Storefront Guard MCP Server
by maxigirl123io.github.maxigirl123/storefront-guardv0.3.2
Verifies a merchant storefront is legitimate before an AI agent commits payment.
context tax
queued
security
queued
cold start
queued
freshness
Active19d ago
Install Storefront Guard MCP server
Install in Claude Code
claude mcp add storefront-guard -e GOOGLE_SAFE_BROWSING_API_KEY='<google-safe-browsing-api-key>' -e SAM_GOV_API_KEY='<sam-gov-api-key>' -e URLHAUS_AUTH_KEY='<urlhaus-auth-key>' -- npx -y storefront-guard-mcp-serverInstall in Cursor
{
"mcpServers": {
"storefront-guard": {
"command": "npx",
"args": [
"-y",
"storefront-guard-mcp-server"
],
"env": {
"GOOGLE_SAFE_BROWSING_API_KEY": "<google-safe-browsing-api-key>",
"SAM_GOV_API_KEY": "<sam-gov-api-key>",
"URLHAUS_AUTH_KEY": "<urlhaus-auth-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"storefront-guard": {
"command": "npx",
"args": [
"-y",
"storefront-guard-mcp-server"
],
"env": {
"GOOGLE_SAFE_BROWSING_API_KEY": "<google-safe-browsing-api-key>",
"SAM_GOV_API_KEY": "<sam-gov-api-key>",
"URLHAUS_AUTH_KEY": "<urlhaus-auth-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"storefront-guard": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"storefront-guard-mcp-server"
],
"env": {
"GOOGLE_SAFE_BROWSING_API_KEY": "<google-safe-browsing-api-key>",
"SAM_GOV_API_KEY": "<sam-gov-api-key>",
"URLHAUS_AUTH_KEY": "<urlhaus-auth-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"storefront-guard": {
"command": "npx",
"args": [
"-y",
"storefront-guard-mcp-server"
],
"env": {
"GOOGLE_SAFE_BROWSING_API_KEY": "<google-safe-browsing-api-key>",
"SAM_GOV_API_KEY": "<sam-gov-api-key>",
"URLHAUS_AUTH_KEY": "<urlhaus-auth-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| GOOGLE_SAFE_BROWSING_API_KEY | — | yes | Google Safe Browsing API key for scam domain checks. Optional — degrades gracefully if not set. |
| SAM_GOV_API_KEY | — | yes | SAM.gov API key for US federal exclusions check. Optional — skipped if not set. |
| URLHAUS_AUTH_KEY | — | yes | URLhaus Auth-Key for malware URL lookups. Optional — degrades gracefully if not set. |
Freshness
Active — last maintenance signal 19d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-21 · 19d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-08-31 · 40d ago · official registry · v0.3.2
FAQ
›How do I install the Storefront Guard MCP server in Claude Code?
Run: claude mcp add storefront-guard -e GOOGLE_SAFE_BROWSING_API_KEY='<google-safe-browsing-api-key>' -e SAM_GOV_API_KEY='<sam-gov-api-key>' -e URLHAUS_AUTH_KEY='<urlhaus-auth-key>' -- npx -y storefront-guard-mcp-server. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Storefront Guard require an API key?
Yes. It expects GOOGLE_SAFE_BROWSING_API_KEY, SAM_GOV_API_KEY, URLHAUS_AUTH_KEY, of which 3 are secrets.
›Can I use Storefront Guard as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Storefront Guard in the official MCP registry?
Yes, as io.github.maxigirl123/storefront-guard.