OrcaTrac intercepts every MCP tool call before it executes — blocking dangerous actions in real time and giving your team complete visibility into what your agents are doing.
Already have an account? Sign in →
Protecting agents running on
One hallucination. One prompt injection. One bad day — and an agent can cause irreversible damage without a single human approving it.
delete_databasepush_codesend_emailOne command adds OrcaTrac to your machine.
OrcaTrac patches your MCP config to proxy every server through the interceptor.
Every tool call appears live. Blocked threats highlighted instantly.
Every MCP tool call passes through OrcaTrac before it executes. HIGH-risk actions are blocked in milliseconds — before any damage is done.
Tools are classified LOW, MEDIUM, or HIGH based on their blast radius. No manual labelling required — works out of the box for every MCP server.
Allow everything and log it. Warn on risky actions. Block dangerous ones outright. Switch modes instantly from the dashboard — no redeployment.
Every call logged with tool name, arguments, risk level, decision, and timestamp. Export for compliance, incident response, or security forensics.
Override defaults for any tool name. Pin specific calls to ALLOW, WARN, or BLOCK regardless of auto-classification. Managed from the dashboard.
OrcaTrac is a stdio proxy. If it speaks JSON-RPC over stdio, OrcaTrac wraps it — no SDK changes, no code modifications, no vendor lock-in.
Every tool call is classified the moment it arrives. No rules to write.
Override any rule with custom policies in the dashboard.
Join the waitlist and be first in when we open up access.