Aperion Shield runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 18 Sep 2026.
Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
We read the source, 3 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
- "(?i)(\\bnc\\s+-(e|c|l)\\s|\\bncat\\s|\\bnetcat\\s|/dev/tcp/|\\bbash\\s+-i\\s+>&\\s*/dev/tcp|\\bmkfifo\\b.{0,40}\\bnc\\b|\\bsocat\\b.{0,40}(exec|pty|tcp)|\\brm\\s+/tmp/f\\s*;)"
"Bash/Write/Read on Cursor go through Shield even when findings is none. In Cursor, ask the agent to write a .env — High-severity paths prompt; Critical (rm -rf /) still denies.".into()
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
…s\\/credentials|~?\\/\\.config\\/gcloud|kubeconfig|\\.kube\\/config|~?\\/\\.netrc|~?\\/\\.docker\\/config\\.json|~?\\/\\.npmrc|~?\\/\\.pypirc)"
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Aperion Shield and you get told the day something new turns up.
Transparent audit proxy for MCP servers: logs every tool call, flags poisoning and rug pulls.
MCP policy proxy: spend caps, approvals for destructive tools, kill switch, dry-run, audit log.
MCP security guard + package manager: trust-scored installs, blocks prompt injection and rug-pulls.
Local-first TDLib Telegram MCP server with 110 tools, account isolation and production guardrails.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
MCP runtime security proxy. Blocks dangerous AI agent tool calls with a policy engine.
MCP security scanner: detect tool poisoning, prompt injection & rug-pulls - 10 OWASP heuristics.
Local MCP proxy for tool restrictions, response redaction, audit logs, and database schema context.
Answers built from our own checks of this server.