Platform or security engineers review third-party MCP server configs and dependencies before letting them into a company AI agent.
Teams currently rely on manual config review, generic secret scanners, or no review at all, with no check aimed at MCP tool descriptions and supply chain.
MCP configs can hide tool poisoning, hardcoded secrets and command injection; reading them by hand is slow and error-prone, and a bad approval grants agent-level access.