Skip to content
Permit.io Launches MCP Gateway to Address Security Gaps in AI Agent Operations

Permit.io Launches MCP Gateway to Address Security Gaps in AI Agent Operations

First seen 26 Mar 2026, 15:47 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 27, 2026 at 15:48 UTC
  • Permit.io launches MCP Gateway to enhance security for AI agents in enterprises.
  • OWASP ranks Shadow MCP Servers as a top-10 risk due to lack of authorization.
  • The MCP protocol has 97 million monthly SDK downloads, indicating rapid adoption.

Permit.io has launched the Permit MCP Gateway to address significant security gaps in the Management Control Protocol (MCP) used by AI agents in enterprise environments. These agents currently operate without fine-grained authorization, delegation tracking, or audit trails, leading to vulnerabilities. OWASP identifies Shadow MCP Servers as a top-10 risk, with incidents like Asana's data leak and a critical flaw in the mcp-remote npm package exposing unpatched systems to remote code execution. The MCP protocol has seen rapid adoption, with 97 million monthly SDK downloads, and is supported by major tech companies. The new gateway provides real-time authorization, tracks delegation chains, and ensures agents do not exceed granted permissions. It is available in both hosted SaaS and on-premises configurations. The launch comes amid growing concerns over the autonomous actions of AI agents without proper oversight.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 177d ago How this analysis works

Timeline

2025-12-01
Anthropic donates MCP protocol to the Linux Foundation.
2026-03-25
Permit.io announces launch of MCP Gateway.
2026-03-26
Permit.io's MCP Gateway officially launched.

More articles in this cluster (2)

Following this threat?

Track Asana in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed