Harvey Announces MCP Policy Engine for Legal AI Security
The system adds runtime controls for tool access, information flows and agent actions while addressing prompt injection and tool-poisoning risks.

Harvey announced the development of a Model Context Protocol policy engine to control tool access, information flows and agent actions across legal workflows, addressing security risks as AI systems connect with external tools and data.
The MCP Policy Engine adds runtime controls to Harvey’s platform and is designed to address prompt injection, tool poisoning and malicious changes to approved tools, a scenario sometimes called a rug-pull attack.
The system uses least-privilege restrictions, complete mediation of tool actions and information-flow controls. Its Tool Pinner tracks approved tools and flags changes for monitoring.
A separate Sanitizer feature removes hidden characters and potentially malicious instructions from tool results before they reach an AI agent. The controls are intended for workflows including contract analysis, due diligence and compliance.
The Model Context Protocol is a standard that allows AI systems to discover and use external tools. MCP increases the capabilities of AI agents while expanding their security exposure. MCP has also been used to provide AI agents with dataset access.
Harvey has more than 3,000 customers in more than 70 countries. The company is exploring automated policy creation, program analysis of agent behavior and formalized controls as it continues developing its security systems.