MCP Gateways Only Log What Flows Through Them; Agents Can Bypass Entirely

Exotic-Border-5328 · reddit · 2026-10-08

The poster highlights an agent security gap: MCP and gateway tools only trace calls routed through them, but nothing stops an agent from calling APIs directly (raw Stripe SDK, M365 Graph, background Zapier), which never appears in MCP traces.

He cites Air Canada's 2024 chatbot refund liability ruling, where the judge rejected "the agent acted on its own" as a defense; Zurich, Lloyd's, and AIG have since updated policies to exclude AI-caused losses unless the agent's authorized scope is documented.

A quick self-check: pull 30 days of Stripe Events and compare against MCP/gateway logs — a mismatch reveals out-of-boundary actions. He is building reconciliation directly from downstream systems of record, independent of the gateway.

Related event: AI agent auditing gaps: gateways miss direct API calls(2 posts)→

Original post →

More from coding & agent

coding & agent channel →