pfSense MCP Server Ships 95 Read Tools and Zero Writes by Default
Temporary-Fun7726 · reddit · 2026-08-29
A developer built an MCP server for pfSense firewalls, raising a general question: if a backing API can mutate production infrastructure, should connecting it to MCP automatically expose those capabilities to an agent?
His answer: no. v1.0 exposes 95 READ tools + 2 guidance tools + 0 WRITE tools in the default profile—even when the underlying pfSense API identity has more privileges. He tested end-to-end with Codex CLI against a real pfSense lab: the agent used READ tools fine, and when explicitly asked to change settings, it refused because its MCP surface had no WRITE capability.
A separate protected WRITE architecture exists, intentionally distinct from the default MCP surface. The author asks MCP server authors: should servers expose everything the credential allows, or enforce a narrower capability boundary?
More from coding & agent
- AI agents spontaneously specialize into roles without communication in SwarmWorld — ProfBuehlerMIT · 2026-08-29
- LangChain creator retweets: The case for model-agnostic frameworks — hwchase17 · 2026-08-29
- Boost AI Agent Quality with Adversarial Review Mechanisms — brandon_galang · 2026-08-29
- Use scheduled tasks to reset Codex quota for uninterrupted coding — lxfater · 2026-08-29
- 28 prompts to take an idea from concept to production — Al_Grigor · 2026-08-29
- AdKit's Ads MCP has managed over $2M in Meta ad spend after its ad library crossed 100K ads — nico_jeannen · 2026-08-29