# Harvey — Building Harvey’s MCP Policy Engine

- Company: Harvey (harvey.ai)
- Announced: 2026-10-07T14:00:00+00:00
- Category: capability-change
- Coverage: not counted
- Announcement: no
- Group: routine
- Source: https://www.harvey.ai/blog/building-harveys-mcp-policy-engine
- Record: https://forck.live/items/17515-building-harvey-s-mcp-policy-engine
- Subject: Harvey

Harvey built a Model Context Protocol (MCP) Policy Engine to govern how agents use partner MCP tools throughout a workflow, targeting tool poisoning and rug-pull attacks that can exfiltrate sensitive data. The engine enforces runtime controls on tool access, information flow, and agent actions, with security reviews starting before the connection and assessing tool argument capacity and authority.

## Evidence

Verbatim from https://www.harvey.ai/blog/building-harveys-mcp-policy-engine:

> Our policy engine targets two particularly persistent threats that are harder to mitigate using existing tools. Both can exploit the lethal trifecta to exfiltrate sensitive data. In a tool poisoning attack, malicious instructions embedded in a tool's definition redirect the agent's behavior. In a rug-pull attack, a server introduces malicious changes after it has been approved, exploiting the trust placed in a previously reviewed tool.

---

Record: https://forck.live/items/17515-building-harvey-s-mcp-policy-engine
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
