LunarBLOCK
lunar.dev: Agent native MCP Gateway for governance and security
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Lunar.dev is an open-source platform for managing, governing and optimizing third-party API consumption across applications and AI agent workloads at scale.
Consumption Management for the AI Era
As AI agents and autonomous workflows increasingly rely on external APIs, there's a growing need for a mediation layer that acts as a central aggregation point between applications, agents, and the services they depend on.
Lunar.dev provides that layer—serving as a unified API Gateway for AI, delivering:
- Live API Traffic Visibility: Get real-time metrics on latency, errors, cost, and token usage across all outbound traffic, including LLM and agent calls.
- AI-Aware Policy Enforcement: Control tool access, throttle agent actions, and govern agentic traffic with fine-grained rules.
- Advanced Traffic Shaping: Apply rate limits, retries, priority queues, and circuit breakers to manage load and ensure reliability.
- Cost & Performance Optimization: Identify waste, smooth traffic peaks, and reduce overuse of costly APIs through smart gateway policies.
- Centralized MCP Aggregation: Streamline operations by consolidating multiple MCP servers into a single gateway, enhancing security, observabi
7950bc3c774aOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add testkit-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env MAX_RESPONSE_TOKENS=${MAX_RESPONSE_TOKENS} --env VITE_AUTH0_AUDIENCE=${VITE_AUTH0_AUDIENCE} -- npx -y @mcpx/[email protected]{
"mcpServers": {
"testkit-mcp-server": {
"command": "npx",
"args": [
"-y",
"@mcpx/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"MAX_RESPONSE_TOKENS": "${MAX_RESPONSE_TOKENS}",
"VITE_AUTH0_AUDIENCE": "${VITE_AUTH0_AUDIENCE}"
}
}
}
}Exposed tools (134)
116 read · 15 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Debugging | read | Trace issues across the stack. |
Legacy | read | Saved unavailable tools |
Operators | read | Operator access |
Readers | read | Read-only access |
add | write | |
another-skill | read | A group-less skill |
arg | read | an arg |
assignee | read | Assignee username or email |
audience | read | Target audience for the summary, such as reviewers or release managers. |
auth_linear | read | Authenticate with Linear |
automated-e2e-regression-suite-orchestration-flaky-quarantine | write | Run the full browser regression suite, retry flaky specs, and quarantine persistently failing tests. |
body | read | The issue body |
brand-voice-guidelines | read | Reference for tone, terminology, and formatting when drafting external copy. |
calculation_summary | read | Explain a calculation result with assumptions and a short confidence note |
channel | read | The Slack channel ID. |
channelId | read | The Slack channel that contains the thread. |
channels.list | read | List Slack channels in the workspace. |
chat.postMessage | write | Post a message to a Slack channel. |
codebase-onboarding-tour | read | Generate a guided, top-to-bottom tour of an unfamiliar repository for a brand-new engineer: start from the entry points and build and run scripts, map the high-level module boundaries and how a request flows from the edge through the service layer down to the data stores, call out the project |
commit-msg | write | Draft a commit message from the staged changes and commit |
create_issue | write | Create a GitHub issue |
create_repository | write | Create a repository |
custom_read_file | read | Custom read tool for TypeScript files only |
custom_repository_report | read | Generate a repository health report with customized defaults. |
custom_safe_read | read | Read a **file** safely |
cycle | read | Optional cycle name or number |
delete_file | destructive | Delete a file |
delete_repo | destructive | Delete a repository |
delete_repository | destructive | Delete an existing repository after validating ownership. |
description | read | Issue description |
diagnostic_summary | read | Draft a short diagnostic summary when an MCP server is unhealthy |
draft | read | draft |
draft-docs-answer | read | Draft an answer from docs. |
draft-me | read | A skill to draft on. |
draft-release-notes | read | Draft release notes from merged changes. |
echo | read | |
empty-body | write | Create a skill before writing instructions. |
encoding | read | File encoding |
error | read | The connection or health-check error |
evaluate | read | Evaluate a deterministic calculation |
existing | read | Existing desc |
explain-library-upgrade | read | Explain relevant upgrade notes from current docs. |
expression | read | The expression or formula that was evaluated |
full-stack-debugging-copilot | read | Trace an issue across the browser, API, database, and logs in one pass. |
get-library-docs | read | Fetch documentation for a Context7 library. |
get-user-data | read | |
getEnv | read | |
greet | read | says hi |
greet-canonicalized | read | says hi |
health_check | read | Check whether the remote server is healthy |
imported-skill | read | Imported description |
incident_channel_update | write | Compose a concise incident or rollout update for a Slack channel |
includeRiskAssessment | read | Include deployment, rollback, and compatibility risk notes. |
includeRisks | read | Whether to include risk notes |
internal_pr_template | read | Internal template for pull request updates |
issueId | read | Linear issue ID |
issue_template | write | Create a standard issue draft |
issue_triage_summary | read | Summarize open Linear issues |
labels | read | Comma-separated labels |
libraryId | read | The Context7 library ID. |
limit | read | Max results |
list_dir | read | List a directory |
list_issues | read | List issues in a repository |
