TraceCtrlTraceCtrl

ENVIRONMENTS · DESKTOP AGENTS

An agent with your engineer’s
keys to production.

Coding agents run on developer machines with the developer’s full privileges — repos, credentials, cloud CLIs. TraceCtrl sees which agents and MCP servers are running, what they can reach, and stops the tool call that shouldn’t happen.

  • Claude Code
  • Cursor
  • GitHub Copilot
  • Codex
  • Windsurf
  • MCP servers
AGENTIC ENDPOINT

dev-machine-047 · senior engineer

2 agents · 5 MCP servers · 1 unapproved

GUARD IN PATH
DEVELOPER MACHINEingestsinvokesinvokes · unapproved
Coding agent
Cursor · dev-machine-047
.env · AWS_SECRET_KEY
in project root
MCP · GitHub
allowlisted
MCP · web-fetch
unapproved
External endpoint
egress target
BLOCKEDcredential egress via unapproved MCP
AgentIdentity / ownerTool
CRITICALSecret in agent context + unapproved MCP server = exfil path · stopped in-path

The endpoint is the new agent perimeter.

.env in repo + agent reads project root + web tool

Credentials walk out in context

Cloud keys ingested into agent context are one poisoned instruction away from leaving the machine.

unapproved MCP server + broad tool grants + no allowlist

Supply chain, but for tools

A developer adds an MCP server from a gist; it now sits inside every session, shadowing legitimate tools.

agent = user identity + prod CLI access + yolo mode

Machine-speed actions, human blame

Every destructive action logs as the engineer. Without agent-level tracing you can't tell who — or what — did it.

HOW TRACECTRL COVERS DESKTOP AGENTS

Know what’s running on every dev machine.