Skip to content

CM-73403: Enforce the unauthorized MCP server guardrail - #551

Open
Altruistus wants to merge 1 commit into
mainfrom
CM-73403-unauthorized-mcp-server-guardrail
Open

Altruistus wants to merge 1 commit into
mainfrom
CM-73403-unauthorized-mcp-server-guardrail

Conversation

@Altruistus

@Altruistus Altruistus commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • New guardrail unauthorized_mcp_server in the pre-MCP-execution hook:
    • Block denies the call before the argument secret scan runs.
    • Report records the event as warned and then runs the argument scan.
    • It defaults to Off when the platform has no entry for it.
  • Server statuses at session start: fetched from GET v4/ai-security/authorization/mcp/servers and cached in ~/.cycode/ai-guardrails-mcp-servers.json, with the same TTL and tenant handling as the guardrail config. The hook only reads the cache, and lets the call through when it is missing.
  • Strict mode: supported through settings.enforce_on=not_authorized.
  • Server name resolution:
    • Cursor: the server name is found in mcp.json by url or command.
    • Plugin names: namespaced tool names are mapped back to the alias the platform stores.

Backend: ai-security-manager MR !133. It needs to be deployed before this is released, although the CLI lets calls through if the endpoint is missing.

Jira

CM-73403

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant