IDEAS CONECTADAS

Atlas de conocimiento

Explora personas, perspectivas y sus fuentes originales.

1 personas · 1 fuentes · 1 opiniones expresadas

EN CONTEXTO

MCP connector approval

Elige una perspectiva y vuelve a la conversación original.

MCP connectors require vendor-submitted tool specs and per-tool security review

EN CONTEXTOMCP connector approval1 opiniones expresadas
2026-10-01

Los sectores iguales orientan la lectura, no indican una clasificación.

Perspectivas 1–1 de 1 · Fuentes más recientes primero

1 / 1

Perspectiva seleccionada

MCP connectors require vendor-submitted tool specs and per-tool security review

For MCP connectors—where the vendor operates the server—Harvey requires the vendor to submit its full tool list, capability scope, hosting and auth details, data-processing regions, and test credentials; the security team then reviews each tool individually, approves or rejects it, assigns a risk level, and records decisions in a code-shipped registry.

Estas son perspectivas individuales, no una medida de consenso. El material fuente permanece en su idioma original.

Evidencia a favor

How We Built Harvey’s Connector Library

Extracto original

An MCP member's server is operated by the vendor, so the review has to judge a system someone else runs, and it gets an extra layer of admission. The vendor submits its full tool list and capability scope, hosting and auth details, data-processing regions, and test credentials, and the security team reviews the tools one by one, deciding for each whether it is approved and assigning its risk level.
Contexto

A native member is a wrapper we wrote around the vendor's API, and it goes through the same security review: which of the vendor's APIs we call and which scopes we request are what the security team signs off on. This way, approval is a hard gate before engineering integration begins. Those decisions land in a registry that ships with the code: a structured URL matcher, the vendor's full advertised tool list, the subset that may be invoked, and a hand-written risk and capability annotation for each.

Las fechas corresponden a las fuentes, no a cambios de opinión. Los textos sin traducción revisada se mantienen en su idioma original.