
Catch MCP servers that change after you approved them
An MCP server can change what its tools do after you approved it. Your agent will call the new one and never notice. mcpgawk records a baseline of every MCP server your agents use, checks behaviour in a sandbox, and sits in the path: once a tool's description or power changes, the call is refused until you decide. The agent cannot approve its own way past it. Everything runs on your machine. Nothing is uploaded. Free CLI, VS Code extension and MCP server. The gateway tier has a 7-day trial.
mcpgawk monitors MCP servers for unauthorized changes post-approval by recording a baseline and checking behavior in a sandbox. It operates locally, ensuring no data is uploaded, and includes a free CLI, VS Code extension, and a 7-day trial for the gateway tier.
Scored deterministically. Only candidates that fire a story trigger are sent to a model, so this one has no written angle.
Gaps in our data, not findings about the product. Their weight is redistributed across the 5 we did measure.
A source that found nothing is a measurement. A source that has not run is a gap. Neither means the launch lacks the thing.