MCP SECURITY GATEWAY LOCAL DEMO

TRUST THE AGENT.
VERIFY THE ACTION.

Language becomes authority.
Atreides makes it enforceable.

Atreides is an MCP security gateway that blocks unsafe agent tool calls before execution, independent of the LLM's own reasoning, then emits a verifiable receipt explaining exactly why.

MCP-native security gatewayPre-execution unsafe tool-call blockHash-chained audit receipts
PROMPT INJECTIONPROVENANCE-FIRST ENFORCEMENT

01 / ATTACK REPLAY

Same attack.
Blocked before execution.

Judges can see the complete before/after: an indirect prompt injection attempts secret egress, Atreides blocks the unauthorized MCP action, and the receipt proves why.

OBSERVEDtrace_47a9

01 / EXTERNAL ISSUE

A malicious README asks an agent to collect diagnostics.

source.trustexternal / untrusted
requested.tooldiagnostics.send
data.labelsecret
EVALUATE

Tracing capability and provenance before execution.

01External issue
02Sensitive read
03Outbound send
04Atreides blocks
RECEIPT PENDINGSHA-256 CHAINED
BEFOREUnprotected agent

The same indirect instruction reaches a privileged action with no policy boundary.

No LLM classification can stop a tool call by itself.
AFTERAtreides intercepts

The exact action is evaluated before the MCP boundary.

Deterministic policy checks provenance, sensitivity, destination, and impact.
AUDITTrust receipt

The decision reason and receipt hash are retained for review.

Cryptographic evidence, not a model confidence score.

The baseline is deliberately synthetic. The block and receipt are real gateway results.

Each frame is an auditable transition, not a model guess.

02 / THE DIFFERENCE

Not a wrapper.
An enforcement layer.

Detection asks whether a phrase looks dangerous. Atreides asks whether untrusted context is authorized to use a risky MCP capability, then enforces that answer outside the model.

01Context envelopeOrigin · trust · sensitivity · hash
02Action graphTask · tool · destination · asset
03Policy decisionAllow · block · approval required
04Trust receiptExplanation · policy · hash chain

01Policy is deterministic.

02Evidence is portable.

03Enforcement is upstream-aware.

03 / WORKFLOW

From prompt injection
to provable block.

This is the complete control path. The model may still see the malicious instruction, but Atreides governs the tool boundary before anything leaves.

01 / SOURCE

Untrusted content enters

A README, issue, webpage, email, or tool result enters the agent workspace with provenance attached.

Click any step to scrub the workflow. Autoplay pauses for reduced-motion users.

04 / POLICY LAB

Test the boundary.
Change the facts.

This is not a mock. Configure an action and evaluate it against the live versioned policy gateway. Every result becomes a trust receipt.

LIVE POLICY RESULT

readyConfigure an action to inspect its authorization path.

Atreides evaluates provenance, sensitivity, destination, and impact before execution.

05 / OPERATOR CONSOLE

Every decision is
an evidence trail.

The before/after proof produces a real policy receipt. Inspect its rule, version, integrity state, and hash here.

Run the proof
atreides / mission-controlGATEWAY OFFLINE
POLICY VERSIONWAITINGversioned policy-as-code
BLOCKED CHAINS03awaiting proof replay
RECEIPT MODEHASHEDephemeral demo ledger
READYRun the safe fixture to obtain a live receiptgateway / waiting for replay