Private trialLocal-firstMCP first

Gate0x The action-control layer for AI agents.

See what your agents can do. Control what they are allowed to do.

The three decisions

ALLOW

Decision
ALLOW
Tool
github.read_issue
Reason
Read-only action allowed.

Forwarded to the tool.

APPROVAL REQUIRED

Decision
REQUIRE_APPROVAL
Tool
database.delete_customer
Reason
Deleting customer data requires approval.

Approve once A Deny D

BLOCK

Decision
BLOCK
Tool
shell.execute
Reason
Command prohibited by policy.

Refused. Never reaches the tool.

Illustration of the three decisions Gate0x returns. Tool names are examples and this is not a live demo.

The problem

Agents do not just answer anymore. They act.

  • send email
  • delete data
  • deploy code
  • make payments
  • publish content
  • change permissions

Once an agent can call tools, the risk is not only what it says. It is what it does. Today the decision to run a tool is often left to the model itself, or to a prompt people learn to click through.

The control point

Put one decision before every action.

AI Agent proposes an action
Gate0x evaluates it against policy
ALLOW BLOCK APPROVAL
Tool runs only if allowed or approved

Gate0x evaluates the proposed action before execution, using deterministic policy. The same call and the same policy always give the same decision, and normal decisions do not require an LLM. Today that point is local MCP tool calls; MCP is the first adapter.

Gate0x Scan

See what your agents can already do.

Scan finds the MCP servers configured on your machine, and the tool permissions they quietly grant your agents. Discovery is local and needs no account.

  • Risky capabilities: shell, payments, deletes, credentials, deploys.
  • Plaintext secrets in config files, reported by name and never printed.
  • Unpinned packages, broad file access and plain-HTTP servers.
  • Unprotected servers: which ones are not behind Gate0x.

It does not start any server and does not upload your configuration. It looks in the default config locations of Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Gemini CLI and Zed. Those locations are not yet verified against every client version; --path scans any file.

Run Gate0x Scan $ node gate0x.js scan copy

Private trial: run from the folder you receive. Nothing is installed.

node gate0x.js scan
Gate0x Scan  found 3 MCP servers
Local only: nothing was uploaded and no MCP server was started.

2 need attention   0 worth a look   1 look fine   0 already protected

[HIGH] filesystem  (Cursor)
  Looks able to: read and change files
  high  Very broad filesystem access  [GX-FS-001]
        Why: The server is allowed to access "/".
        Fix: Restrict it to a single project directory.
  medium  Unpinned package  [GX-SUP-001]
        Why: npx runs "@modelcontextprotocol/server-filesystem" without a pinned version, so a new release (or a compromised one) runs automatically.
        Fix: Pin an exact version, for example package@1.2.3.

[HIGH] github  (Cursor)
  Looks able to: deploy or publish (for example push code), send data over the network
  high  Secret stored in plain text in the config  [GX-SEC-001]
        Why: Literal secret value(s) for: GITHUB_PERSONAL_ACCESS_TOKEN.
        Fix: Move the secret to an environment variable your shell provides (or a secret manager), and rotate it if this file was ever shared.

Look fine: memory

Next
  node gate0x.js wrap filesystem --apply     protect it: shows the change, asks first, keeps a backup
  node gate0x.js scan --verbose              every finding, and which config files were checked

Capabilities are inferred from names and packages in the config; Gate0x did not start any server.

Gate0x Protect

Control actions before they execute.

Protect is a local proxy for MCP servers that run on your machine. Your agent talks to Gate0x, Gate0x decides each tool call by policy, and only then does the real server see it. This is the flow that was tested on a real client.

  1. Claude Code the agent calls a tool
  2. Gate0x checks the call against policy
  3. delete_note the proposed action
  4. REQUIRE_APPROVAL held, not forwarded
  5. Human decision approve once, or deny
  6. Execute the exact held call is forwarded Deny or no answer: not forwarded

Static illustration of the validated flow, not a live demo. The approver sees this in a terminal:

Approval Watch (terminal)
ACTION REQUIRES APPROVAL

Tool:
gate0x-test-server.delete_note

Arguments:
{"name":"test"}
(secret values are redacted)

Reason:
Deleting or destroying data requires approval.

Expires:
in 120 seconds, at 14:03:09. No answer means denied.

[A] Approve once
[D] Deny

Choice:

The human sees the exact call.

Only an explicit A approves and only an explicit D denies. Enter alone does nothing, and silence is a denial.

  • Deterministic policy. Rules decide, not a model. Every decision carries a reason code and the rule that made it.
  • Approval tied to the exact call. It is single-use for the call shown, and it expires.
  • Audit trail with redaction. Each decision is written before the call runs, in a tamper-evident log. Secret-looking arguments are redacted, best effort.

Local-first

Start local.

  • No account required for Scan.
  • Scan does not upload your local MCP configuration.
  • Enforcement stays close to the agent. Local enforcement keeps the normal policy decision path on your machine.
  • No telemetry. Gate0x makes no network connections of its own.

Where it goes

Discover. Enforce. Coordinate.

Private trial

Scan

Discover.

See which agents can reach which tools, and what is risky about them.

Private trial

Protect

Enforce.

Decide each local MCP tool call by policy, with human approval and an audit trail.

Planned, not built

Control

Coordinate teams.

Shared policy and review across a team. Nothing here is available yet and there is no date.

Gate0x complements your existing identity, gateway and agent stack by controlling the action immediately before execution.

Proof

Tested on a real agent workflow.

  1. read_note ALLOW forwarded
  2. delete_note REQUIRE_APPROVAL withheld
  3. human approval APPROVED the exact held call forwarded
  4. no approval TIMEOUT not forwarded

This validation used Claude Code and a project-scoped local MCP server (a harmless synthetic test server). It was run by hand, on one macOS machine, on release candidate 4.

It does not show that other clients work. We have not validated them, and the private trial is where we find out.

Security · current scope

What it covers today, and what it does not.

Covered today

  • Local stdio MCP tools/call.
  • A macOS-first private trial. Linux is tested by CI only; Windows is not supported.

Not covered, or limited

  • Remote MCP servers, MCP resources and prompts, and an agent's built-in tools are not yet covered.
  • Classification is heuristic and can miss dangerous tools. Write explicit rules for the ones that matter.
  • Gate0x is not complete agent security. It does not replace host-agent, identity, network or enterprise gateway controls.

Local approvals are not a security boundary. They are a safeguard against mistakes, not against an agent with equivalent shell access as your user, which can approve its own request. Block or approval-gate shell execution. Read the security page.

Private trial

Put Gate0x in front of your first agent action.

We are onboarding a small group of developers. Tell us what you run and we will send the package.