Creator here 👋 I built MCPProxy because I wanted tool discovery without giving agents every tool at once. New servers stay quarantined until you approve them. Thanks for sharing, Daniel.
Your agent doesn’t need 200 MCP tools in its context window.
MCPProxy is a Go-based MCP gateway for builders connecting AI agents to multiple MCP servers.
It helps you keep tool access manageable by searching across connected servers and returning only the relevant tools, instead of loading every schema at once.
Key features:
• Tool discovery – search connected servers with `retrieve_tools` and load full schemas only when needed
• Intent-aware calls – use read, write, or destructive call variants, with intent checked against tool annotations
• Server quarantine – keep new servers blocked until you manually approve them
• Activity log – record calls locally with request IDs for later review
• Single-binary deployment – run the core on macOS, Linux, or Windows with the web UI embedded
It’s open-source (MIT license).
Link in the reply 👇
@sunsetsyntax exactly, the description is the prompt nobody reviews. it also re-flags a tool if its description changes later, so an approved tool can't quietly flip
@cloneismin yep, that's the part I like most, one place to see what each agent can touch. agent tokens let u scope it per client too, e.g. read-only for one agent
I had 4 MCP servers × 9 AI clients — that's 36 config entries to keep in sync by hand. I built MCPProxy to fix it: register each server once, every client connects through one endpoint. Runs on your machine, open source (MIT). #MCP
An MCP tool description can hide instructions your agent follows and you never see. I built MCPProxy to catch that: new servers get quarantined on arrival and scanned before any tool runs. Runs on your machine, open source (MIT). #MCP
@htekdev State machines + event queues solve most of this. The real nightmare is debugging when agent A fails silently and agent B waits forever. Circuit breakers and timeouts are your friends.
@svpino the DCR to CIMD shift is huge. DCR was a non-starter for any serious deployment because it required servers to trust arbitrary client registrations
@bcherny the multi-tool orchestration is where it gets magical. how many tools does that setup load into context? with slack + bigquery + sentry MCPs that's probably 80+ tool definitions per session. curious if tool search keeps it manageable or if you need more aggressive filtering
@ZackKorman@_JohnHammond the scariest part is tool description poisoning - a malicious MCP server can inject instructions into the tool description that manipulate the agent's reasoning
@omarsar0 smart approach. the key insight is tool selection should happen before definitions enter context, not after the LLM has already consumed them all
#lottery open ML course https://t.co/0QYcf8q23o is considerably updated, pls. check it out. The pack of Bonus Assignments is offered at a 50% discount https://t.co/85wK9h9KJz and you have a chance to get it for free if you retweet this. 17 lucky ones per week till the end of Feb.