ALLOW
- Decision
- ALLOW
- Tool
- github.read_issue
- Reason
- Read-only action allowed.
Forwarded to the tool.
Private trialLocal-firstMCP first
See what your agents can do. Control what they are allowed to do.
ALLOW
Forwarded to the tool.
APPROVAL REQUIRED
BLOCK
Refused. Never reaches the tool.
Illustration of the three decisions Gate0x returns. Tool names are examples and this is not a live demo.
The problem
Once an agent can call tools, the risk is not only what it says. It is what it does. Today the decision to run a tool is often left to the model itself, or to a prompt people learn to click through.
The control point
Gate0x evaluates the proposed action before execution, using deterministic policy. The same call and the same policy always give the same decision, and normal decisions do not require an LLM. Today that point is local MCP tool calls; MCP is the first adapter.
Gate0x Scan
Scan finds the MCP servers configured on your machine, and the tool permissions they quietly grant your agents. Discovery is local and needs no account.
It does not start any server and does not upload your configuration. It looks in the
default config locations of Claude Desktop, Claude Code, Cursor, Windsurf, VS Code,
Gemini CLI and Zed. Those locations are not yet verified against every client
version; --path scans any file.
Private trial: run from the folder you receive. Nothing is installed.
Gate0x Scan found 3 MCP servers
Local only: nothing was uploaded and no MCP server was started.
2 need attention 0 worth a look 1 look fine 0 already protected
[HIGH] filesystem (Cursor)
Looks able to: read and change files
high Very broad filesystem access [GX-FS-001]
Why: The server is allowed to access "/".
Fix: Restrict it to a single project directory.
medium Unpinned package [GX-SUP-001]
Why: npx runs "@modelcontextprotocol/server-filesystem" without a pinned version, so a new release (or a compromised one) runs automatically.
Fix: Pin an exact version, for example package@1.2.3.
[HIGH] github (Cursor)
Looks able to: deploy or publish (for example push code), send data over the network
high Secret stored in plain text in the config [GX-SEC-001]
Why: Literal secret value(s) for: GITHUB_PERSONAL_ACCESS_TOKEN.
Fix: Move the secret to an environment variable your shell provides (or a secret manager), and rotate it if this file was ever shared.
Look fine: memory
Next
node gate0x.js wrap filesystem --apply protect it: shows the change, asks first, keeps a backup
node gate0x.js scan --verbose every finding, and which config files were checked
Capabilities are inferred from names and packages in the config; Gate0x did not start any server.
Gate0x Protect
Protect is a local proxy for MCP servers that run on your machine. Your agent talks to Gate0x, Gate0x decides each tool call by policy, and only then does the real server see it. This is the flow that was tested on a real client.
Static illustration of the validated flow, not a live demo. The approver sees this in a terminal:
ACTION REQUIRES APPROVAL
Tool:
gate0x-test-server.delete_note
Arguments:
{"name":"test"}
(secret values are redacted)
Reason:
Deleting or destroying data requires approval.
Expires:
in 120 seconds, at 14:03:09. No answer means denied.
[A] Approve once
[D] Deny
Choice:
Only an explicit A approves and only an explicit D
denies. Enter alone does nothing, and silence is a denial.
Local-first
Where it goes
Private trial
Discover.
See which agents can reach which tools, and what is risky about them.
Private trial
Enforce.
Decide each local MCP tool call by policy, with human approval and an audit trail.
Planned, not built
Coordinate teams.
Shared policy and review across a team. Nothing here is available yet and there is no date.
Gate0x complements your existing identity, gateway and agent stack by controlling the action immediately before execution.
Proof
This validation used Claude Code and a project-scoped local MCP server (a harmless synthetic test server). It was run by hand, on one macOS machine, on release candidate 4.
It does not show that other clients work. We have not validated them, and the private trial is where we find out.
Security · current scope
tools/call.Local approvals are not a security boundary. They are a safeguard against mistakes, not against an agent with equivalent shell access as your user, which can approve its own request. Block or approval-gate shell execution. Read the security page.
Private trial
We are onboarding a small group of developers. Tell us what you run and we will send the package.