MCP security

Catch a malicious MCP server
before your AI does.

MCP servers can carry hidden instructions that hijack your assistant. gate scans every server before it goes live, watches it for changes afterwards, and keeps a record of everything your AI did.

Scan any MCP server for free — no account needed

Connect the tools your AI already wants to use
ClaudeChatGPTSentryLinearNotionStripe
The problem

The attack surface nobody is watching

Your AI reads every tool description a server sends it — and does what the text says. That makes MCP servers a direct line into your assistant.

Tool poisoning

A single manipulated tool description can quietly instruct your AI to leak data or take actions you never approved.

Rug pulls & drift

A server that was safe yesterday can change its tools today. Without monitoring, you'd never know.

Shadow MCP

Teammates connect unvetted servers straight into their AI apps — invisible to you until something goes wrong.

Why gate

Security at every stage of the connection

gate checks servers before they go live, watches them while they run, and records everything they do.

Scan

Every server checked before it reaches your AI

Before a server goes live, gate scans its tools for prompt injection, hidden text, and descriptions written to hijack your assistant.

  • Automatic prompt-injection & hidden-text detection
  • Suspicious tool descriptions flagged in plain language
  • Provenance checks against a verified catalog
Watch

Drift alerts when a server quietly changes

gate keeps watching after you connect. If a tool's description or behavior changes, you're the first to know — before your AI acts on it.

  • Continuous monitoring of every connected server
  • Alerts on changed or newly added tools
  • Re-scan on every change
Contain

Limit the blast radius with per-tool rules

Even a trusted server doesn't need free rein. Allow, block, or require human approval per tool — so sensitive actions always pass through you first.

  • Allow, Ask, or Block on every single tool
  • Human approval for sensitive actions
  • Different rules per app and per team
Prove

A full audit trail, readable by humans

Every tool call is logged and summarized in plain English. When someone asks what your AI did last week, you have the answer in seconds.

  • Complete, searchable log of every action
  • Plain-language summaries and daily digests
  • Evidence for reviews and audits
How it works

Secure your MCP setup in three steps

01

Scan your servers

Run any server through the free scanner — or connect it to gate and it's scanned automatically.

02

Route through the gateway

One URL in your AI clients means every call passes the same security checks.

03

Set your guardrails

Block risky tools, require approval for sensitive ones, and get alerted on drift.

FAQ

Questions, answered

What are the biggest MCP security risks?

The main risks are prompt injection and tool poisoning (malicious instructions hidden in tool descriptions), rug pulls (a server changing its tools after you've connected it), and over-permissioned access with no audit trail. gate addresses all four with scanning, drift alerts, per-tool rules, and logging.

What is tool poisoning?

Tool poisoning is when an MCP server embeds hidden instructions in a tool's description or metadata. Your AI reads those descriptions to decide what to do — so a poisoned description can make it leak data or take unauthorized actions. gate scans for exactly this pattern before a server goes live.

How does gate's security scan work?

gate fetches a server's tool list and analyzes every name, description, and schema for prompt-injection patterns, hidden text, and instructions aimed at the model rather than the user. You get a plain-language report before you connect — and a re-scan whenever the server changes.

What is shadow MCP?

Shadow MCP is the AI-era version of shadow IT: teammates connecting MCP servers to their AI apps without review or oversight. A gateway ends it structurally — connections run through one governed URL instead of scattered local configs.

Can I require approval before a tool runs?

Yes. Any tool can be set to Ask, which pauses the call until a human approves it from the dashboard or their inbox. Sensitive actions never run unattended.

Don't let your AI trust a server you haven't checked.

Scan free, connect through the gateway, and keep every tool call on the record.

Get started free