PENSÉES EN RELATION

Atlas des connaissances

Explorez les personnes, leurs points de vue et les sources originales.

1 personnes · 1 sources · 1 opinions exprimées

EN CONTEXTE

MCP connector approval

Choisissez un point de vue et retrouvez la conversation originale.

MCP connectors require vendor-submitted tool specs and per-tool security review

EN CONTEXTEMCP connector approval1 opinions exprimées
2026-10-01

Les secteurs égaux servent de repères, pas de classement.

Points de vue 1–1 sur 1 · Sources les plus récentes en premier

1 / 1

Point de vue sélectionné

MCP connectors require vendor-submitted tool specs and per-tool security review

For MCP connectors—where the vendor operates the server—Harvey requires the vendor to submit its full tool list, capability scope, hosting and auth details, data-processing regions, and test credentials; the security team then reviews each tool individually, approves or rejects it, assigns a risk level, and records decisions in a code-shipped registry.

Il s’agit de points de vue individuels, non d’une mesure du consensus. Le matériel source reste dans sa langue d’origine.

Éléments favorables

How We Built Harvey’s Connector Library

Extrait original

An MCP member's server is operated by the vendor, so the review has to judge a system someone else runs, and it gets an extra layer of admission. The vendor submits its full tool list and capability scope, hosting and auth details, data-processing regions, and test credentials, and the security team reviews the tools one by one, deciding for each whether it is approved and assigning its risk level.
Contexte

A native member is a wrapper we wrote around the vendor's API, and it goes through the same security review: which of the vendor's APIs we call and which scopes we request are what the security team signs off on. This way, approval is a hard gate before engineering integration begins. Those decisions land in a registry that ships with the code: a structured URL matcher, the vendor's full advertised tool list, the subset that may be invoked, and a hand-written risk and capability annotation for each.

Les dates concernent les sources, pas des changements d’opinion. Les textes sans traduction révisée restent dans leur langue originale.