MCP Gateways Only Log What Flows Through Them; Agents Can Bypass Entirely
Exotic-Border-5328 · reddit · 2026-10-08
The poster highlights an agent security gap: MCP and gateway tools only trace calls routed through them, but nothing stops an agent from calling APIs directly (raw Stripe SDK, M365 Graph, background Zapier), which never appears in MCP traces.
He cites Air Canada's 2024 chatbot refund liability ruling, where the judge rejected "the agent acted on its own" as a defense; Zurich, Lloyd's, and AIG have since updated policies to exclude AI-caused losses unless the agent's authorized scope is documented.
A quick self-check: pull 30 days of Stripe Events and compare against MCP/gateway logs — a mismatch reveals out-of-boundary actions. He is building reconciliation directly from downstream systems of record, independent of the gateway.
Related event: AI agent auditing gaps: gateways miss direct API calls(2 posts)→
More from coding & agent
- One Prompt Chain Makes Claude Run a Full Product Launch: Positioning to 7-Day Content — thisguyknowsai · 2026-10-08
- 10 Legal Traps in Vibe-Coded Apps: 170 Lovable Builds Found Leaking Data — alex_verem · 2026-10-08
- Microsoft extends GitHub Spec Kit: presets, extensions and bundles for enterprise SDD — WirelessLife · 2026-10-08
- After an agent leaked salary data, Reddit distilled a 5-step pre-launch access checklist — Wild-Lawyer8511 · 2026-10-08
- Codex reproduces the MCP failure and locates VS Code's hidden MCP logs — dfinke · 2026-10-08
- Codex writes mcp., starts the server and verifies the connection autonomously — dfinke · 2026-10-08