

arc-gate-mcp
Runtime governance proxy for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.
What it does
arc-gate-mcp sits between your MCP client and any MCP server. Every tool result passes through Arc Gate governance before reaching your agent β blocking prompt injection attacks that exploit the MCP trust boundary.
Installation
pip install arc-gate-mcp
Usage
arc-gate-mcp --upstream "uvx mcp-server-fetch" --policy balanced
With Claude Desktop
{
"mcpServers": {
"arc-gate": {
"command": "uvx",
"args": ["arc-gate-mcp", "--upstream", "uvx mcp-server-fetch", "--policy", "browser_agent"]
}
}
}
Policy modes
balancedβ general purposebrowser_agentβ web browsing agentsfinance_agentβ financial data agentsrag_assistantβ document retrieval agentsstrictβ maximum enforcement
Links
License
AGPL-3.0
Used with Heym
arc-gate-mcp is available as a template on Heym β an enterprise agent platform. Try the Governed Web Research Agent template to see Arc Gate MCP in action.











