GuardiAgent – Sandboxing / permission model for MCP servers
GuardiAgent – Sandboxing / permission model for MCP servers
Anthropic's Model Context Protocol (MCP) has made it easy to spin up servers that expose tools and data to LLMs. A lot of these MCP servers run locally because they need access to your files, shell, browser, etc. The problem: they typically run with the same privileges as your user. If a server is buggy, misconfigured, or prompt-injected, it can do anything you can do: read SSH keys, exfiltrate dotfiles, poke around in private repos, etc. Our research group is working on this by adding a security manifest (inspired by the Android app manifest) plus a local policy enforcement engine that sandbox MCP servers. You can specify which hosts they can reach, which files/directories they can read/write, and so on, instead of giving them full user-level access. Code and docs: https://github.com/orgs/GuardiAgent/repositories https://www.guardiagent.com Curious how others are locking down agents/tools today and what you'd want from a system like this.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Incorrect prediction on native model
Similar products
Representing Agents as MCP Servers
Chat with 1000s of MCP servers
MCP Servers, in one place
Mcploitable – Vulnerable MCP Servers for the OWASP Agentic Top
Fast MCP – A Ruby gem to create MCP servers
MCP Servers Directory
Directory of MCP servers
OAuth 2.0 framework for MCP servers
SpecToMCP – Generate MCP servers from API specifications
MCPJam - the first testing & evaluations platform for MCP servers