mcpbeat Sign in

Shadowgate MCP Server

answering

Shadowgate MCP is answering right now. Last checked 11 min ago. Last commit 13 May 2026.

Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.

Uptime history 48 days of history · worst day 99%
48 days agonow
100.0%
Uptime 24h
91 of 91 checks
Tools
hidden behind auth
333 ms
Response time
average over 24h
0
Stars
last commit 13 May 2026

What the code does

We read the source, 3 h ago · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

Touches key and credential files shadowgate/patterns.py:151
        re.compile(r"(?:~|\$HOME|/home/[^\s]+|/Users/[^\s]+)?/\.ssh/(?:id_rsa|id_ed25519|id_ecdsa|config)\b|\\.ssh\\(?:id_rsa|id_ed25519|id_ecdsa|config)\b", LINE_FLAGS),

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 11 min ago.

run in your terminal
claude mcp add shadowgate-mcp --transport http https://shadowgate-mcp.mcp.xpay.sh/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "shadowgate-mcp": {
      "url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.shadowgate-mcp]
url = "https://shadowgate-mcp.mcp.xpay.sh/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "shadowgate-mcp": {
      "url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "shadowgate-mcp": {
      "url": "https://shadowgate-mcp.mcp.xpay.sh/mcp"
    }
  }
}

This endpoint answered with an authorization challenge. The server is running, but it did not say what kind of credentials it expects.

Endpoints

URLTransportStateLatencyChecked
https://shadowgate-mcp.mcp.xpay.sh/mcp streamable-http needs auth 235 ms 11 min ago

Alternatives to Shadowgate MCP

same job, measured the same way
Shellward
by jnmetacode

AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.

235 installs/wk local only
AI Firewall MCP
by akhilucky

Multi-agent LLM security layer detecting prompt injection and jailbreaks.

89 installs/wk local only
TrustScan
by entradox

Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.

4 tools answering
Agent Security
by mdfifty50-boop

Security scanning and threat detection for AI agents

46 installs/wk local only
Securityscan
by securityscan-api

Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.

135 installs/wk local only
AIShield Security Scanner
by lm203688

Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

46 installs/wk 9 tools local only
Mund — MCP Security Scanner
by tyox-all

Scan for prompt injection, secrets, PII, and vet MCP servers before installation

48 installs/wk local only
Hares — MCP security scanner
by alialrikabi313

Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)

24 installs/wk local only

Shadowgate MCP — questions

Answers built from our own checks of this server.

Why is there no tool list for Shadowgate MCP?
The server answered our handshake with an authorization challenge, so it is running — but it will not describe its tools to an anonymous client. To see them you need to connect with your own credentials. We record it as alive, not as broken: 100.0% of checks in the last 24 hours got a reply.
Is Shadowgate MCP working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 333 ms. The bar chart above shows every period we have measured.
How do I connect Shadowgate MCP?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address. You will need your own credentials: it refuses anonymous clients.
Does Shadowgate MCP need an API key?
Yes. Every time we knock, Shadowgate MCP answers with an authorization challenge instead of its tool list — that is how we know it is running and gated rather than broken. Bring your own credentials and it will talk.
How fast is Shadowgate MCP?
It answers our handshake in 333 ms on average, which is faster than 46% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is Shadowgate MCP open source?
Yes — it is published under the MIT licence, written in Python and 0 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.