Skip to content

Privacy related Permission Gates? #18

Description

@salderma

Hi,

Came across your MCP router from the OMO discord.

Curious what you think about the possibility of evaluating what the MCP's being asked to do, based on some global or project specific privacy rules?

I'm thinking about this from a perspective of data or intellectual property loss to external parties through MCP service use. Organizations are already trying to be very careful about loss of internal data to the big LLM providers, I think it makes sense to think about the topic from an MCP perspective too.

MCPs are designed to provide a JSON tool-spec response, given that your tool is man-in-the-middling the agent-MCP communication, it seems like a great place to be able to evaluate if or when a downstream MCP tool is doing something risky with our information/data... maybe there's a way to prefer "local" or "internal" MCPs over external ones for some sensitive tasks.

If nothing else, it would be an interesting place to log everything destined for (and maybe also returning from) an MCP, perhaps that can be used to track and evaluate MCP related leakage concerns.

Maybe your tool isn't the right place to assert such constraints, I admit I'm not as deep into the architecture as I should be to raise such a question...but not sure where else to discuss it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions