Wombat Gateway
Adds resource-level, deny-by-default permissions between your AI agent and its tools: the same push_files call can be allowed on feature branches and denied …
Unix-style rwxd permissions proxy for MCP tool calls. Enforces resource-level deny-by-default policies between Claude Code and upstream MCP servers. Full audit logging.
- Block Claude from pushing to production branches while allowing feature branches
- Enforce read-only access to sensitive config files
- Audit every MCP tool call with structured logging for compliance
Adds resource-level, deny-by-default permissions between your AI agent and its tools: the same push_files call can be allowed on feature branches and denied on main, and read_file can work in your project but not on ~/.aws/credentials. Every tool call is checked against a policy manifest and audit-logged.
Any team deploying Claude Code at scale who needs guardrails on what agents can actually do. Essential for enterprise deployments.
https://github.com/usewombat/gateway
By usewombat
How to Get It
npm install -g @usewombat/gateway && claude mcp add wombat -- wombat --manifest ~/my-project/permissions.json --upstream github
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Once it’s connected, paste this into Claude:
Help me block Claude from pushing to production branches while allowing feature branches
Trust Signals Auto-scanned
Data & Access
Community Pulse Active
Discussed on Hacker News, Reddit
- Europe opens its ‘first gateway office’ to fast-track hiring in India — Reddit · 5277 pts
- The gateway tapes have given me psychic abilities — Reddit · 1208 pts
- Guacamole – A clientless remote desktop gateway — Hacker News · 1096 pts
3 mentions across 2 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 42d ago; license MIT.
Things to check
- New project (March 2026). Architecture is sound but needs production validation.
- Single maintainer. Consider the risk if this person stops maintaining the project.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 42d ago; license MIT.
Related Outcomes
This tool shows up in these problem-focused recommendations.