MCP proxy: governing every tool call an agent makes
An MCP proxy is a process that sits between an MCP client, such as Claude Code, Cursor or Codex, and the MCP servers it calls, so that every message between them passes through it. It looks like a server to the agent and like a client to the server. What it does with that position is what separates one MCP proxy from another.
Three kinds of MCP proxy
| Kind | What it does | Where it runs |
|---|---|---|
| Transport bridge | converts between transports, such as a local stdio server and a remote HTTP one | beside the client |
| Gateway | puts many servers behind one endpoint, with authentication, rate limits and logging | on a server the team shares |
| Governing proxy | decides every tool call before the server sees it | on the machine the agent runs on |
Most results for "MCP proxy" are the first kind. A gateway suits servers the team hosts centrally. A governing proxy is for the servers an agent starts on a developer's own laptop, which is where a local stdio server runs.
What the Memnox MCP proxy does
Memnox ships a governing proxy, open source and local. One command points every MCP server on the machine at it, and keeps a backup of each config it changes:
memnox mcp wrap # repoint every MCP server at the proxy
memnox mcp unwrap # put them back byte for byteClaude Code, Cursor and Codex configs are handled by name, and anything with a
standard .mcp.json is handled too. Then the proxy sees three things:
| Message | What the proxy does |
|---|---|
initialize | passes it through unchanged |
tools/list | classifies every tool as read, write, destructive, communication or unknown, and removes any tool you hid, so the agent never learns it exists |
tools/call | decides it before it reaches the server: allow forwards it, ask holds it for a person, deny returns an error the agent can act on |
Rules name a call as mcp.<server>.<tool>, in the same rule file that governs
shell commands and file edits:
version = 1
[[policies]]
name = "ask-before-github-writes"
[policies.match]
actions = ["mcp.github.create_*", "mcp.github.merge_*"]
[policies.decision]
effect = "ask"
reason = "these change something other people see."A denied call comes back as a protocol error the client already understands, naming the rule, the reason and one alternative where the rule gave one. It carries nothing else, because the text is read by a model, and a refusal that told a model what to do would be an injection point.
A new MCP server starts on probation
When somebody installs a new MCP server, it starts on probation for seven days:
its writes and its outward and destructive actions ask first, and its reads do
not. memnox mcp trust <server> ends probation early, on the record. A server is
judged by what its tools can actually do rather than by a score or an install
count.
What an MCP proxy cannot see
Only what goes through it. An MCP server an agent reaches without its config is
outside the proxy, and a tool that lies about its name in tools/list is
classified by the lie. That is why Memnox also holds the shell, the network, git
credentials and the browser, and the
runtime reference lists each seam with its limits.
Questions people ask
What is the difference between an MCP proxy and an MCP gateway?
A gateway is usually a shared service that puts many servers behind one endpoint. A proxy can be anything in the path; a governing proxy is one that decides each tool call, and the Memnox one runs on the machine the agent runs on.
Is the Memnox MCP proxy open source?
Yes. It is part of the Apache-2.0 Memnox runtime, and it needs no account and no network.
Does the agent have to support the proxy?
No. memnox mcp wrap rewrites the agent's MCP config so the server it starts is
the proxy, which starts the real server. The agent calls its tools as before.
Can I hide a tool from the agent completely?
Yes. A hidden tool is removed from tools/list and denied if it is called
anyway, since hiding it alone would leave the call itself open.

