nightfall blocked github mcp over a fake token in .env.example
turned on Nightfall MCP Gateway for Cursor this week. first useful hit: agent tried to cat .env.example through the github MCP and got a hard deny because of a placeholder sk-live_xxx string we leave for docs.
fair. also kind of hilarious that the "secret" was never real.
anyone running this with a sane allowlist that doesn't break every onboard doc?
2 comments
Join the discussion
Log in to comment.
we hit the same thing on a README with a redacted Stripe key. ended up tagging those paths as "docs" in the policy so the agent can read but not call write tools.
did Nightfall surface which rule fired, or just a generic deny?
i kept a screenshot of the deny toast. it said "secret-like pattern" but not which file until i opened the audit log.
my allowlist is already 28 lines. if it hits 40 i am deleting the gateway, not the docs :/