VellaVeto — blocks unsafe MCP tool calls by default
VellaVeto — blocks unsafe MCP tool calls by default
Reposting because the March thread linked a now-outdated repo, and the project has changed substantially. VellaVeto is a fail-closed gateway between an AI agent and its MCP tools. Every tool call is evaluated before execution; if evaluation fails for any reason, the call is denied. Concrete example: under shield mode, a filesystem server trying to read ~/.ssh/id_rsa is denied by default. A list_files /tmp call from the same server is allowed. What it does not solve: prompt injection, model-level jailbreaks, or supply-chain attacks in server packages. It only controls what crosses the tool-call boundary. Since March, I added three zero-config protection levels, topology discovery, tamper-evident audit, Consumer Shield, and MCPSEC, an open benchmark for MCP gateways. The feedback I’d most like: Is the tool-call boundary the right place to enforce MCP security? Are the MCPSEC attack classes sensible? What important attack classes am I still missing?
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Cordon – Security gateway for MCP tool calls with HITL approvals
VimFreeDrag – Move Blocks of Text in Vim
Authorize MCP tool calls without giving agents the credentials
Authorize MCP tool calls without giving agents the credentials
mcp-chat, chat server using MCP tool calls
DayBrix, a daily falling-blocks webgame
Qi Blocks – collection of 48 free blocks for Gutenberg
Hijax: Intercept Ajax Calls
How to overcome your creative blocks
1Baton – a no-code tool for chaining API calls