Open-source MCP server monitoring for Python apps

Pythonic Model Context Protocol servers handle tool calls, session events, module imports, and subprocess activity. BlueRock has released MCP Python Hooks, an open source runtime sensor that gives developers a way to capture those signals without modifying application code.

MCP server monitoring

What the sensor captures

The tool wraps a Python process at startup so its hooks initialize before application code executes. According to BlueRock CEO Harold Byun, this is achieved through Python-native mechanisms: audit hooks for security-sensitive operations, sys.meta_path import hooks for module visibility, and framework-specific hooks built on the wrapt library for MCP protocol activity. The wrapper avoids any SDK integration or code edits.

Once active, the sensor emits structured NDJSON events to a local spool directory at ~/.bluerock/event-spool/. Six MCP event types are supported in this release, covering server initialization, tool and resource registration, session creation and termination, client connections across stdio, HTTP, and SSE transports, and individual protocol messages. Each emitted event includes process ID, timestamps, and a per-process source event counter.

Import monitoring runs alongside the MCP hooks. Every loaded module produces a python_import event recording the module name, file path, package version where available, and a SHA-256 hash of the module file on disk. Coverage extends to direct dependencies and their transitive dependencies, which the project documents as a supply-chain visibility feature.

Mechanism and overhead

Byun said overhead depends on event volume and export configuration, and the capture layer is designed to be lightweight. Framework hooks load lazily through @wrapt.when_imported(), so libraries the application never imports incur no cost. A per-feature configuration gate adds a second layer of control, letting operators disable categories they do not need.

The sensor runs on Python 3.10 and later. Pre-built wheels target Linux on x86_64 and aarch64 and macOS on both Apple Silicon and Intel. The Rust-based event-writing backend ships as a separate package called bluerock-oss.

Boundaries of the open source release

“The OSS release is primarily focused on visibility: capturing structured MCP and Python runtime events so teams can understand what executed,” Byun said. “Operators can control which hook categories are enabled, which limits what is captured at the source. More granular redaction and filtering, such as per-tool or per-field handling, are not part of the initial OSS scope.”

He added that the same execution data forms the basis for real-time policy enforcement and guardrails in the paid platform.

Integration paths

Because events are written as NDJSON, downstream routing is left to the operator. The repository ships with a Grafana and Loki dashboard that runs locally through Docker Compose, and BlueRock points to OTLP forwarding for users feeding events into Datadog, Splunk, or other SIEM systems.

Jeremiah Lowin, CEO of Prefect and creator of FastMCP, said in a statement provided by BlueRock that teams have moved quickly to adopt MCP and agent-driven architectures, and that visibility into tool executions and runtime behavior has lagged that adoption. Byun said tool execution visibility for governing the agentic execution layer is becoming a requirement for teams operating MCP infrastructure in production.

BlueRock MCP Python Hooks is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!

Source link

Visited 1 times, 1 visit(s) today

Related Article

How Cinematic LUT Transforms Video on the Galaxy S26 Series – Samsung Global Newsroom

Beyond high resolution, video trends are shifting toward mood and emotional storytelling. Samsung Electronics debuted the Advanced Professional Video (APV) codec on Galaxy S26 Ultra, laying the groundwork for mobile video production while maintaining image quality and minimizing loss during editing. In response, Samsung asked a simple question — can anyone create Hollywood-style videos on

Zeekr Wants To Rival Porsche By Reviving FR Performance Brand

Autoblog and Yahoo may earn commission from links in this article. The FR Sub-Brand Zeekr, a brand under the Geely group, wants to take a stab at the performance EV market, aiming to challenge Porsche. The FR sub-brand is similar to BMW‘s M, Mercedes’ AMG, and Toyota‘s GR divisions. putting performance at the forefront of

Canadian Officials Claim OpenAI Violated Federal And Provincial Privacy Laws

Iryna Tolmachova/Shutterstock Philippe Dufresne, the Privacy Commissioner of Canada, has found OpenAI was “not compliant with” Canadian federal and provincial privacy laws in the training of its AI models. Following an investigation, Dufresne and his counterparts in Alberta, Quebec and British Columbia say OpenAI’s approach to things

Google UK employees in letter to the company: You have 10 working days to voluntarily recognise …

