Release Gate runs on your own machine — the client starts it, so there is no endpoint to ping. 253 installs a week from pypi. Last commit 6 Aug 2026.
Pre-deploy security auditor for AI agent code — the risks generic SAST misses.
We read the source, 18 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
proc = subprocess.run(
: vscode.Uri.file(path.join(baseUri?.fsPath ?? '', filePath)))
model’s output through <code>eval()</code>. Here is exactly what <b>release-gate</b>
env = dict(os.environ)
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add release-gate -- uvx release-gate
{
"mcpServers": {
"release-gate": {
"args": [
"release-gate"
],
"command": "uvx"
}
}
}
[mcp_servers.release-gate]
command = "uvx"
args = ["release-gate"]
{
"mcpServers": {
"release-gate": {
"args": [
"release-gate"
],
"command": "uvx"
}
}
}
{
"mcpServers": {
"release-gate": {
"args": [
"release-gate"
],
"command": "uvx"
}
}
}
This one needs environment variables set before it will start:
RG_MCP_ALLOWED_ROOTS (Colon/semicolon-separated directories the server may read under. Defaults to the working directory. The server refuses any path outside these roots (blocks ../, absolute, and symlink escapes).).
The author declared them in the registry entry; get the values from the project itself.
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Create and manage secure sandboxes for running AI agent code
Deterministic release gate for AI-written code and coding agents.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Enterprise certification for codebases with multi-agent security, reliability, and quality audits
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.
Answers built from our own checks of this server.