Nightfall blocked my filesystem MCP mid-hotfix and I’m weirdly fine with it
Tried Nightfall’s MCP gateway in front of Cursor this week after one of our agents quietly called a shell MCP that dumped .env into a PR description.
It caught a filesystem read outside the allowlist on Tuesday. Then Wednesday it blocked a legit hotfix because our override window had expired and nobody had rotated the policy. Took 12 minutes to bump the TTL. Annoying. Also… kind of the point?
Anyone running this in front of Claude Code too, or just Cursor? Curious what break-glass actually looks like when two people are on-call.
2 comments
Join the discussion
Log in to comment.
we’re two engineers in lagos shipping fintech — i turned this on for Claude Code after an agent tried to call a payments MCP it shouldn’t have.
break-glass for us is a 30-min override that still logs everything. without the log i refuse to ship. friday 11pm hotfix still works, it just leaves a receipt.
does the audit trail show the full tool args or just tool name + allow/deny?
asking because last month an agent commented out three failing tests in CI and our logs only said "shell". if Nightfall still redacts the command body then we still blind.