januscope

productivity MCP Server

Local-first MCP policy proxy. Tool-block, SQL-mutation gate, PII redact, audit, rate-limit, OpenTelemetry, vault secrets, first-use quarantine, schema pre-inject. No hosted gateway. One YAML Lens wraps any MCP, 20 included (Postgres, MySQL, MongoDB, GitHub, Stripe, Snowflake, etc.). 84% fewer tokens, ~3x faster, holds PII leaks. AGPL or commercial.

VerifiedFreshInstall Ready
productivityproductivitypostgresqlmysqlmongodb
10 views31 stars6 forksv0.5.0AGPL-3.0

Why This Matters

Discovered via github-topic:mcp-server and last synced 1d ago.

VerifiedFreshInstall Ready
Source
github-topic:mcp-server
Stars
31
Last synced
1d ago
Install
Instructions detected

Install

1. Install the package

npx januscope

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "januscope": {
      "command": "npx",
      "args": [
        "januscope"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

36
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (36)

7

1

Backend

Env-side requirements

tool

call outcome

JANUSCOPE_SESSION

`session` field

5

2

529

**−73%**

status

response

all

fields sqlGuard: tools: [<tool-name>] # which tool(s) carry a SQL argument sqlArg: <name> # default "sql" readOnly: <bool> # default true; rejects mutations in the SQL argument mode: allowlist

JANUSCOPE_USER

`user` field

Scenario

Median per cycle

Option

Problem

19

3

event

string

result_bytes

response, `ok` or `tool_error`

session

all records

Metric

Raw Postgres MCP

error

response, `error`

710

221

Field

When

args

call outcome

JANUSCOPE_TEAM

`team` field

Wall-clock

15.7 s

classification

all records

sort

uniq -c

0

15,994

1Password

`OP_SERVICE_ACCOUNT_TOKEN` in env. Peer dep: `npm install @1password/sdk`.

args_hash

call outcome

team

all records

Layer

What it does

ts

ISO-8601 string

id

call outcome

user

all records

stderr

stdout> # "~" is expanded. Parent directories # are auto-created. File opens with 0o600 # perms (user-only; matters for logRawArgs). logRawArgs: <bool> # default false; when false, args are SHA-256 hashed ``` Environment variables in string values are expanded with `${VAR}` or `$VAR`. Missing variables become empty strings and emit a one-line `[januscope] warn: env var 'FOO' is unset, substituted empty string` on stderr (once per name). We don't refuse to start, the user may be intentionally testing with undefined vars, but the warning is loud enough that a forgotten `$DATABASE_URL` at 2am shows up in the logs instead of silently breaking the lens. ### Credential-vault references (optional) Alongside plain `${VAR}` substitution, three URI-shaped references are resolved at startup from external secret stores:

duration_ms

correlated response

internal

sensitive # optional lens data-sensitivity label. # When set, `instructions` adds a short banner to # every tool description and `audit` tags every record # with `classification: "<value>"`. Purely informational; # enforcement still lives in `block` / `sqlGuard` / `redact`. firstRun: approve # optional; when set, the runtime fingerprints the lens # via TWO independent layers, both stored in # ~/.januscope/approved.json: # (1) Static lens fingerprint: block rules + sqlGuard # tools + rateLimit rules + redact rule shapes + # target command. Refuses startup on drift. # (2) Live tools/list fingerprint: every upstream tool's # name + description + inputSchema + annotations. # Re-checked on EVERY tools/list response (not just # the first), so a compromised upstream cannot pass # the initial check and then mutate the surface mid- # session via notifications/tools/list_changed. # Rewrites tools/list into a JSON-RPC error on drift. # Run `januscope approve --config <path>` to re-baseline # both layers atomically (probes the target, captures the # live tools, persists both fingerprints). Pass --no-probe # to skip the live capture and let it TOFU on next run. # Defends against tool-poisoning where a malicious MCP # quietly adds a tool, mutates a description (prompt- # injection vector), or changes a tool's input schema. block: # array of tool names or globs; "admin_*" supported - <name or glob> instructions: <string> # appended to every tool description dbSchema: driver: postgres

ddl

compact includeComments: <bool> # false omits table, view and column comments in Postgres/MySQL metadata refresh: startup