Signet Eval MCP Server
Deterministic policy enforcement for AI agent tool calls. Every action an agent proposes passes through user-defined rules before execution. No LLM in the authorization path. Advisory nudges are separate from authorization. 25ms end-to-end.
People who need security tools inside Claude, Cursor, VS Code, or another MCP client. The project is written in Rust.
VERIFIED ACTIVE
LAST COMMIT 2026-08-01 · ★ 3 · #174 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25
MIT · Rust servers · how we verify → /methodology
01 · Evidence
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
license MIT - declared in the repository
registry namespace io.github.jmcentire is GitHub-verified and matches the repo owner
02 · What Signet Eval can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
Latest releases
v3.12.1 · 2026-08-01
Durable safety-default release. · Ships the GitHub remote-owner identity guard and embeds its check for atomic first-use installation. · Restores hard denial of ephemeral Task state in favor of Kindex tasks. · Requires…
v3.12.0 · 2026-06-13
Add Antigravity and OpenCode hook adapters, and change prefer_persistent_task_store default policy to Ask
v3.11.1 · 2026-05-29
Fixed · Scoped preflight state to real client chat/session identifiers before falling back to SIGNET_SESSION. · Hook evaluation now extracts session identifiers from client payloads for preflight, pause, and disable…
03 · Who maintains Signet Eval
signet-eval is maintained by jmcentire. We track 2 MCP servers from jmcentire - 2 actively maintained, 27 combined GitHub stars, oldest repo from Feb 2026. Full record: all servers from jmcentire.
04 · Facts
- repository
- github.com/jmcentire/signet-eval
- category
- security - ranked #174 of 182 actively-maintained security servers as of 2026-08-25.
- release cadence
- 3 releases in the last 90 days (latest 2026-08-01)
- registry
- io.github.jmcentire/signet-eval (active, first published 2026-05-16)
05 · Signet Eval FAQ
What is Signet Eval?
Deterministic policy enforcement for AI agent tool calls. Every action an agent proposes passes through user-defined rules before execution. No LLM in the authorization path. Advisory nudges are separate from authorization. 25ms end-to-end.
Is Signet Eval still maintained?
Yes - as of 2026-08-25, its last commit was 2026-08-01 and it shipped 3 releases in the last 90 days. We re-verify nightly.
06 · Alternatives to Signet Eval
Alternatives to Signet Eval
Maintained security servers if Signet Eval isn't the fit.
- SafeDep Vet MCP Protect your AI agents and IDEs from malicious open-source packages. ★ 1,102 · 2026-08-24
- SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants. ★ 632 · 2026-08-24
- Decionis MCP Server Fail-closed policy gate for AI agent actions, with local evaluation and native pre-tool hooks. ★ 533 · 2026-08-24
- HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server. ★ 470 · 2026-08-25
- Emisar Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step. ★ 409 · 2026-08-23
- Bradesco MCP server for Bradesco - Pix, Cobrança (boleto), Arrecadação, Extrato (OAuth2 + mTLS) ★ 269 · 2026-08-12
Pairs well with
Servers that cover what Signet Eval doesn't - only shown when the pairing reason fits the companion.
More security MCP servers · Shellward · Patch Tuesday · Web Metadata, OpenGraph & Contact Extractor · ServiceNow MCP Server · Observatory
More Rust MCP servers · Rustunnel · Audio Analyzer · Baton · Kitewright MCP Server · Kreuzcrawl · see all