Agent skill

Protect MCP Setup

by wshobson in wshobson/agents

Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.

MITAuto-check passedAgent Workflows

Install Protect MCP Setup

skills CLI
$ npx skills add wshobson/agents --skill protect-mcp-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents protect-mcp-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/protect-mcp/skills/protect-mcp-setup .claude/skills/protect-mcp-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
protect-mcp-setup
GitHub stars
40k
Token cost
~2.1k tokens
SKILL.md length
579 words
Files
2 (incl. references)
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.

  • Setting up projects that need cryptographic audit trails
  • SKILL.md covers Overview, Problem, Solution and Hook Configuration, plus 6 more sections
  • Calls npx, claude and node; needs PROTECT_MCP_KEY
  • Policy-gated tool execution

What it does

Protect MCP Setup is an agent skill from wshobson/agents. Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool execution, or compliance-ready evidence of agent actions.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/receipt-format.md`).

It sits in Agent Workflows, covering Cryptography and MCP servers. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.

When your agent uses it

  • Setting up projects that need cryptographic audit trails
  • Policy-gated tool execution
  • Compliance-ready evidence of agent actions

Example prompts

  • “/protect-mcp-setup”

Requirements

  • Node.js
  • A credential in PROTECT_MCP_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • claude
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • npmjs.com
    • datatracker.ietf.org
    • github.com
    • veritasacta.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PROTECT_MCP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Protect MCP Setup loads about 2.1k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 579 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 579 words, ~2,107 tokens.

Download SKILL.mdSave it as .claude/skills/protect-mcp-setup/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
protect-mcp-setup
description
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool execution, or compliance-ready evidence of agent actions.

protect-mcp — Policy Enforcement + Signed Receipts

Cryptographic governance for every Claude Code tool call. Each invocation is evaluated against a Cedar policy and produces an Ed25519-signed receipt that anyone can verify offline.

Overview

Claude Code runs powerful tools: Bash, Edit, Write, WebFetch. By default there is no audit trail, no policy enforcement, and no way to prove what was decided after the fact. protect-mcp closes all three gaps:

  • Cedar policies (AWS's open authorization engine) evaluate every tool call before execution. Cedar deny is authoritative.
  • Ed25519 receipts record the name of each tool that ran, signed with your key.
  • Offline verification via npx @veritasacta/verify. No server, no account, no trust in the operator.

Problem

AI agents make decisions that affect money, safety, and rights. The Claude Code session log records what happened, but the log is:

  • Mutable — anyone with access can edit it
  • Unsigned — there is no way to prove integrity
  • Operator-bound — verification requires trusting whoever holds the log

For compliance contexts (finance, healthcare, regulated research), this is not sufficient. You need tamper-evident evidence that can be verified by third parties without trusting you.

Solution

Add protect-mcp to your Claude Code project:

bash
# 1. Install the plugin (adds hooks + skill to your project)
claude plugin install wshobson/agents/protect-mcp

# 2. Create ./protect.cedar (see below). The plugin installs the hooks.

# 3. Create the signing key once (protect-mcp 0.7.4 sign does not create it).
#    An existing key is never replaced. See references/receipt-format.md to rotate.
if [ ! -e ./protect-mcp.key ]; then
  d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./protect-mcp.key
fi
echo "/protect-mcp.key" >> .gitignore

# 4. Use Claude Code normally. Every tool call is now policy-evaluated
#    and produces a signed receipt in ./receipts/

Hook Configuration

Installing the plugin adds both hooks from hooks/hooks.json. Each hook runs a script bundled with the plugin:

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": ".*",
        "hooks": [
          { "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }
        ]
      }
    ],
    "PostToolUse": [
      {
        "matcher": ".*",
        "hooks": [
          { "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/sign.sh" }
        ]
      }
    ]
  }
}

Claude Code passes the hook event to the command as JSON on stdin and does not set TOOL_NAME or TOOL_INPUT variables. evaluate.sh reads tool_name and tool_input from that payload and passes them to protect-mcp as flags; sign.sh reads tool_name only, because the 0.7.4 signer records nothing else. Set PROTECT_MCP_POLICY, PROTECT_MCP_RECEIPTS, and PROTECT_MCP_KEY to change the default paths. When the policy file is missing, the PreToolUse hook prints a warning to stderr and allows the call.

