Hi,
Came across your MCP router from the OMO discord.
Curious what you think about the possibility of evaluating what the MCP's being asked to do, based on some global or project specific privacy rules?
I'm thinking about this from a perspective of data or intellectual property loss to external parties through MCP service use. Organizations are already trying to be very careful about loss of internal data to the big LLM providers, I think it makes sense to think about the topic from an MCP perspective too.
MCPs are designed to provide a JSON tool-spec response, given that your tool is man-in-the-middling the agent-MCP communication, it seems like a great place to be able to evaluate if or when a downstream MCP tool is doing something risky with our information/data... maybe there's a way to prefer "local" or "internal" MCPs over external ones for some sensitive tasks.
If nothing else, it would be an interesting place to log everything destined for (and maybe also returning from) an MCP, perhaps that can be used to track and evaluate MCP related leakage concerns.
Maybe your tool isn't the right place to assert such constraints, I admit I'm not as deep into the architecture as I should be to raise such a question...but not sure where else to discuss it.
Hi,
Came across your MCP router from the OMO discord.
Curious what you think about the possibility of evaluating what the MCP's being asked to do, based on some global or project specific privacy rules?
I'm thinking about this from a perspective of data or intellectual property loss to external parties through MCP service use. Organizations are already trying to be very careful about loss of internal data to the big LLM providers, I think it makes sense to think about the topic from an MCP perspective too.
MCPs are designed to provide a JSON tool-spec response, given that your tool is man-in-the-middling the agent-MCP communication, it seems like a great place to be able to evaluate if or when a downstream MCP tool is doing something risky with our information/data... maybe there's a way to prefer "local" or "internal" MCPs over external ones for some sensitive tasks.
If nothing else, it would be an interesting place to log everything destined for (and maybe also returning from) an MCP, perhaps that can be used to track and evaluate MCP related leakage concerns.
Maybe your tool isn't the right place to assert such constraints, I admit I'm not as deep into the architecture as I should be to raise such a question...but not sure where else to discuss it.