Browse
→ Infrastructure
→ Promptfoo MCP Proxy
Promptfoo MCP Proxy
Open-source MCP proxy from Promptfoo that sits between AI applications and MCP servers to provide enterprise-grade security, monitoring and access control. Whitelists approved MCP servers, grants granular permissions and monitors for PII and sensitive data exposure. Provides detailed logging and real-time alerts for unauthorized access attempts and policy violations. Includes red-teaming capabilities for testing MCP server security with an evil MCP server for adversarial testing. Part of the Promptfoo open-source LLM evaluation and red-teaming platform with over 22,000 GitHub stars. Demonstrated live at Black Hat USA 2026 at the OpenAI booth. Available on GitHub.
MCP unverified
Integration
| Transport | http |
| Auth | none |
| Endpoint | https://www.promptfoo.dev/mcp/ |
| Install | npx promptfoo@latest mcp-proxy |
Use Cases
| 01 | Deploy Promptfoo MCP Proxy between AI assistants and MCP servers to whitelist approved servers, enforce granular tool permissions and monitor all MCP communications for sensitive data exposure |
| 02 | Red-team MCP server deployments using Promptfoo adversarial testing tools including the evil MCP server to identify prompt injection vulnerabilities, data exfiltration risks and unauthorized access paths |
| 03 | Add enterprise security controls to existing MCP server infrastructure by routing traffic through the Promptfoo proxy for real-time PII detection, access logging and policy enforcement without modifying server code |
Tags
security proxy red-team mcp-gateway access-control monitoring pii-detection open-source
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>