PIC: an open-source MCP guard that blocks high-impact agent calls lacking verifiable evidence
Creamy-And-Crowded · reddit · 2026-09-29
The author open-sourced PIC (Apache 2.0), a guard layer that checks high-impact tool calls before execution. The demo is a payment case:
Untrusted proposal → BLOCKED
"Trusted" + matching hash → BLOCKED
Verifiable signature → ALLOWED
The point: a caller-supplied "trusted" label and a matching hash prove which file was used, not that anyone authorized payment. PIC checks the proposed action, provenance and evidence against server policy at the tool boundary.
The repo ships the MCP guard, integration guide, spec, and conformance tests; run the demo with python -u examples/mcppicclientdemo.py. The author asks where this would be hard to adopt or how you'd try to break it for servers that move money, export data, or delete things.
More from coding & agent
- How a Telugu voice note becomes Hindsight agent memory — write-side design — Jeevana_Nanepalli · 2026-09-29
- Curia: open-source tool runs Claude Code agents as a rule-bound society of named seats — bobo-the-merciful · 2026-09-29
- 10 paper-trading agents show parallel calls can bypass spend limits — where should the hard cap live? — Accomplished_Fun_408 · 2026-09-29
- ROFT: fine-tuning only on self-explanations matches GRPO on SWE-bench without RL — iScienceLuvr · 2026-09-29
- Eric Elliott resurfaces Leanpub podcast on AI Driven Development, consciousness and economics — ericelliott_ · 2026-09-29
- Anthropic maps multiagent system risks; researcher likens it to sociology, not chemistry — mattturck · 2026-09-29