Pages
Policy Config — MCP Server Allow-List
Source: c65 policy-definitions.md P6 — list-editor shape
‹ Policy Catalog
MCP Server Allow-List
BetaAgents may only connect to approved MCP servers — an unapproved server is an unvetted capability injection.
Action & Autonomy
medium
P6Satisfies
OWASP ASI
CSF 2.0
ISO 27001
Underlying control— show
tool: tool_kind = "mcp" and allowlisted = falseedit as custom control →Approved MCP servers
3 entries · patterns supported (* and ?)
| Server | Scope | Added by | Last matched | |
|---|---|---|---|---|
| github-mcp | global | mark | 12m ago | |
| linear-mcp | global | mark | 1h ago | |
| internal-docs-mcpsupport agents only | agent | jess | 3d ago | |
| you |
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| No exceptions — the policy applies everywhere. | ||||
Remediation shown on findings: Register the MCP server for review, or point the agent at an approved equivalent.