Cup'n'String
Join Waitlist

© 2026 Cup'n'String

MCP Security

Secure Claude Desktop and Its MCP Servers

Claude Desktop connects to Model Context Protocol servers that can read files and execute commands. Cup’n’String proxies that MCP activity, auditing file reads and terminal executions while safeguarding local API keys.

Support levelActive Proxy & Shielding
CategoryAI Coding Agents
Governance capabilities
AttributeOutbound policyAuditBlockRedactShield secrets

What Cup’n’String controls

Discover Claude Desktop and its configured MCP servers
Apply policy and tool allowlists to MCP activity
Detect risky tool calls and outbound destinations
Shield credentials and sensitive files
Route approved access through the control plane
Record audit evidence of MCP tool usage
Enforce host firewall controls where applicable

Common risks

MCP servers configured in Claude Desktop extend what the assistant can do on the workstation.

MCP tools can read files and run commands
Filesystem and shell exposure to the assistant
Local services reachable via tools
Direct provider API egress
Unmanaged MCP servers are hard to inventory
Lack of centralized audit

How it works

  1. Step 1Install / enroll the Cup’n’String Desktop Agent
  2. Step 2Discover local resources
  3. Step 3Classify environment / resource type
  4. Step 4Apply tenant policy
  5. Step 5Enforce allowed / blocked behavior
  6. Step 6Capture audit evidence
  7. Step 7Expose approved services through controlled access when needed

Recommended policies

Allow only approved MCP servers
Allowlist specific MCP tools
Block direct access to secrets
Restrict filesystem and shell scope
Log all model endpoint calls
Require approval for new MCP servers
Deny unknown local services by default

Frequently asked questions

Can Cup’n’String detect Claude Desktop automatically?
Yes. It is detected via the app process and MCP server configuration, and governed through Active Proxy & Shielding (macOS and Windows).
Can MCP tools be allowlisted?
Yes. Where MCP activity is routed through supported paths, tool allowlists and policy can constrain what the assistant invokes.
Does this replace Claude Desktop?
No. It governs MCP activity; the app keeps working.
Can this work self-hosted?
Yes.
Can MCP activity be audited?
Yes. Tool usage routed through supported paths can be recorded.

Govern Claude Desktop with Cup’n’String

Discover the environment, apply policy, shield credentials, and capture audit evidence.

Related pages