mcpgawk

mcpgawk

Catch MCP servers that change after you approved them

Developer ToolsGitHubSecurity
▲ 69 votes1 commentsLaunched Oct 6, 2026
Visit Website
Daily #22Weekly #41
mcpgawk screenshot 1

An MCP server can change what its tools do after you approved it. Your agent will call the new one and never notice. mcpgawk records a baseline of every MCP server your agents use, checks behaviour in a sandbox, and sits in the path: once a tool changes after you approved it, the call is refused until you decide. The agent cannot approve its own way past it. Everything runs on your machine. Nothing is uploaded. Free CLI, VS Code extension and MCP server. The gateway tier has a 7-day trial.

AI Analysis

📝 Summary

mcpgawk is a security tool that catches MCP servers changing tool behaviors after user approval, a blind spot for AI agents. It records baselines, runs sandbox checks, and intercepts as a local gateway to refuse altered calls until re-approved by the user. Agents cannot self-approve bypasses. Fully local with zero uploads for privacy. Offered as free CLI, VS Code extension, and MCP server; gateway tier includes 7-day trial. Solves critical post-approval mutation risks in agent-tool ecosystems, delivering secure, transparent AI agent operations without cloud dependency.

📈 Market Timing

In 2025-2026, AI agent adoption and tool-calling frameworks are surging, with rising concerns over supply-chain attacks and dynamic server trust. Privacy-first, on-device security aligns with regulatory trends and user demands for control. MCP-related vulnerabilities are emerging alongside agent tech maturity. This positions mcpgawk at an ideal juncture. Excellent Timing.

✅ Feasibility

High. Technical implementation leverages existing sandboxing, proxy patterns, and local execution, keeping difficulty moderate for security devs. Low ongoing operational costs with no cloud infra needed. Minimal supply chain or compliance risks as everything runs on-user machine. Strong scalability for desktop use; team with GitHub/dev tools experience would fit well. Main challenge is broad MCP protocol support.

🎯 Target Market

Main segments: AI/ML engineers and developers building agentic apps, security-focused indie hackers and dev teams using GitHub. Industries: AI development, cybersecurity, software tools. Primarily global with heavy US/Europe concentration. TAM for AI security ~$5B+, SAM for agent tooling security ~$300-500M, SOM for local MCP guards ~$30-50M. Core pains: undetected tool changes, agent trust issues, privacy in third-party servers. Moderate-high willingness to pay for gateway tier among professionals.

⚔️ Competition

Low. Direct competitors: 1. Lakera Guard (lakera.ai), 2. NVIDIA NeMo Guardrails (nvidia.com/nemo), 3. Giskard (giskard.ai), 4. Protect AI (protect.ai), 5. LangSmith (smith.langchain.com). Advantages: extreme specificity to post-approval MCP changes, fully local/no-upload model, sandbox+gateway combo that agents cannot bypass, free core tools. Disadvantages: narrower scope than broad LLM guards, newer entrant with potentially fewer integrations, relies on trial-to-paid conversion vs some open-source alternatives.

Upgrade Pro to unlock full AI analysis