VERNETZTES DENKEN

Wissensatlas

Personen, Standpunkte und ihre Originalbelege erkunden.

1 Personen · 1 Quellen · 1 geäußerte Meinungen

IM KONTEXT

MCP connector approval

Einen Standpunkt auswählen und das Originalgespräch nachverfolgen.

MCP connectors require vendor-submitted tool specs and per-tool security review

IM KONTEXTMCP connector approval1 ausgedrückte Meinungen
2026-10-01

Gleich große Sektoren dienen der Orientierung, nicht der Rangfolge.

Standpunkte 1–1 von 1 · Neueste Quellen zuerst

1 / 1

Ausgewählter Standpunkt

MCP connectors require vendor-submitted tool specs and per-tool security review

For MCP connectors—where the vendor operates the server—Harvey requires the vendor to submit its full tool list, capability scope, hosting and auth details, data-processing regions, and test credentials; the security team then reviews each tool individually, approves or rejects it, assigns a risk level, and records decisions in a code-shipped registry.

Dies sind individuelle Standpunkte, keine Messung einer Übereinstimmung. Das Quellenmaterial bleibt in der Originalsprache.

Stützende Belege

How We Built Harvey’s Connector Library

Originalauszug

An MCP member's server is operated by the vendor, so the review has to judge a system someone else runs, and it gets an extra layer of admission. The vendor submits its full tool list and capability scope, hosting and auth details, data-processing regions, and test credentials, and the security team reviews the tools one by one, deciding for each whether it is approved and assigning its risk level.
Kontext

A native member is a wrapper we wrote around the vendor's API, and it goes through the same security review: which of the vendor's APIs we call and which scopes we request are what the security team signs off on. This way, approval is a hard gate before engineering integration begins. Those decisions land in a registry that ships with the code: a structured URL matcher, the vendor's full advertised tool list, the subset that may be invoked, and a hand-written risk and capability annotation for each.

Die Daten beziehen sich auf Quellen, nicht auf Änderungen der Überzeugung. Texte ohne geprüfte Übersetzung bleiben in ihrer Originalsprache.