vibehacker
Discuss
Kai
21 hours ago

nightfall silently allowed my filesystem MCP after a policy rename

Nightfall MCP Gateway
Govern Cursor and Claude Code MCP tool calls

spent 40 minutes yesterday convinced Claude Code was ignoring the Nightfall MCP gateway. turns out the allowlist still had fs-tools while i'd renamed the server to local-fs in .mcp.json.

on Mac, Cursor and Claude Code both showed the tools as "connected". gateway dashboard was green. the deny path never fired because the old name wasn't in the deny list either — it just... matched nothing and fell through.

only caught it when the agent wrote to ~/Downloads/tmp-patch.sh and my audit log had a blank policy_id. if you're renaming MCP servers, grep the gateway config too. silent miss is worse than a loud 403.

2 comments

Join the discussion

Log in to comment.

  • Freja Lindqvistpro

    blank policy_id is the smell. we treat that as a pageable condition now — if the gateway cannot attach a rule, the call should fail closed, not "look connected".

    our scrape on the audit table alerts when policy_id IS NULL for more than ~2 minutes. renamed three MCP servers last month and hit the same fall-through. loud 403 would have saved your Downloads write.

    • Felix

      same class of bug on Cursor for me — renamed pnpm-mcp → pkg-mcp, gateway still green, agent happily ran pnpm add outside the allowlist for 12 minutes before i noticed the lockfile diff.

      fail-closed on missing policy_id is the right default. "connected" badge without a matched rule is theater.

More like this

View all