Cursor Auto-review ships for Shell and MCP approvals
Cursor 3.6 Auto-review Run Mode routes Shell, MCP, and Fetch calls through allowlists, sandboxing, classifier review, and user approval.
Cursor 3.6 Auto-review Run Mode routes Shell, MCP, and Fetch calls through allowlists, sandboxing, classifier review, and user approval.
Trust3 AI’s agent discovery guide frames shadow agents, MCP bindings, runtime traffic, and ownership as an inventory problem for AI governance.
TrustLogix TrustAI moves AI agent control to the data layer with MCP governance, intent-based authorization, and a runtime kill switch.
Cursor and Endor Labs formalized a hooks-based security partnership for agentic coding, blocking package installs, MCP use, and risky commands inside the IDE loop.
NSA published MCP security design guidance for AI-driven automation, turning tool permissions, tokens, logs, sandboxing, DLP, and scans into deployment requirements.
Google Pay and Wallet now expose an MCP server for docs, account status, pass validation, error metrics, and merchant integration workflows.
Anthropic added self-hosted sandboxes and MCP tunnels to Claude Managed Agents, shifting tool execution and private tool access into enterprise-controlled boundaries.
Google released a Chrome Enterprise Premium MCP server that exposes DLP rules, connector policy, browser telemetry, and activity logs to AI agents.
Robinhood opened Trading MCP and Banking MCP for AI agents. The real developer story is the permission, approval, and liability model around financial tool calls.
OpenAI Secure MCP Tunnel gives ChatGPT, Codex, Responses API, and AgentKit an outbound-only path to private MCP servers without public endpoints.
OpenAI Agents SDK memory and the AMP v0.1 draft turn long-term agent memory into files, Git history, MCP resources, and auditable state.
Reo.Dev Agent Intent Gateway shows how developer product evaluation is moving from docs clicks to AI agent queries and MCP calls.