Skip to main content

Review Commands

mcpproxy review is the one CLI entry point for the review decisions that the Web UI Review queue and the macOS Review Queue also offer. It reads the same review payload as GET /api/v1/review and GET /api/v1/servers/{id}/review, and every decision goes through the scan gate: it never calls the legacy unquarantine endpoint.

For the concepts behind quarantine and the four review verbs see Security Quarantine. For scanner setup and scan reports see Security Scanner Commands.

Overview​

mcpproxy review
├── list Servers that need review
├── show <server> [--full] Captured tool definitions and scan verdicts
├── approve <server> [flags] Approve a server, or approve tools on a trusted server
└── reject <server> [flags] Keep a server quarantined, or block tools

All subcommands accept the global -o table|json|yaml flag. With -o json the output is the data object of the REST response.

review list​

mcpproxy review list
SERVER KIND QUARANTINED PENDING CHANGED TIERS SCAN
filesystem server_review true 0 0 map[destructive:1] map[verdict:clean]

review show​

mcpproxy review show filesystem --full
Server: filesystem
TOOL TIER APPROVAL SCAN DESCRIPTION
delete_0 destructive pending clean from the server, not verified:
Delete a file
This cannot be undone
Input schema:
{"type":"object"}

Descriptions and schemas come from the upstream server and are shown as plain text; they are not verified. Without --full only the first line of each description is shown and the schemas are left out.

review approve​

mcpproxy review approve <server> [--tools a,b] [--except a,b] [--force] [--yes]
FlagMeaning
--except a,bQuarantined server only: block these tools while approving the server
--tools a,bTrusted server only: approve only these pending or changed tools
--forceApprove although the scan verdict is dangerous (use only after reading the findings)
--yesSkip the confirmation prompt

The command picks the right endpoint for you:

Server stateEndpointNotes
QuarantinedPOST /api/v1/servers/{id}/security/approve--except becomes block; --force is sent as force
Trusted (not quarantined)POST /api/v1/servers/{id}/tools/approve--tools selects tools; without it every pending or changed tool is approved

Using the wrong flag for the state fails with exit code 1 instead of doing something else:

  • --tools on a quarantined server: --tools cannot select a quarantined server approval; use --except to block tools
  • --except on a trusted server: --except applies only while approving a quarantined server
mcpproxy review approve filesystem --except delete_0 --force --yes
Approved server filesystem
mcpproxy review approve trusted --tools write_0 --yes
Approved 1 tool for server trusted

review reject​

mcpproxy review reject <server> [--tools a,b] [--yes]

Without --tools the server stays quarantined (POST /api/v1/servers/{id}/security/reject). With --tools the listed pending or changed tools are blocked (POST /api/v1/servers/{id}/tools/block).

mcpproxy review reject filesystem --yes
Rejected server filesystem
mcpproxy review reject trusted --tools write_0 --yes
Blocked 1 tool for server trusted

Older commands​

These keep working and name the matching mcpproxy review command in their help:

CommandSame as
mcpproxy upstream approve <server> [tools...]mcpproxy review approve <server> --tools ... for a trusted server
mcpproxy tools approve <server:tool>...mcpproxy review approve <server> --tools ...
mcpproxy tools reject <server:tool>...mcpproxy review reject <server> --tools ...
mcpproxy security approve <server>mcpproxy review approve <server>
mcpproxy security reject <server>mcpproxy review reject <server>