Google’s DeepMind employees are demanding union recognition amid concerns over their AI technology’s use by the US and Israeli militaries. Workers seek a commitment against developing AI weapons and surveillance tools, urging management to voluntarily recognize their unions or face legal action. The move highlights growing anxieties about AI’s ethical implications and its potential for

Disney+ to become ‘super app’ that goes beyond streaming service: report

A Bloomberg report last week claimed that Disney intends to make Disney+ into a “super app” that features much more than just a streaming service. And today on Disney’s earnings call, that direction was strongly signaled by company leadership. Disney signals plans for ‘super app’ in earnings call following Bloomberg report The idea of “super

iPhone Ultra Design Leak Reveals its Tablet Roots

We’re starting to build a clear picture of Apple’s first foldable phone, the iPhone Ultra, and it seems to represent a fundamentally different approach. Well known YouTuber Unboxed Therapy recently showcased an iPhone Ultra dummy unit, offering an early insight into the look and feel of Apple’s forthcoming foldable smartphone debut. For those who haven’t

Images, Not Chatbots, Drive Downloads for AI Apps

The still image is incredibly powerful; photographers know this better than anyone. And even in AI, it is the picture side of the product that is turbo-charging their gigantic businesses, according to a new report. Per Android Authority, the fastest growth for apps like ChatGPT and Google Gemini comes when there is an AI image

Why OpenAI, Amazon and Apple Want to Be Your Smartphone

On January 9, 2007, Steve Jobs stood on stage at Macworld and introduced three products. An iPod with a bigger screen and touch controls, a mobile phone, and something he described as a breakthrough internet communications device. He repeated the list three times so that all three product announcements could sink in. Then he revealed

Overseas Koreans can access public sites without Korean phones

A woman uses her smartphone. (123rf) South Koreans living overseas will be able to use local mobile numbers and electronic passports to verify their identities on Korean public websites, easing a long-running inconvenience for millions of nationals abroad. The Overseas Koreans Agency and the Ministry of the Interior and Safety said Wednesday they have improved

Gov. Kemp signs bill banning cell phones for Georgia high school students

The measure builds on a law passed last year that prohibited student access to personal electronic devices “bell to bell” in kindergarten through eighth grade. ATLANTA — Gov. Brian Kemp signed legislation on Tuesday expanding Georgia’s ban on cell phones in public schools — extending restrictions to include high school students. The measure, known as

Apple’s iPhone 17 Is the Best-Selling Phone for the First Quarter of 2026

Apple’s iPhone 17, 17 Pro and 17 Pro Max were the three highest-selling phones in the world for the first quarter of 2026, according to a list published Monday by analytics firm Counterpoint Research. The base model iPhone 17 accounted for 6% of global sales, but the top 10 list also includes five Samsung Galaxy A series

US Travelers Can Now Use T-Mobile’s Satellite Service in Canada and New Zealand

You wouldn’t think satellites zipping overhead would be bound by geographic boundaries, but T-Mobile subscribers have only been able to use the carrier’s T-Satellite service in the continental US, Puerto Rico, Hawaii and parts of Alaska. Now, customers traveling in Canada and New Zealand can connect to the satellite service when they are out of cellular

Book Publishers Accuse Meta And Mark Zuckerberg Of Copyright Infringement

Wally Skalij/Getty Images Meta’s AI endeavors have drawn another legal challenge. The social media company and its CEO Mark Zuckerberg are facing a class action lawsuit from five book publishers and one author on claims that it illegally used copyrighted works to train its Llama generative AI

Amazon just redesigned its Photos app for iPhone, here’s what’s new

Prime members have access to unlimited photo back, and Amazon just redesigned its Photos app for iPhone users. Amazon Photos app redesign highlights curated memories and more natural search Amazon highlights two key upgrades with its redesigned Photos app for iPhone. First, Amazon Photos now launches right into a curated carousel of memories and not

High Performance NdFeB Material Market Explodes with EV Demand |

High Performance NdFeB Material Market According to a newly published report by QY Research, the global High Performance NdFeB Material Market 2026 delivers a comprehensive and data-driven analysis designed to enhance business decision-making and unlock high-growth opportunities across industries. This study provides deep insights into market dynamics, competitive landscape, and future growth potential, helping organizations

0
Would love your thoughts, please comment.x
()
x