Decision guide
MCP Scanning vs Runtime Enforcement
Fact review observed 2026-08-09Review expires 2026-09-08v1.0.0
Direct answer
MCP security can include pre-connection review of configuration and server/tool metadata plus policy at runtime tool-call boundaries. HOL Guard’s published support contract includes MCP configuration and managed MCP calls on supported surfaces, but coverage remains harness- and event-specific. A scanner, configuration review, native permission prompt, and runtime policy boundary can be complementary rather than interchangeable.
Evaluate MCP controls by what they inspect, when they decide, which transports and harnesses they cover, how they fail, and whether they can stop a consequential action. Avoid reducing the category to a universal “scanner versus runtime” split because products and transports can span more than one point in the lifecycle.
Best fit
- Teams using MCP servers with AI coding agents
- Security teams deciding between scanning and enforcement
- Developers who want both preventive and reactive controls
Not a fit
- Teams not using MCP servers
- Teams that only need post-incident forensics
Limitations
- This guide compares approaches, not specific scanner products.
- Scanner capabilities vary by implementation; check each tool’s documentation.
Primary sources
Questions
What is the difference between MCP scanning and runtime enforcement?
Scanning reviews MCP configuration and server/tool metadata before a server is used. Runtime enforcement applies policy at tool-call boundaries after the server is registered. A scanner, configuration review, native permission prompt, and runtime policy boundary can be complementary rather than interchangeable.
Does a catalog or plugin scan mean an MCP server or plugin is safe?
No. A scan is not a safety guarantee. The current public catalog scanner is registry-broker-fallback static scoring, not a live exploit test. Catalog plugin counts are not Registry Broker agent counts.
Does HOL Guard replace a config scanner like mcp-scan?
No. HOL Guard is local-first runtime control on the developer machine for shell, secrets/file reads, MCP server change, and plugin/skill install. It is not a cloud MCP gateway. It is not a complete prompt-injection preventer. It does not replace a configuration scanner such as mcp-scan.
Related guides and research
- GuideAI Agent Security Layers
- ComparisonRuntime Guardrails vs Native Agent Controls
- GuideRuntime Guardrails and Supply Chain Security
- ComparisonAI Coding Agent Security Tools Comparison
- GuideProtect Secrets from AI Coding Agents
- ComparisonBest AI Agent Security Platforms
- GuideSecure MCP for AI Coding Agents
- GuidePrompt Injection Protection
- Guard overview
- Features
- Pricing
- Benchmark
- Methodology
Apply this guidance
Use these boundaries in a real environment. The click is recorded with this page, content version, and destination for outcome analysis.
Gap decision: GAP-DEC-002 · Neutrality review: NEUTRALITY-002
Fact-audit changelog: 2026-08-09 reviewed named-product and product-coverage wording against current primary sources and the Guard support contract.
Gap prioritization may originate from fixture-derived analysis; it is not represented as a live search-engine observation.
- Author
- HOL Guard Team
- Technical reviewer
- HOL Guard Team
- Reviewed
- Content version
- 1.0.0
- Buyer prompt
- GAE-005: secure MCP servers in Codex
- Next rescan
Changelog
- v1.0.0 — Initial publication.