Open-Source MCP Tool Safety Workbench
kr-jmlab · reddit · 2026-07-14
The author releases an open-source desktop tool Spring AI Playground for connecting, reviewing, grading, and intercepting MCP tools before agent invocation.
Core capabilities include:
- Connect and inspect any MCP server, scoring tools by L0-L5 risk levels based on transport, auth mode, directory trustworthiness, documentation completeness, etc.
- Human-in-the-loop approval: high-risk or destructive tool calls are paused and require explicit confirmation.
- Republish external tools as a proxy view with aliases, risk levels, approval flags, and key masking.
- Dynamic tool discovery: avoids loading all tool definitions into context at once, retrieves on demand via persistent index.
- All risk signals, injection attempts, approvals, and call logs go into a dashboard and timeline.
The author also maps these controls to OWASP MCP Top 10 and includes GitHub link and a 1-minute demo.
More from coding & agent
- Kimi K3 rises to No. 4 on the Agent Arena leaderboard — HeyZoyaKhan · 2026-07-22
- Claude adds screen-recorded skills that can replay your workflow — CodeByPoonam · 2026-07-22
- Devin adds e2b sandboxes for remote agent execution — badphilosopher · 2026-07-22
- Hermes Agent Refactoring Proposal: Decoupling via Event Bus and Monorepo Slicing — Promptmethus · 2026-07-22
- ty now reads Pydantic config keywords and field metadata — charliermarsh · 2026-07-22
- Pensar Launches AI Security Agent to Autonomously Discover and Patch 0-Days — andriy_mulyar · 2026-07-22