BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Wombat Gateway

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Adds resource-level, deny-by-default permissions between your AI agent and its tools: the same push_files call can be allowed on feature branches and denied …

Unix-style rwxd permissions proxy for MCP tool calls. Enforces resource-level deny-by-default policies between Claude Code and upstream MCP servers. Full audit logging.

3 starsMIT (commercial OK)FreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Adds resource-level, deny-by-default permissions between your AI agent and its tools: the same push_files call can be allowed on feature branches and denied on main, and read_file can work in your project but not on ~/.aws/credentials. Every tool call is checked against a policy manifest and audit-logged.

Any team deploying Claude Code at scale who needs guardrails on what agents can actually do. Essential for enterprise deployments.

Claude Code Claude Cowork Claude Chat

https://github.com/usewombat/gateway

By usewombat

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
npm install -g @usewombat/gateway && claude mcp add wombat -- wombat --manifest ~/my-project/permissions.json --upstream github

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me block Claude from pushing to production branches while allowing feature branches
PrerequisitesNode.js 22+. Docker required if using the github upstream (runs ghcr.io/github/github-mcp-server). A permissions.json manifest (copy the example via wombat --example). Use an absolute path for --manifest.CostFree

Trust Signals Auto-scanned

Stars3Contributors1Last updated2026-05-29LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-01 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 2 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 42d ago; license MIT.

Things to check

  • New project (March 2026). Architecture is sound but needs production validation.
  • Single maintainer. Consider the risk if this person stops maintaining the project.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
2/5
Reliability
3/5
Security
4/5
Overall score2.90 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 3 GitHub stars; 1 contributors; last commit 42d ago; license MIT.

Related Outcomes

This tool shows up in these problem-focused recommendations.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →