| |
Show HN: cMCP, deny an AI agent's tool call and get a signed receipt
cMCP is a secure gateway that enforces tool-call policies for AI agents by running policy evaluation inside a hardware Trusted Execution Environment (TEE), preventing the agent from circumventing access controls. Every tool call is intercepted, evaluated against a Cedar policy, and blocked or redacted if denied, with each session producing a cryptographically signed TRACE Claim as tamper-evident proof of compliance. The project is in developer preview and can run in software mode without special hardware, addressing the risk that AI agents might leak sensitive data or that policy enforcement could be compromised.
Read Full Article →
← More Tech news