Governed MCP gateway: approval gates, signed audit receipts, and cost control for agent tool calls.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Governed MCP gateway: approval gates, signed audit receipts, and cost control for agent tool calls.