list_projects | read | List active Linear projects for a team |
list_repos | read | List repositories |
masked_read | read | Masked read |
missing-skill | read | Updated description. |
missing_description | read | |
my-skill | read | Does a thing |
my-tool | read | Does something |
new | read | d |
owner | read | Repository owner |
path | read | File path |
ping | read | Ping the server to check connectivity. |
post_message | write | Post a message to a Slack channel |
powerOfTwo | read | |
prNumber | read | Pull request number |
priority | read | Issue priority |
projectName | read | Linear project name |
publish-me | write | A skill to publish. |
pullNumber | read | Pull request number whose diff and metadata should be analyzed. |
quarterly-board-deck-assembler | read | Compile metrics, narrative, and appendix slides into the standard board template. |
read_file | read | Reads the contents of a file from the filesystem |
readers | read | |
release-notes-generator | read | Summarize merged PRs since the last tag into grouped, human-readable release notes. |
release_notes | read | Prepare release notes |
release_prompt | read | Prepare release notes |
reload-tools | read | reloads tools |
repo | read | Target repository |
repo-review | read | Review repository changes |
request_authentication_link | read | auth |
resolve-library-id | read | Resolve a package name to a Context7 library ID. |
resource-only | read | Existing desc |
review-prs | read | Reviews pull requests and explains when changes need follow-up. |
review-pull-requests | read | Review repository changes with the local project rules. |
review-pull-requests-v2 | read | Updated description. |
reviewFocus | read | Area reviewers should focus on |
safe_read | read | Read a file safely |
search-docs | read | Search docs. |
search_messages | read | Search recent Slack messages |
search_repositories | read | Search repositories |
shared_name | read | Shared name tool |
simple_tool | read | A tool without parameters |
skill | read | desc |
sprint_planning_brief | read | Draft a sprint planning brief from Linear project and issue context |
stale_tool | read | |
status | read | Workflow status filter |
summarize | read | UPDATED |
summarize-thread | read | Summarize a Slack thread for handoff. |
summarize_prompt | read | Summarize recent file changes |
take_screenshot | read | Capture a browser screenshot |
teamKey | read | Linear team key |
temporary-skill | read | Temporary skill for route testing. |
temporary-skill-updated | read | Updated details without touching capabilities. |
test-tool | read | A test tool |
text | read | The message text. |
threadTs | read | The timestamp of the parent thread message. |
title | read | The issue title |
toggle_feature | read | Toggle a feature flag |
tool | read | |
tool1 | read | Test tool |
tool2 | read | Another tool |
tool3 | read | No params tool |
tool_a | read | A tool |
topic | read | topic |
triage | read | Triage issue |
update_issue_status | write | Move a Linear issue to another workflow status |
updated-skill | read | Updated description. |
valid-mock-skill | read | A valid mock skill. |
whoami | read | |
workspace_file_brief | read | Summarize important local files and suggest next files to inspect |
write-release-notes | write | Summarize merged changes. |
write_file | write | Write a file |
write_pull_request | write | Draft a pull request summary |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const raw = yaml.load(fs.readFileSync(file, 'utf8')) as any;
const { createConnection } = await (new Function('spec', 'return import(spec)')(ENV UI_URL=http://127.0.0.1:${UI_PORT}const DEFAULT_MCP_URL = 'http://127.0.0.1:9000/mcp';
const DEFAULT_URL = 'http://127.0.0.1:9000/mcp';
const DEFAULT_URL = 'http://127.0.0.1:9000/mcp';
API_KEY: "fixedEnforcedByCatalog",
API_KEY: "fixedEnforcedByCatalog",
delete_file, delete_repo, delete_repository
.dcignore
.prettierignore
.version
.eslintrc.js
.it.env
- ../../../testkit-mcp-server/dist:/app
- ../../../testkit-mcp-server/node_modules:/app/node_modules
import { DEFAULT_CONFIG } from "../../config.js";import { Config } from "../../model/config/config.js";import { ToolGroup } from "../../model/config/permissions.js";url: http://127.0.0.1:9000/mcp
aiohttp, aioconsole, lunar_interceptor
@anthropic-ai/sdk, @google/genai, @modelcontextprotocol/sdk, dotenv, winston, @types/node, ts-node, typescript
@modelcontextprotocol/sdk, @playwright/mcp, axios, @playwright/test, @types/dockerode, @types/jest, @types/js-yaml, @typescript-eslint/eslint-plugin
@eslint/js, concurrently, prompts, globals, typescript-eslint, typescript, eslint
@modelcontextprotocol/sdk, @opentelemetry/api, @opentelemetry/exporter-prometheus, @opentelemetry/sdk-metrics, @types/cors, @types/luxon, cors, dotenv
Gates applied: no_behavioural_pass.
7950bc3c774afull audit observations/trust-audit/mcp-server/thelunarcompany__lunar.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 7950bc3c774a | BLOCK | F | 59 | first audit |
Questions
What is the Lunar MCP server?
lunar.dev: Agent native MCP Gateway for governance and security
What tools does Lunar expose?
134 in total: 116 read-only, 15 that write, and 3 that can delete or overwrite (delete_file, delete_repo, delete_repository). Every one is listed on this page with its risk.
Is Lunar safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Lunar need?
It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, MAX_RESPONSE_TOKENS, VITE_AUTH0_AUDIENCE, VITE_AUTH0_CLIENT_ID, VITE_AUTH0_DOMAIN and VITE_AUTH_BFF_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lunar run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mcpx/testkit-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (7950bc3c774a), read on 2026-09-30. The repository is watched and re-audited when it changes.