{"repo":"2alf/Heimdall","free":true,"listed":false,"github":"https://github.com/2alf/Heimdall","clone":"git clone https://github.com/2alf/Heimdall.git","description":"Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.","language":"Rust","stars":51,"topics":["mcp-security","security-scanner","ai-security","cybersecurity","llm-security","mcp-client","prompt-injection-defense","ai-agents","cursor","mcp"],"license":"GPL-3.0","category":"ai-agents","readme_excerpt":"Heimdall The watchman for your local AI agents' MCP layer. Heimdall fingerprints the MCP config and server files that Claude Desktop, Claude Code, Cursor, Windsurf, and LM Studio load, and sounds the alarm the instant one is altered behind your back. Named for the Norse watchman who guards the one bridge into Asgard and blows the horn when enemies approach — it guards your entry points , it watches and warns , and it doesn't pretend to be a wall. (Formerly Claude Defender, renamed once it grew past just Claude.) --- Contents - The threat: LOTL through MCP · How it works · A look inside - Why the baseline can't be forged · Supported MCP hosts · Features - Footprint · Benchmarks · Install · CLI - What it is — and isn't · Roadmap · Security & license --- The threat: LOTL through MCP Living-off-the-land attackers don't bring malware — they subvert the legitimate tools already on your machine. An MCP server is a perfect target: a trusted program your agent launches with full access. Poison its source, or slip a malicious server into a config an agent reads, and you have a trojanised entry point that runs every time — and nothing looks wrong . That's the point of LOTL. Heimdall's job is to notice: it fingerprints every config and server file, and the instant one changes it shows you exactly what changed and lets you revert. How it works Event-driven: it wakes only when a watched file changes, so at rest it does effectively no work, and detection is sub-second. A look inside Changes","default_branch":null,"files":null,"tree":[],"storefront":"/r/2alf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/2alf/Heimdall/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}