SEOSiri API Guard MCP Server
Officialseosiri-api-guard-mcp-server
An open-source, stateless, and high-performance Model Context Protocol (MCP) framework designed to validate, sanitize, and authorize LLM-generated API payloads.
💖 Sponsorship & Attribution
This project is developed and maintained by SEOSiri-Official (Official website: seosiri.com). To fund ongoing safety research or scale advanced compliance modules, consider supporting the team via the SEOSiri Sponsors Page.
Related MCP server: fallpharm-mcp
Decoupled Compliance Profiles
Universal Core: OWASP injection scanning (SQLi, Command Injection) and credential redaction.
Fintech (PCI-DSS): Real-time credit card (PAN) detection using the Luhn algorithm.
Healthcare (HIPAA/FHIR): Automatic scrubbing of PII/PHI (Social Security Numbers, Dates of Birth).
SEO & Digital Marketing (GDPR/AEO): IP logging redaction and validation of programmatic SEO metadata boundaries (canonical URL structures, title, and description lengths) to protect search index health.
Biorobotics Safety Interlock: Scans mechanical G-code commands generated by actuators against physical deck limits and safe velocity envelopes, issuing dynamic remediation recommendations.
Quickstart
Install Package in Editable Mode:
pip install -e .
Available Tools
1 toolsanitize_and_validate_payloadC
Main Security Gatekeeper: Processes proposed payloads against universal OWASP rules and activates industry-specific compliance profiles (hipaa, pci, seo, biorobotics) dynamically.
| Name | Required | Description | Default |
|---|---|---|---|
| proposed_payload | Yes | ||
| active_profiles_csv | No | universal |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided, so description must carry behavioral burden. It mentions dynamic activation of profiles but does not explain failure outcomes (e.g., rejection vs sanitization) or side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with main purpose. Efficient but could be slightly more concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given lack of annotations and poor parameter descriptions, the description leaves gaps in understanding validation behavior and input formats, despite an existing output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has 0% description coverage. The description references 'proposed payload' and examples of profiles but does not clarify format (e.g., string encoding) or valid values for 'active_profiles_csv'.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('processes', 'activates') and resource ('payloads', 'compliance profiles'), and specifies the security gatekeeper role. No sibling tools to differentiate from.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Implies use when needing security validation (OWASP rules) and compliance. No explicit when-not to use or alternative tools mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v0.1.0- First observed
sanitize_and_validate_payload
TDQS
Only one tool exists, so there is no possibility of confusion with other tools. The tool's purpose is clear and distinct.
The single tool uses a clear verb_noun pattern (sanitize_and_validate_payload) in snake_case, which is consistent and descriptive.
A single tool is well-scoped for a dedicated security guard server focused on payload sanitization and validation, with no unnecessary bloat.
The tool covers the full scope of the server's purpose: both sanitization and validation with dynamic profile activation, with no obvious gaps.
Maintenance
Related MCP Connectors
AI governance MCP server for EU AI Act compliance and jurisdiction verification
Hosted MCP server for real-world data: business registries, sanctions, companies, domains, crypto.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Guarded MCP server for agent-readable business truth, provenance, readiness, and discovery.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceMCP server for sovereign US legal workflows, providing Ed25519-signed manifests and offline-capable access via your own infrastructure.MIT
- AlicenseNot gradedqualityCmaintenanceProvides a sovereign, MIT-licensed MCP server for professional-service workflows, running entirely on your infrastructure with Ed25519 cryptographic signing for every action.MIT
- AlicenseNot gradedqualityCmaintenanceA sovereign, MIT-licensed MCP server for professional-service workflow automation, enabling offline-capable, cryptographically signed operations without vendor lock-in.MIT
- FlicenseNot gradedqualityBmaintenanceA governed MCP server with OAuth 2.1 + PKCE, declarative tool scoping, row-level data filters, per-identity rate limits, and a tamper-evident audit trail.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/SEOSiri-Official/seosiri-api-guard-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server