
mcpgawk
Catch MCP servers that change after you approved them

An MCP server can change what its tools do after you approved it. Your agent will call the new one and never notice. mcpgawk records a baseline of every MCP server your agents use, checks behaviour in a sandbox, and sits in the path: once a tool changes after you approved it, the call is refused until you decide. The agent cannot approve its own way past it. Everything runs on your machine. Nothing is uploaded. Free CLI, VS Code extension and MCP server. The gateway tier has a 7-day trial.
AI Analysis
mcpgawk is a security tool that catches MCP servers changing tool behaviors after user approval, a blind spot for AI agents. It records baselines, runs sandbox checks, and intercepts as a local gateway to refuse altered calls until re-approved by the user. Agents cannot self-approve bypasses. Fully local with zero uploads for privacy. Offered as free CLI, VS Code extension, and MCP server; gateway tier includes 7-day trial. Solves critical post-approval mutation risks in agent-tool ecosystems, delivering secure, transparent AI agent operations without cloud dependency.
In 2025-2026, AI agent adoption and tool-calling frameworks are surging, with rising concerns over supply-chain attacks and dynamic server trust. Privacy-first, on-device security aligns with regulatory trends and user demands for control. MCP-related vulnerabilities are emerging alongside agent tech maturity. This positions mcpgawk at an ideal juncture. Excellent Timing.
High. Technical implementation leverages existing sandboxing, proxy patterns, and local execution, keeping difficulty moderate for security devs. Low ongoing operational costs with no cloud infra needed. Minimal supply chain or compliance risks as everything runs on-user machine. Strong scalability for desktop use; team with GitHub/dev tools experience would fit well. Main challenge is broad MCP protocol support.
Main segments: AI/ML engineers and developers building agentic apps, security-focused indie hackers and dev teams using GitHub. Industries: AI development, cybersecurity, software tools. Primarily global with heavy US/Europe concentration. TAM for AI security ~$5B+, SAM for agent tooling security ~$300-500M, SOM for local MCP guards ~$30-50M. Core pains: undetected tool changes, agent trust issues, privacy in third-party servers. Moderate-high willingness to pay for gateway tier among professionals.
Low. Direct competitors: 1. Lakera Guard (lakera.ai), 2. NVIDIA NeMo Guardrails (nvidia.com/nemo), 3. Giskard (giskard.ai), 4. Protect AI (protect.ai), 5. LangSmith (smith.langchain.com). Advantages: extreme specificity to post-approval MCP changes, fully local/no-upload model, sandbox+gateway combo that agents cannot bypass, free core tools. Disadvantages: narrower scope than broad LLM guards, newer entrant with potentially fewer integrations, relies on trial-to-paid conversion vs some open-source alternatives.
Upgrade Pro to unlock full AI analysis
Similar Products

Opaline
PostHog for team Claude Code and Codex sessions.
▲ 141 votes

React UI Kit V7
All the chat components you need. None of the complexity
▲ 115 votes

Replay QA Security Scan
Automated Penetration Testing for AI-Built Apps
▲ 102 votes

CodeBurn
See where your AI coding spend actually goes
▲ 101 votes

Audryo
Customer email your agent can operate.
▲ 68 votes
Refoid
Automate App Store refund responses and track every outcome
▲ 68 votes