What each hook does

PreToolUse — Runs BEFORE the tool executes. Evaluates the tool call against your Cedar policy file. If Cedar returns deny, the hook exits with code 2 and Claude Code blocks the tool call entirely.

PostToolUse runs AFTER the tool completes. It signs a receipt that names the tool and appends it to ./receipts/receipts.jsonl. protect-mcp 0.7.4 does not record the tool input or output.

Show full SKILL.md (229 more words)Show less

Cedar Policy File

Create ./protect.cedar at the project root:

cedar
// Read-only tools: one rule can name several tools in `when`. Add WebFetch
// with your own URL rule.
permit (principal, action == Action::"MCP::Tool::call", resource) when {
    resource == Tool::"Read" || resource == Tool::"Glob" || resource == Tool::"Grep"
};

// Safe commands only; git limited to read subcommands
permit (principal, action == Action::"MCP::Tool::call", resource == Tool::"Bash") when {
    context has input && context.input has command &&
    (context.input.command like "git status*" || context.input.command like "git diff*" ||
     context.input.command like "git log*" || context.input.command like "git show*" ||
     context.input.command like "npm*" || context.input.command like "ls*" ||
     context.input.command like "cat*" || context.input.command like "echo*" ||
     context.input.command like "pwd*" || context.input.command like "test*")
};

// No chaining (`&` also denies `2>&1`), `$` expansion, redirection (`>` or
// `<`, which covers `<(`), file output (`git diff --output`), or rm -rf
forbid (principal, action == Action::"MCP::Tool::call", resource == Tool::"Bash") when {
    context has input && context.input has command &&
    (context.input.command like "*;*" || context.input.command like "*&*" ||
     context.input.command like "*|*" || context.input.command like "*$*" ||
     context.input.command like "*`*" || context.input.command like "*>*" ||
     context.input.command like "*<*" || context.input.command like "*\n*" ||
     context.input.command like "*--output*" || context.input.command like "*rm -rf*")
};

// Writes only inside the project (paths are absolute), never via `..`
permit (principal, action == Action::"MCP::Tool::call", resource) when {
    (resource == Tool::"Write" || resource == Tool::"Edit") &&
    context has input && context.input has file_path &&
    context.input.file_path like "/path/to/project/*"
};
forbid (principal, action == Action::"MCP::Tool::call", resource) when {
    (resource == Tool::"Write" || resource == Tool::"Edit") &&
    context has input && context.input has file_path &&
    (context.input.file_path like "*/../*" || context.input.file_path like "*/..")
};

String matching is best-effort: like checks the raw string, not a resolved path, and an npm* permit runs arbitrary code, so it is only as safe as the project's scripts.

Verification

Verify every receipt against the public key in ./protect-mcp.key:

bash
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./protect-mcp.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"
# Exit 0 = every receipt verified
# Exit 1 = a receipt failed (tampered, wrong key, or malformed line)
# Exit 2 = the file could not be read

The plugin's slash commands do the same inside Claude Code. /verify-receipt takes one receipt in its own file, e.g., from tail -n 1 ./receipts/receipts.jsonl > receipt.json.

/verify-receipt receipt.json
/audit-chain --last 20

Receipt Format

Each receipt is one line of ./receipts/receipts.jsonl. See references/receipt-format.md for a sample.

  • Ed25519 signatures (RFC 8032) over all fields but signature
  • JCS canonicalization (RFC 8785) before signing
  • No public key in the receipt, so pass it with --key
  • No link to the previous receipt, so a deleted line goes undetected

Why This Matters

BeforeAfter
"Trust me, the agent only read files"Cryptographically provable: every Read logged and signed
"The log shows it happened"The receipt proves it happened, and no one can edit it
"You'd have to audit our system"Anyone can verify every receipt offline
"Logs might be different by now"Ed25519 signatures lock the record at signing time

Standards

  • Ed25519 — RFC 8032 (digital signatures)
  • JCS — RFC 8785 (deterministic JSON canonicalization)
  • Cedar — AWS's open authorization policy language
  • IETF draft — draft-farley-acta-signed-receipts

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/protect-mcp/skills/protect-mcp-setup of wshobson/agents.

