Mmcp.market

Bastion MCP server

by Gowthaman90·io.github.Gowthaman90/mcp-bastion·v0.6.1

Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.

A92/100grade A
What users say
No reviews yet
Be the first
Safety scan
A92/100

full report

Adoption
Growing

6 stars45 downloads/wk

Reviews

Write one

Nobody has reviewed Bastion yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Bastion tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it

no findings
  • Code scan6 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 1 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 92/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the Bastion repository's README, as published. We do not edit it. Read it on GitHub

🛡️ mcp-bastion

A reliability & security proxy for the Model Context Protocol (MCP).

Self-healing connections, runtime tool-security, and a compliance-mapped audit trail for your MCP servers.

-2ea44f>)

mcp-bastion sits between your MCP client (Claude Code, Cursor, Cline, Windsurf, Zed, Claude Desktop, or any MCP-compliant agent) and your MCP servers. It is client-agnostic — it works with any compliant client through configuration alone, with zero client-specific code — and non-invasive: your servers run unchanged, and removing Bastion is a one-line config revert.

📦 Package: mcp-bastion on npm · 🗂️ Official MCP Registry: io.github.Gowthaman90/mcp-bastion

🔒 Security, measured: on the open, vendor-neutral mcp-defense-bench, Bastion covers 63% of the MCP attack surface (15.0/24 vectors; 11 enforced) at zero false positives — the broadest of the proxies measured.

📖 Launch story: Medium · dev.to

👤 Created & maintained by Gowthaman Arumugam — Independent Researcher. Companion benchmark: mcp-defense-bench.

Contents

  • Why
  • How it works
  • Features
  • Quick start
  • Demo
  • Control tools
  • Configuration
  • Transports
  • Runtime security
  • Audit & compliance
  • Client setup
  • Architecture

Why

When an MCP server disconnects mid-session, the agent only sees a generic "No such tool available" error — indistinguishable from a tool that never existed — and it cannot reconnect; only a human can. Long agent sessions silently lose capabilities and fail in confusing ways.

Bastion closes that gap. It health-checks every server, auto-reconnects with backoff, and — crucially — exposes control tools so the agent itself can inspect connection health and recover a dropped server without human intervention.

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

Runs npx -y mcp-bastion on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp-bastion -- npx -y mcp-bastion
Add to Cursor

Bastion: common questions

Is Bastion MCP server safe?
Yes, by our scan: it is graded A (92/100). Read the Bastion safety report
How do I install Bastion?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Bastion need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Bastion maintained?
The last commit was in the last day (2026-09-24). The latest release is v0.6.1.
What can I use instead of Bastion?
Servers from other publishers that do the same job: MCPProxy MCP server, npm Registry MCP Server and prodlint MCP server. Compare all Bastion alternatives.

Alternatives to Bastion

Same job from other publishers: the closest match first, then the best rated.

All Bastion alternatives →
  • MCPProxy
    Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
    B
  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B
  • prodlint
    Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
    A
  • grim-mcp
    Security audit for AI agents: code, deps, exposure, secrets, drift, SBOM, and IoC.
    C
  • Guardvibe
    Deterministic security layer your AI can't be. 479 rules, 39 tools, CLI + doctor + host audit.
    C

More from Gowthaman90 →