Vibe Coding
mcp-airlock is a stateless governance proxy that sits in front of MCP servers with policy, dry-run and human confirmation
mcp-airlock (created 2026-09-13) targets the 2026-07-28 MCP spec and implements policy evaluation, dry-run, human confirmation, audit and tracing as a stateless proxy rather than as changes inside each server. Given that this week's CVE wave is almost entirely missing-boundary bugs in individual servers, a proxy that terminates policy once and fronts everything is the structurally right answer to a class of failure that keeps recurring per-server. It is early and small, so treat it as a design to copy more than a dependency to adopt.
Source
↳ Follow the thread