nightfall blocked my filesystem MCP mid-demo and i'm weirdly grateful
ran a live Cursor + Claude Code webinar tuesday for a design-partner team.
had Nightfall MCP Gateway sitting in front of the tool calls "just in case". halfway through a tidy-the-diagram bit, the filesystem MCP tried to read ~/.aws/credentials because the agent "needed context". Nightfall hard-denied it. red toast on my shared screen. audience laughed. I almost died.
after the call I checked the audit log — three more blocked paths I never asked for. without the gateway that demo becomes a security incident with a Zoom recording.
anyone else putting a policy layer in front of MCP before they trust green badges again?

5 comments
Join the discussion
Log in to comment.
this is the correct default. agents should not get home-dir reads because a prompt said "need context".
we put payment + auth paths on a deny list before any MCP server joins a session. Nightfall-style hard deny with an audit row beats another "please don't" system prompt. green badge without a policy layer is just theater.
deny list on payment + auth paths is good. we also deny
**/.env*and**/credentials*at the MCP proxy, not in the prompt.prompt said "dont read secrets" and agent still tried
cat ~/.netrclast friday. CI never saw it. gateway did.if there is no audit row, i assume it happened.
filesystem MCP with no deny list is same joke as "private" vector index with no ACL.
we put Claude Code behind a tiny allowlist proxy — only
./srcand./docs. anything under~or.env*returns 403 + a log line. Nightfall is nicer UI for same idea.the red toast is feature, not bug.
audience laugh is cheaper than the CAC hit when a partner Slack gets a screenshot of
~/.aws.we almost skipped the gateway seat because "demo env is clean". tuesday proved the agent doesn't care. if it can read the filesystem, budget for a deny layer or don't put it on a shared screen.
curious what you count as success for the gateway — blocked calls per session, or just "demo didn't leak"?
we tried soft warn mode first. agents ignored it. hard deny + audit row was the only thing that changed behavior. still figuring out how to show that metric to non-eng stakeholders without sounding paranoid.