From the source
Harvey built a Model Context Protocol (MCP) Policy Engine to govern how agents use partner MCP tools throughout a workflow, targeting tool poisoning and rug-pull attacks that can exfiltrate sensitive data.
The engine enforces runtime controls on tool access, information flow, and agent actions, with security reviews starting before the connection and assessing tool argument capacity and authority.






