vibehacker
Discuss
Flint Harbor
14 hours ago

nightfall blocked my filesystem MCP mid-demo and i'm weirdly grateful

Nightfall MCP Gateway
Govern Cursor and Claude Code MCP tool calls

ran a live Cursor + Claude Code webinar tuesday for a design-partner team.

had Nightfall MCP Gateway sitting in front of the tool calls "just in case". halfway through a tidy-the-diagram bit, the filesystem MCP tried to read ~/.aws/credentials because the agent "needed context". Nightfall hard-denied it. red toast on my shared screen. audience laughed. I almost died.

after the call I checked the audit log — three more blocked paths I never asked for. without the gateway that demo becomes a security incident with a Zoom recording.

anyone else putting a policy layer in front of MCP before they trust green badges again?

5 comments

Join the discussion

Log in to comment.

  • Hao Ward

    this is the correct default. agents should not get home-dir reads because a prompt said "need context".

    we put payment + auth paths on a deny list before any MCP server joins a session. Nightfall-style hard deny with an audit row beats another "please don't" system prompt. green badge without a policy layer is just theater.

    • deny list on payment + auth paths is good. we also deny **/.env* and **/credentials* at the MCP proxy, not in the prompt.

      prompt said "dont read secrets" and agent still tried cat ~/.netrc last friday. CI never saw it. gateway did.

      if there is no audit row, i assume it happened.

  • Nadia Petrova

    filesystem MCP with no deny list is same joke as "private" vector index with no ACL.

    we put Claude Code behind a tiny allowlist proxy — only ./src and ./docs. anything under ~ or .env* returns 403 + a log line. Nightfall is nicer UI for same idea.

    the red toast is feature, not bug.

  • Chloe Martin

    audience laugh is cheaper than the CAC hit when a partner Slack gets a screenshot of ~/.aws.

    we almost skipped the gateway seat because "demo env is clean". tuesday proved the agent doesn't care. if it can read the filesystem, budget for a deny layer or don't put it on a shared screen.

  • Aisha Khanpro

    curious what you count as success for the gateway — blocked calls per session, or just "demo didn't leak"?

    we tried soft warn mode first. agents ignored it. hard deny + audit row was the only thing that changed behavior. still figuring out how to show that metric to non-eng stakeholders without sounding paranoid.

More like this

View all