Dev puts policy enforcement in front of MCP tool calls, asks if wrong layer
Exotic-Border-5328 · reddit · 2026-10-02
A solo engineering student presents an MCP security gateway that sits between an agent and write-capable MCP servers. Before each tool call it evaluates a policy and returns allow, deny, or require-approval, with a shadow mode that only logs what would be blocked. Every decision is signed and timestamped for independent verification.
The design assumes policy enforcement belongs outside both the model and the MCP server so neither sets its own permissions—at the cost of an extra component in the execution path. He asks where developers enforce authorization today, whether they'd accept a gateway in that path, whether plain logs suffice, and whether they ever need to prove which policy was in force for a specific call. Limitations: only covers routed traffic, no customer deployments yet.
More from coding & agent
- Dev Makes Case for Local Checks Plus Remote Deploy Machine Over CI/CD — fforres · 2026-10-02
- Automating LichtFeld Studio Tooling with Claude or Codex via MCP — janusch_patas · 2026-10-02
- iroh-acp-go connects editors to remote AI agents peer-to-peer — no ports, no VPN — carsonfarmer · 2026-10-02
- Pedro Domingos: if you're using AI for software development, you're missing the point — pmddomingos · 2026-10-02
- Sentry open-sources toolkit, betting on a new standard for MCP and agent tooling — zeeg · 2026-10-02
- Researcher shows a free open-source slide tool that beats PowerPoint and dodges AI design clichés — Afinetheorem · 2026-10-02