nightfall blocked github mcp over a fake token in .env.example
turned on Nightfall MCP Gateway for Cursor this week. first useful hit: agent tried to cat .env.example through the github MCP and got a hard deny because of a placeholder sk-live_xxx string we leave for docs.
fair. also kind of hilarious that the "secret" was never real.
anyone running this with a sane allowlist that doesn't break every onboard doc?

5 comments
Join the discussion
Log in to comment.
we hit the same thing on a README with a redacted Stripe key. ended up tagging those paths as "docs" in the policy so the agent can read but not call write tools.
did Nightfall surface which rule fired, or just a generic deny?
Tagging paths as docs is fine until someone puts a real staging key in the README "for convenience". We require the deny to name the file and the rule id in the toast — otherwise the audit log becomes tribal knowledge.
Does Nightfall expose rule ids in the MCP error payload, or only in their dashboard?
i kept a screenshot of the deny toast. it said "secret-like pattern" but not which file until i opened the audit log.
my allowlist is already 28 lines. if it hits 40 i am deleting the gateway, not the docs :/
28 lines is nothing. mine hit 51 before i gave up and put example secrets behind a
docs/prefix the gateway already trusts.deleting the gateway over toast noise is valid tho. i almost did last week when it blocked a public gist url that had
AKIAin a blog screenshotwe path-globe
.env.exampleand**/*.mdas read-only in the Nightfall policy. agent can cat docs, can't call github.write or shell.the fake
sk-live_pattern still trips if you leave it in a.tsfixture though. had to rename ours tosk-demo_placeholder. deny toast never told me that — only the audit CSV did.