August 4, 2026
Receipts, secrets, and a ghosted comment
Show HN: cMCP, deny an AI agent's tool call and get a signed receipt
This AI babysitter promises proof when it says no — but the comments got weird fast
TLDR: cMCP is selling itself as a way to stop AI assistants from making risky app calls and to produce proof of what was blocked. The community reaction was less hype than confusion, with one commenter pointing out a vanished explanation and another rushing in with a simpler guide.
A new project called cMCP just rolled onto Show HN with a big promise: if an AI tries to use a tool it shouldn’t, this system can block it and hand you a signed receipt showing what happened. In plain English, it’s pitching itself as a security guard for AI helpers — especially the kind that can poke around apps like Salesforce or Snowflake and potentially spill sensitive customer data. The flashy part is that it claims this guard runs in a locked-down hardware safe, so even the system operator allegedly can’t quietly tamper with the rules after the fact.
But in classic internet fashion, the comment drama instantly became the real show. One of the first visible reactions wasn’t even about the product — it was a baffled complaint that the creator’s explanation had already been flagged and buried. That gave the thread an immediate whiff of mystery, with readers left wondering whether the most useful plain-English explanation had been swallowed by moderation before anyone could judge it. Another comment swooped in with a rescue link to a quickstart, basically saying: if the main post sounds like a wall of security buzzwords, here’s the easier version.
So the mood was less “everyone is cheering” and more “wait, what exactly is this, and why is the explanation dead?” The hottest subtext wasn’t a full-on war — it was confusion, suspicion, and that very online comedy where a tool meant to create trust kicked off by making people ask whether they could even trust the thread explaining it.
Key Points
- •cMCP is presented as an open-source gateway that enforces MCP tool-call policy inside a hardware Trusted Execution Environment.
- •The runtime evaluates each tool call against a Cedar policy bundle and can allow, deny, or redact requests.
- •The article argues software-only MCP governance cannot reliably prove policy integrity, in-memory decision integrity, or audit-log authenticity.
- •Each session produces a signed TRACE Claim, hardware-attested in TEE mode and signed-only in software mode, for independent verification.
- •The project is in Developer Preview, launched June 23, 2026, and includes a quick-start path that can run in software mode without hardware.