heddle
Heddle — The policy-and-trust layer for MCP tool servers. Turn YAML configs into validated, policy-enforced MCP tools.
- Restrict database query tools to read-only access by role
- Enforce approval workflows before sensitive API calls execute
- Audit and log all tool invocations for compliance reporting
Enforces governance and access controls on MCP tool servers, reducing security risk and compliance violations when deploying AI-driven tooling across teams without manual policy management.
Platform engineers and security teams implementing MCP tool servers with fine-grained permission requirements.
https://github.com/goweft/heddle
By goweft
How to Get It
claude plugins install goweft/heddle
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Trust Signals Auto-scanned
Community Pulse Emerging
Discussed on Reddit
1 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
Auto-assessment from April sweep — baseline scores pending hands-on review.
2026-04-18: Approved in April sweep: New and small but has a clear description and recent commits — worth tracking.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.