Skip to main content
MCP Guard protects the MCP / tools surface — everything the AI can call. Every tool call, function invocation, and MCP server interaction is validated against deny-by-default whitelists before it reaches an external system.

What MCP Guard protects

The integration layer: the tools, functions, APIs, and MCP servers an agent or application invokes to take action in the world. This is where an AI stops producing text and starts having real-world effect, so an unauthorized call or an inflated parameter can do concrete damage.

Threats it stops

  • Tool poisoning & unauthorized tool use — only allowlisted tools can be invoked, within defined scopes and resource bounds, under deny-by-default (BG-21).
  • Parameter injection — per-call argument and schema validation blocks inflated or malicious parameters and cross-tool escalation (BG-21, BG-25).
  • Schema violation & unauthorized functions — function invocation restricted to allowlisted functions with signature and return-type checks; implicit calls and function-chaining escalation blocked (BG-25).

How it works

MCP Guard enforces deny-by-default tool and function whitelists with argument-level validation, privilege tiers, and quotas, and requires confirmation for high-risk actions. Every invocation is checked before execution and logged; anything outside the approved set is deterministically refused with a reason code.

Controls

MCP Guard runs BG-21 and BG-25. See the Controls Catalog for each control’s definition, scope, and benchmark.

OWASP coverage

Addresses LLM06 Excessive Agency from the OWASP LLM Top 10, alongside Agent Guard.

Agent Guard

Governs the plan and reasoning chain behind these calls.

Controls Catalog

The controls MCP Guard runs, in full detail.

Guard Gateway API

Route tool-augmented traffic through BeyondGuard.

Policy Configuration

Define tool and function whitelists and scopes.