  • SKILL.md
  • references/receipt-format.md

Open the folder on GitHubat commit 46891e7

Compare with similar skills

Protect MCP Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Protect MCP Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Protect MCP Setup this skillwshobson/agents40k—~2.1kAutomated safety check: PassMIT
Webcrypt MCPputervision/state-memory-mcp50—~847Automated safety check: PassMIT
X Use Setupihuzaifashoukat/x-use171—~1.3kAutomated safety check: PassMIT
Bind MCPLeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassMIT
Agentic Tool Integrationsamugit83/redamon3k—~1.3kAutomated safety check: PassMIT
Sap Dependency Securitysecondsky/sap-skills462—~5.9kAutomated safety check: WarnGPL-3.0

Similar skills

  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    50 GitHub stars~847 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • X Use Setup

    ihuzaifashoukat/x-use

    Zero-knowledge onboarding for x-use that verifies the install, registers the MCP server, then interviews the user to configure their first X account (cookies, niche, keywords, persona).

    171 GitHub stars~1.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Bind MCP

    LeoYeAI/openclaw-master-skills

    Bind Protocol MCP server for credential verification, policy authoring, and zero-knowledge proof generation.

    2.2k GitHub stars~4.5k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    3k GitHub stars~1.3k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Sap Dependency Security

    secondsky/sap-skills

    SAP dependency security and MCP executable trust policy with secure upgrades, cooldowns, staged rollout, and supply-chain protection.

    462 GitHub stars~5.9k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check: warnings
  • Security Scan

    affaan-m/ECC

    Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.

    276k GitHub starsUsed in 5 repos~1.1k tokens
    Agent WorkflowsAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 5 days ago
    Auto-check passed

Questions about Protect MCP Setup

What does Protect MCP Setup do?

Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Protect MCP Setup is an agent skill from wshobson/agents. Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls.

When should I use Protect MCP Setup?

Protect MCP Setup fits situations like: setting up projects that need cryptographic audit trails; policy-gated tool execution; compliance-ready evidence of agent actions.

How do I install Protect MCP Setup in Claude Code?

Run `npx skills add wshobson/agents --skill protect-mcp-setup -a claude-code`. Or copy the skill folder (plugins/protect-mcp/skills/protect-mcp-setup in wshobson/agents) into .claude/skills/protect-mcp-setup in your project. Claude Code loads it when a task matches its description.

How do I install Protect MCP Setup in Codex?

Run `npx skills add wshobson/agents --skill protect-mcp-setup -a codex`. Or copy the skill folder (plugins/protect-mcp/skills/protect-mcp-setup in wshobson/agents) into .agents/skills/protect-mcp-setup in your project. Codex loads it when a task matches its description.

Can I use Protect MCP Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill protect-mcp-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protect-mcp-setup, .gemini/skills/protect-mcp-setup, .github/skills/protect-mcp-setup and .opencode/skills/protect-mcp-setup in your project.

What does Protect MCP Setup need to run?

Going by SKILL.md and its folder, Protect MCP Setup needs the command-line tools its instructions call (npx, claude and node) and credentials named PROTECT_MCP_KEY. Our summary lists: Node.js; A credential in PROTECT_MCP_KEY.

Does Protect MCP Setup access the network?

SKILL.md names 4 domains. As links in the text: npmjs.com, datatracker.ietf.org, github.com and veritasacta.com. This is read from the text; nothing was executed.

Is Protect MCP Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Protect MCP Setup use?

Protect MCP Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Protect MCP Setup use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 415 tokens, read only when the agent opens those files.

What are the alternatives to Protect MCP Setup?

Skills that share tags, products or a category with Protect MCP Setup: Webcrypt MCP (putervision/state-memory-mcp, 50 stars), X Use Setup (ihuzaifashoukat/x-use, 171 stars), Bind MCP (LeoYeAI/openclaw-master-skills, 2.2k stars) and Agentic Tool Integration (samugit83/redamon, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Protect MCP Setup?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.