Home / MCP tooling

mcp-egress

Record every host an MCP server contacts, per tool, and fail CI on new ones.

Python · MIT · latest v0.1.0

What it is

Run a stdio MCP server behind a small recording proxy and get the exact set of hosts it contacts while you run initialize, tools/list and sample tool calls. Every host is attributed to the phase and the tool that reached it, written to egress.json, printed as a table, and printed again as two ready-to-paste blocks: Claude Code WebFetch(domain:host) permission rules and a sandbox allowed-domain list. Keep the file as a baseline and --check fails CI the day a tool starts talking to a host nobody declared.

Install

pipx install git+https://github.com/basitalisandhu/mcp-egress                       # isolated CLI install
uvx --from git+https://github.com/basitalisandhu/mcp-egress mcp-egress --help       # run without installing
pip install git+https://github.com/basitalisandhu/mcp-egress                        # into the current environment
git clone https://github.com/basitalisandhu/mcp-egress && cd mcp-egress && uv venv && uv pip install -e ".[dev]"   # development

From the README; see the full README for every option.

Releases

Topics: agent-security, ai-agents, allowlist, ci, claude-code, cli, devsecops, egress, hacktoberfest, llm-security, mcp, model-context-protocol, network-security, proxy, python, security-tools, supply-chain-security