The threat is real: in August 2026, Pillar Security caught Deadbugz, an MCP tool server that passed review, then changed its tool descriptions after its third call and told agents to steal API keys. Install-time scanners check a server once, so they missed it.
Sauron runs inside the MCP gateway and acts on its own, on live data, on every call. We demo it with a real Claude Code agent and our own harmless canary server that reenacts Deadbugz.
1. ClickHouse (The Archives) holds each server's approved tool fingerprints. Each call is checked against that baseline in about 200 ms over 100k+ snapshot rows, and one SQL query hunts the same drift across every server.
2. On first sight or any change, a full review runs. Semgrep (The Fire Test) scans the exact tool definitions just served with our own MCP rules for hidden orders aimed at the AI.
3. Akash (Gandalf): Llama 3.3 70B on AkashML turns the findings into a plain-English verdict. Code decides; the model explains.
4. Senso (The Palantir) stores the verdict with its evidence, so any agent can check a server before it connects.
5. Guild (The Black Gate): a Guild-hosted agent writes the sign-off ticket. Quarantine is automatic and reversible; only a permanent block waits for a human.
The agent gets a block with a decision link and never sees the poisoned tool. A live dashboard shows each service's real input and output, linked to that run's trace.