01Policy-based access control using glob patterns for argument validation
02Supports stdio, HTTP (JSON-RPC 2.0 with Bearer token auth), and bridge operating modes
03Optional SQLite-based audit logging for all tool calls and MCP Apps UI support
040 GitHub stars
05Flexible JSON-based plugin configuration for defining tools and allowed environments
06Secure command execution with multiple sandboxing modes (none, bubblewrap, WASM)