access to`.env` , private keys (`id_rsa` ,`id_ed25519` ), and cloud credentials.\n- **Destructive Command Blocker:** Intercepts dangerous terminal commands (`rm -rf` , disk formatters, fork bombs).\n- **Local Audit Logging:** Records blocked and allowed actions into a structured, JSON-lines log (`argos-audit.log` ) without cloud telemetry.\n- **Flexible Configuration:** Declarative rule customization via`argos.toml` .\n- **Your Own Local & Private Tool** : Built entirely in Rust as a self-contained, ~1 MB single binary with zero external telemetry or cloud dependencies. Argos relies strictly on deterministic pattern matching, native OS primitives, and JSON-RPC stream interception—ensuring your sensitive code, configuration keys, and audit trails never leave your local machine.\n\nDownload the latest pre-compiled binary for your system from the [Releases](https://github.com/JUSICK/Argos-mcp-guardrail/releases) page:\n\n- **Windows** : Download`argos.exe` (or unpack`argos-windows-x86_64.zip` ).\n- **Linux** : Download and extract`argos-linux-x86_64.tar.gz` :\n\n```\ntar -xvf argos-linux-x86_64.tar.gz\nchmod +x argos\n```\n\nIf you are running **macOS** (Apple Silicon / Intel) or prefer compiling locally:\n\n```\ngit clone [https://github.com/JUSICK/Argos-mcp-guardrail.git](https://github.com/JUSICK/Argos-mcp-guardrail.git)\ncd Argos-mcp-guardrail\ncargo build --release\n```\n\nThe compiled binary will be located at:\n\n- Linux / macOS: target/release/argos\n- Windows: target/release/argos.exe\n\nCreate and place `argos.toml` next to the argos executable or in your workspace root:\n\n```\n[filesystem]\n# Enforce workspace boundary checks\nblock_path_traversal = true\n\n# Block access to sensitive files and credentials\nblocked_patterns = [\".env\", \".ssh\", \"id_rsa\", \"id_ed25519\", \"credentials\", \".aws\", \".npmrc\"]\n\n# Explicit exceptions allowed through the policy\nallowed_patterns = [\".env.example\", \".env.sample\", \".env.template\"]\n\n[commands]\n# Block destructive terminal commands\nblocked_commands = [\n  \"rm -rf\",\n  \"mkfs\",\n  \":(){ :|:& };:\",\n  \"chmod -R 777\",\n  \"dd if=\"\n]\n\n[audit]\nenabled = true\n# Allows to log ALLOWED processes\nlog_allowed = false\n# Just a file name to create one in the same directory where argos is, or full dir\nlog_file = \"argos-audit.log\"\n```\n\nUpdate your `claude_desktop_config.json`:\n\n```\n{\n  \"mcpServers\": {\n    \"Argos\": {\n      \"command\": \"C:\\\\path\\\\to\\\\argos.exe\",\n      \"args\": [\n        \"--\",\n        \"npx.cmd\",\n        \"-y\",\n        \"@modelcontextprotocol/server-filesystem\",\n        \"C:\\\\Users\\\\username\\\\projects\\\\my-workspace\"\n      ]\n    }\n  }\n}\n{\n  \"mcpServers\": {\n    \"Argos\": {\n      \"command\": \"/usr/local/bin/argos\",\n      \"args\": [\n        \"--\",\n        \"npx\",\n        \"-y\",\n        \"@modelcontextprotocol/server-filesystem\",\n        \"/Users/username/projects/my-workspace\"\n      ]\n    }\n  }\n}\n```\n\nRestart Claude Desktop, and Argos will actively guard your tool calls against unauthorized filesystem traversal and credential exposure.\n\n```\n[ AI Client (Claude / Cursor) ]\n              │\n              │ stdin / stdout (JSON-RPC)\n              ▼\n   ┌───────────────────────┐\n   │         argos         │  <── Inspects tools/call in <0.2ms\n   └───────────────────────┘\n         │           │\n   (If Allowed)  (If Blocked) ──> Returns JSON-RPC Error & logs event\n         │\n         ▼\n[ Real MCP Tool Server ]\n```\n\nYou are able to have as many Argos as you want, change their names e.g. \"Argos-Backend\", \"Argos-Frontend\" for a big project that has 2 or more AI agents.\n\nMIT License. Free for personal and commercial use.", "url": "https://wpnews.pro/news/argos-a-1mb-rust-security-shim-for-model-context-protocol-servers", "canonical_source": "https://github.com/JUSICK/Argos-mcp-guardrail", "published_at": "2026-10-07 13:04:17+00:00", "updated_at": "2026-10-07 13:20:38.221340+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-safety", "ai-tools", "developer-tools"], "entities": ["Argos", "Model Context Protocol", "Rust", "Claude Desktop", "Cursor", "Tokio", "JUSICK/Argos-mcp-guardrail"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/argos-a-1mb-rust-security-shim-for-model-context-protocol-servers", "markdown": "https://wpnews.pro/news/argos-a-1mb-rust-security-shim-for-model-context-protocol-servers.md", "text": "https://wpnews.pro/news/argos-a-1mb-rust-security-shim-for-model-context-protocol-servers.txt", "jsonld": "https://wpnews.pro/news/argos-a-1mb-rust-security-shim-for-model-context-protocol-servers.jsonld"}}