# Protect MCP servers

Wrap existing MCP servers with zn automatically (init) or one by one (shield).

Source: https://usezn.com/docs/zn-gate/shield/

## Automatic: `zn-gate init`

`init` finds the MCP configuration of supported environments (Claude Desktop, Claude Code, Cursor, Antigravity, Codex, OpenCode and others), backs it up and wraps each server with zn.

```bash
# Preview what would change
npx -y zn-gate init --dry-run

# Apply, in non-blocking shadow mode first (log only, nothing dropped)
npx -y zn-gate init --shadow

# Enforce
npx -y zn-gate init

# Restore the original configs from the backups
npx -y zn-gate init --revert
```

Start with `--shadow`, review the logs (`npx -y zn-gate logs`), then enforce.

## One server: `zn-gate shield`

Put zn in front of any MCP server command. zn inspects outgoing tool arguments, sanitizes tool results and checks `tools/list` descriptions for poisoned instructions:

```bash
npx -y zn-gate shield -- uvx mcp-server-fetch
npx -y zn-gate shield -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/db
```

In a client config, replace the server command with `npx` and prefix the original arguments with `-y zn-gate shield --`.

## Keep tool access narrow

zn stops hostile input; it does not decide which tools an agent should have. After wrapping, review each server and keep only the tools your agent needs. Put destructive operations behind explicit approval.
