What MCP Guard protects
The integration layer: the tools, functions, APIs, and MCP servers an agent or application invokes to take action in the world. This is where an AI stops producing text and starts having real-world effect, so an unauthorized call or an inflated parameter can do concrete damage.Threats it stops
- Tool poisoning & unauthorized tool use — only allowlisted tools can be invoked, within defined scopes and resource bounds, under deny-by-default (
BG-21). - Parameter injection — per-call argument and schema validation blocks inflated or malicious parameters and cross-tool escalation (
BG-21,BG-25). - Schema violation & unauthorized functions — function invocation restricted to allowlisted functions with signature and return-type checks; implicit calls and function-chaining escalation blocked (
BG-25).
How it works
MCP Guard enforces deny-by-default tool and function whitelists with argument-level validation, privilege tiers, and quotas, and requires confirmation for high-risk actions. Every invocation is checked before execution and logged; anything outside the approved set is deterministically refused with a reason code.Controls
MCP Guard runsBG-21 and BG-25. See the Controls Catalog for each control’s definition, scope, and benchmark.
OWASP coverage
Addresses LLM06 Excessive Agency from the OWASP LLM Top 10, alongside Agent Guard.Related
Agent Guard
Governs the plan and reasoning chain behind these calls.
Controls Catalog
The controls MCP Guard runs, in full detail.
Guard Gateway API
Route tool-augmented traffic through BeyondGuard.
Policy Configuration
Define tool and function whitelists and scopes.