Co

Cordon – Security gateway for MCP tool calls with HITL approvals

Hacker News

Cordon – Security gateway for MCP tool calls with HITL approvals

MCP lets LLMs call real tools, databases, file systems, APIs. The spec has no security model. An agent is either off or full admin, and "trust the model" is the current answer. Cordon is an open source MCP gateway. It's a transparent proxy that sits between your LLM client and your MCP servers. Every tool call flows through it. You define policies per tool: allow, block, approve, read only, log only. The piece I haven't seen elsewhere is synchronous human-in-the-loop approvals. When a tool call hits an "approve" policy, the agent pauses and I get a terminal prompt (or a Slack Block Kit message) with the exact args. I approve or deny. The agent resumes. Every decision is logged. Install: `npx cordon-cli init` auto-patches your Claude Desktop config in about two minutes. Works with Claude Desktop, Claude Code, Cursor, Windsurf, and any stdio MCP client. Open source, MIT. Published to the official MCP registry as io.github.marras0914/cordon. There's also a hosted dashboard for centralized audit logs, but the gateway runs local and the CLI is fully offline. Happy to answer questions about the threat model, why I built it as a proxy vs. a client-side wrapper, or how write-detection works without me enumerating every dangerous tool name. GitHub: https://github.com/marras0914/cordon Writeup with config examples: https://dev.to/marras0914/mcp-has-no-security-model-heres-ho... Approval flow demo: https://i.imgur.com/nDAVxqN.gif

Share card

Actual performance

2points
1comments
Did not reach leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: agent, cursor, claude · Missing: mac, agents, macos
95%95% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersIH features products with proven revenue · Missing: supports, reddit linkedin, podcasting
45%45% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
TrustMRRLess likely to generate early MRR · Strong signals: way · Missing: mobile apps, ios, personal
42%42% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: host, calls · Missing: plus, platform, intuitive
34%34% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Hacker NewsMay not resonate with HN audience · Strong signals: open source, ide, io · Missing: https docs, excited, just released
32%32% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
Acquire.comPre-revenue stage for this audience · Strong signals: arr · Missing: mrr, revenue, profit
19%19% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
1%1% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

ThornGuard
ThornGuard47%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

MCP Security Gateway for AI Agents

Indie Hackers1ai
SolonGate
SolonGate36%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security Gateway for AI Agents

Indie Hackersai
Permit MCP Gateway
Permit MCP Gateway88%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Drop-in MCP Security Developers Love and CISOs Trust

Product Hunt+134Developer Tools
Ra
Rayrun – one MCP gateway for the whole company29%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Rayrun – one MCP gateway for the whole company

Hacker News2
Cencurity
Cencurity75%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security gateway for LLM agents

Product Hunt+83
Ve
VellaVeto — blocks unsafe MCP tool calls by default30%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

VellaVeto — blocks unsafe MCP tool calls by default

Hacker News2
Go
GoLrn – Your Gateway to Information Security Basics40%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

GoLrn – Your Gateway to Information Security Basics

Hacker News1
Bi
Biboumi – An XMPP-to-IRC gateway60%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Biboumi – An XMPP-to-IRC gateway

Hacker News76
Ko
Kong Gateway 3.038%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Kong Gateway 3.0

Hacker News1
AgentLock
AgentLock23%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Security gateway for AI agents with human approval

Indie Hackerscommitment-side-project