MCP Scanning vs Runtime Enforcement
Fact review observed 2026-08-09 · source review expires 2026-09-08 · content version 1.0.0
MCP security can include pre-connection review of configuration and server/tool metadata plus policy at runtime tool-call boundaries. HOL Guard’s published support contract includes MCP configuration and managed MCP calls on supported surfaces, but coverage remains harness- and event-specific. A scanner, configuration review, native permission prompt, and runtime policy boundary can be complementary rather than interchangeable.
Comparison facts are reviewed by HOL Guard Research. Named vendor facts expire after the current review window rather than being assumed unchanged.
Corrections are triaged within 7 calendar days. Report a correction.
Evaluate MCP controls by what they inspect, when they decide, which transports and harnesses they cover, how they fail, and whether they can stop a consequential action. Avoid reducing the category to a universal “scanner versus runtime” split because products and transports can span more than one point in the lifecycle.
Best fit
- Teams using MCP servers with AI coding agents
- Security teams deciding between scanning and enforcement
- Developers who want both preventive and reactive controls
Not a fit
- Teams not using MCP servers
- Teams that only need post-incident forensics
Primary sources
Limitations
- This guide compares approaches, not specific scanner products.
- Scanner capabilities vary by implementation; check each tool’s documentation.
Related
Gap decision: GAP-DEC-002 · Neutrality review: NEUTRALITY-002
Fact-audit changelog: 2026-08-09 reviewed named-product and product-coverage wording against current primary sources and the Guard support contract.
Gap prioritization may originate from fixture-derived analysis; it is not represented as a live search-engine observation.
- Author
- HOL Guard Team
- Technical reviewer
- HOL Guard Team
- Reviewed
- Content version
- 1.0.0
- Buyer prompt
- GAE-005: secure MCP servers in Codex
- Next rescan
Changelog
- v1.0.0 — Initial publication.