Argos –- A 1MB Rust Security Shim for Model Context Protocol Servers A developer released Argos, a ~1 MB single-binary Rust security shim that sits between AI clients such as Claude Desktop and Cursor and Model Context Protocol (MCP) tool servers, inspecting raw JSON-RPC traffic to block unauthorized file access, path traversal, and destructive commands. Argos enforces workspace boundaries via OS path canonicalization and '../' stripping, shields files including .env, id_rsa, id_ed25519, and cloud credentials, intercepts commands such as 'rm -rf', 'mkfs', and fork bombs, and writes blocked and allowed actions to a local JSON-lines log (argos-audit.log) with no cloud telemetry, configured through argos.toml. The project claims sub-millisecond overhead, with the inspection of tools/call shown at under 0.2ms, and ships pre-compiled binaries for Windows and Linux plus source builds via cargo build --release. Zero-overhead policy enforcement gateway and runtime guardrail for Model Context Protocol MCP servers. argos acts as a transparent security pipe between AI clients Claude Desktop, Cursor and underlying MCP tool servers. Inspired by the zero-friction philosophy of Quad9/Pi-hole, it inspects raw JSON-RPC traffic on the fly and deterministically blocks unauthorized file access, path traversal attacks, and destructive commands before they reach your system. - Sub-millisecond Overhead: Built with pure Rust and Tokio asynchronous streams. Zero perceptible lag for the agent or developer. - Path Traversal Sandboxing: Enforces strict workspace boundaries via OS path canonicalization and ../ stripping. - Secret & Sensitive File Shield: Block access to .env , private keys id rsa , id ed25519 , and cloud credentials. - Destructive Command Blocker: Intercepts dangerous terminal commands rm -rf , disk formatters, fork bombs . - Local Audit Logging: Records blocked and allowed actions into a structured, JSON-lines log argos-audit.log without cloud telemetry. - Flexible Configuration: Declarative rule customization via argos.toml . - Your Own Local & Private Tool : Built entirely in Rust as a self-contained, ~1 MB single binary with zero external telemetry or cloud dependencies. Argos relies strictly on deterministic pattern matching, native OS primitives, and JSON-RPC stream interception—ensuring your sensitive code, configuration keys, and audit trails never leave your local machine. Download the latest pre-compiled binary for your system from the Releases https://github.com/JUSICK/Argos-mcp-guardrail/releases page: - Windows : Download argos.exe or unpack argos-windows-x86 64.zip . - Linux : Download and extract argos-linux-x86 64.tar.gz : tar -xvf argos-linux-x86 64.tar.gz chmod +x argos If you are running macOS Apple Silicon / Intel or prefer compiling locally: git clone https://github.com/JUSICK/Argos-mcp-guardrail.git https://github.com/JUSICK/Argos-mcp-guardrail.git cd Argos-mcp-guardrail cargo build --release The compiled binary will be located at: - Linux / macOS: target/release/argos - Windows: target/release/argos.exe Create and place argos.toml next to the argos executable or in your workspace root: filesystem Enforce workspace boundary checks block path traversal = true Block access to sensitive files and credentials blocked patterns = ".env", ".ssh", "id rsa", "id ed25519", "credentials", ".aws", ".npmrc" Explicit exceptions allowed through the policy allowed patterns = ".env.example", ".env.sample", ".env.template" commands Block destructive terminal commands blocked commands = "rm -rf", "mkfs", ": { :|:& };:", "chmod -R 777", "dd if=" audit enabled = true Allows to log ALLOWED processes log allowed = false Just a file name to create one in the same directory where argos is, or full dir log file = "argos-audit.log" Update your claude desktop config.json : { "mcpServers": { "Argos": { "command": "C:\\path\\to\\argos.exe", "args": "--", "npx.cmd", "-y", "@modelcontextprotocol/server-filesystem", "C:\\Users\\username\\projects\\my-workspace" } } } { "mcpServers": { "Argos": { "command": "/usr/local/bin/argos", "args": "--", "npx", "-y", "@modelcontextprotocol/server-filesystem", "/Users/username/projects/my-workspace" } } } Restart Claude Desktop, and Argos will actively guard your tool calls against unauthorized filesystem traversal and credential exposure. AI Client Claude / Cursor │ │ stdin / stdout JSON-RPC ▼ ┌───────────────────────┐ │ argos │ <── Inspects tools/call in <0.2ms └───────────────────────┘ │ │ If Allowed If Blocked ── Returns JSON-RPC Error & logs event │ ▼ Real MCP Tool Server You are able to have as many Argos as you want, change their names e.g. "Argos-Backend", "Argos-Frontend" for a big project that has 2 or more AI agents. MIT License. Free for personal and commercial use.