Armour
A secure stdio MCP proxy, written in Go
Details
- External ID
- 46696348
- Source
- HN
- Company
- —
- Product
- Armour
- Website domain
- github.com
- Launched
- Jan. 20, 2026
- Cohort
- —
- Upvotes
- 23
- Upvotes percentile
- 0.6732542819499341
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
At my last company, we connected Claude Code and Cursor to almost all our internal services via MCP. It made the team incredibly fast, but we hit a wall: permissions.If you give an agent "Read Only" access, it can’t actually fix anything. If you give it "Write" access, it’s only a matter of time before a hallucination or a bad prompt results in a deleted database or a nuked production bucket. We had a few "close calls" that convinced us that simply reducing IAM permissions makes agents useless.I built Armour (https://github.com/fuushyn/armour) to solve this. It’s a stdio proxy for MCP servers that lets you stay "secure by default" without stripping the agent's capabilities.How it works: Instead of connecting your IDE directly to an MCP server, you point it to Armour. It acts as a middleware layer where you can:Register all tools in one place: A single proxy for all your internal MCPs.Argument-level blocking: This is the core feature. You can allow an agent to use a tool like github, but block specific arguments like delete.The goal is to move away from the "all-or-nothing" permission model. You should be able to trust an agent with a shell without worrying it will run rm -rf /.Repo - https://github.com/fuushyn/armour
Enrichment
- Theme
- Claude integrations and coding agents
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- secure proxy for model context protocol stdio
- Manually corrected
- False
Could you build this?
Partial The basic proxy server wrapping stdio is simple, but reliable security enforcement and protocol-level granular permission filtering across arbitrary MCP tools require deep OS and systems security engineering.
What it would actually take: Written in Go, the tool acts as a stdio middleware multiplexing JSON-RPC 2.0 messages between MCP clients and servers. The hard part is implementing declarative policy rules, AST parsing of commands, and deterministic security boundaries without breaking tool calling semantics across heterogeneous tool suites.
Discussion
6 comments analyzed.
Competitors mentioned: Keypost.ai (policy enforcement and rate limiting), stdio MCP proxy (argument-level blocking)
Concerns raised: Rule composition complexity with multiple constraints, Read-only permissions making agents too restrictive, Write access creating unacceptable risk
Feature requests: Stateful rules (rate limits, quotas) beyond argument pattern matching, Support for complex conditional rules (e.g., resource-specific access with time-based constraints)
Competitors
Other products that read as similar to this one — 230 launches clear the similarity bar, closest 8 shown.
Attention rank: #82 of 231 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 69 days after the earliest competitor.
- SentinelAgent Guard · ph · 2026-09-23 · 2 upvotes · similarity 0.52
- Buddy AI Access (MCP) · ph · 2026-09-15 · 99 upvotes · similarity 0.48
- GuardiAgent · hn · 2025-11-21 · 9 upvotes · similarity 0.48
- Authorize MCP tool calls without giving agents the credentials · hn · 2026-09-14 · 7 upvotes · similarity 0.48
- A context-aware permission guard for Claude Code · hn · 2026-03-11 · 127 upvotes · similarity 0.45
- Risk Analysis Database of Every MCP Server · hn · 2026-02-05 · 22 upvotes · similarity 0.44
- I built a smart proxy so your coding agent can run loose · hn · 2026-07-14 · 14 upvotes · similarity 0.44
- MCP Mesh · hn · 2025-12-30 · 8 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.