Pangea MCP proxy

by pangeacyber

Not rated
GitHub

About

Protect any MCP server from malicious entities and confidential PII using Pangea's AI Guard and Vault.

Details

Author
pangeacyber
Categories
Cloud Service, Infrastructure

Setup

Install Pangea MCP proxy in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/pangeacyber/pangea-mcp-proxy

Follow the installation instructions in the repository README, then restart your MCP client.

Protect any MCP server from malicious entities and confidential PII using Pangea's AI Guard and Vault.

Protect communications between a client and any MCP server. Now with 99% less prompt injection! The Pangea MCP proxy allows any MCP client to secure the messages it sends and receives to/from an MCP server, using thePangea AI Guardservice to guard tools' inputs and outputs.

What it does: protect users from common threat vectors by running all MCP I/O through Pangea AI Guard, which blocks:

- Prompt injections (yes, even the ones wrapped in a riddle)
- Malicious links, IPs, domains (via CrowdStrike, DomainTools, WhoisXML threat intel)
- 50 types of confidential information and PII
- 10 content filters, including toxicity, self harm, violence, and filtering by topic
- Support for 104 spoken languages

Bonus: It stores your AI Guard token safely in Pangea Vault, with automatic rotation.

Extra bonus: Each request to AI Guard and its detection results are logged to your Secure Audit Log, giving you an immutable trail of activity for audits, debugging, and incident response.

- Node.js v22.15.0 or greater.
- A Pangea API token with access to AI Guard. This token needs to be stored in Pangea Vault. See
Service Tokensfor documentation on how to create and manage Pangea API tokens.
- A Pangea API token with access to Vault. This will be used to fetch the above token at runtime.

In an existing stdio-based MCP server configuration like the following:

{ "mcpServers": { "qrcode": { "command": "npx", "args": ["-y", "@jwalsh/mcp-server-qrcode"] } } }

Wrap the original command withnpx -y @pangeacyber/mcp-proxyand add environment variables:

{ "mcpServers": { "qrcode": { "command": "npx", "args": [ "-y", "@pangeacyber/mcp-proxy", "--", "npx", "-y", "@jwalsh/mcp-server-qrcode" ], "env": { "PANGEA_VAULT_TOKEN": "pts_00000000000000000000000000000000", "PANGEA_VAULT_ITEM_ID": "pvi_00000000000000000000000000000000" } } } }

- Update thePANGEA_VAULT_TOKENvalue to the Pangea Vault API token.
- Update thePANGEA_VAULT_ITEM_IDvalue to the Vault item ID that contains the Pangea AI Guard API token.

For remote servers using HTTP or SSE, usemcp-remoteto turn them into stdio servers:

{ "mcpServers": { "proxied": { "command": "npx", "args": [ "-y", "@pangeacyber/mcp-proxy", "--", "npx", "-y", "mcp-remote", "https://remote.mcp.server/sse" ], "env": { "PANGEA_VAULT_TOKEN": "pts_00000000000000000000000000000000", "PANGEA_VAULT_ITEM_ID": "pvi_00000000000000000000000000000000" } } } }

To identify the calling app by ID in Pangea, set theAPP_IDenvironment variable.

To identify the calling app by name in Pangea, set theAPP_NAMEenvironment variable.

To use a Pangea base URL other than the defaulthttps://{SERVICE_NAME}.aws.us.pangea.cloud, set thePANGEA_BASE_URL_TEMPLATEenvironment variable to a custom template (e.g.https://{SERVICE_NAME}.dev.pangea.cloud).

Navigate your Aiven projects and interact with the PostgreSQL®, Apache Kafka®, ClickHouse® and OpenSearch® services

Yunxiao MCP Server provides AI assistants with the ability to interact with the Yunxiao platform.

Get prescriptive CDK advice, explain CDK Nag rules, check suppressions, generate Bedrock Agent schemas, and discover AWS Solutions Constructs patterns.

This AWS Labs Model Context Protocol (MCP) server for CloudTrail enables your AI agents to query AWS account activity for security investigations, compliance auditing, and operational troubleshooting.

Core AWS MCP server providing prompt understanding and server management capabilities.

Analyze CDK projects to identify AWS services used and get pricing information from AWS pricing webpages and API.

Query and analyze your Axiom logs, traces, and all other event data in natural language

Manage and interact with Microsoft Azure services.

Bastion: External Attack Surface Monitoring

Ask your AI assistant about your attack surface: run scans, catch expiring certificates and domains, triage findings, and generate reports.

Agent-ready global image CDN that AI agents can install and operate through MCP.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.