AgentFence: A Local MCP Policy Firewall for AI Agent Tool Calls
Last Updated on August 19, 2026 by Editorial Team
Author(s): Diogo Santos
Originally published on Towards AI.
Your coding agent can now touch your filesystem, GitHub, and shell. AgentFence is a single Go binary that decides allow, deny, or ask before any of it runs — no cloud, no telemetry.
Your AI coding agent just asked to write a file. The path is .env. The content is OPENAI_API_KEY=sk-....

The article explains why tool-using AI agents pose real security risks—prompt injection, destructive actions, and secret leakage—and introduces AgentFence as a local, no-cloud “policy gate” that sits between an agent and its tools. It uses a YAML policy to decide on every tool call with deny-by-default behavior (allow/deny/ask) and provides reasons for each decision, plus constraints for specific paths, repos, URLs, shell commands, and memory writes. AgentFence runs either as an offline batch checker for CI (evaluating recorded tool calls) or as an MCP proxy that intercepts live MCP tool calls, supports approval flows for “ask” decisions, and can redact sensitive values before logging. The walkthrough covers how to validate/explain/test policies, how to wire AgentFence into an MCP client via proxy mode, and how to create an owned, tamper-evident audit trail that can be verified offline (optionally signed and with publishable anchors). It also stresses limitations—AgentFence is not a sandbox, shell command constraints are best-effort, tamper evidence detects after-the-fact issues rather than preventing full log rewriting, and taint tracking is heuristic—while concluding with takeaways and encouragement to try the demo and contribute feedback.
Read the full blog for free on Medium.
Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.
Published via Towards AI
Towards AI Academy
We Build Enterprise-Grade AI. We'll Teach You to Master It Too.
15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.
Start free — no commitment:
→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day
→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages
Our courses:
→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.
→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.
→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.
Note: Article content contains the views of the contributing authors and not Towards AI.