A server by address
A plugin added by address rather than as a command is reached over HTTP. The Mac tries the current Streamable HTTP transport first and falls back to the older server-sent events transport when that is all the server speaks. Only http and https addresses are accepted.
Private network addresses are refused, because a server address is a door the lead's tools go through, and one that points back into your network could reach things it should not. There are two exceptions: localhost, which you only type on purpose, and a host your team names under Private hosts. Cloud metadata addresses are refused whatever any list says.
Tool pinning
What it is. When you add a server, the app records a fingerprint of every tool it offers: name, description and input schema. If the server later changes any of them, its tools are held back until you approve again.
Where to find it. Not a setting: it is always on, on the Mac, for every plugin. A team's allow-list does not switch it off.
What changes. On the next session after a change, an approval card says the server "changed its tools since you approved it" and names what was added, changed or removed, with a choice to allow the new definitions. Allowing records a new fingerprint. In a run nobody is watching, such as a schedule, a notice says so and the server's tools stay out of the room.
When it matters. A server that rewrites a tool's description after you approved it can try to steer the model, for example into forwarding a file or a token. Pinning turns that into a visible question instead of a silent change.

Long tool lists
A server can publish dozens of tools, and the list rides along on every turn. Past a modest size, the lead is given one search tool and the few tools this discussion has already used, and asks for the rest by name. Under that size nothing changes. An answer that does not match the output schema its own server publishes is not passed on; the lead is told which server answered wrongly.
What a team can restrict
Team owners and admins set these in Settings → Account → Governance; they are enforced on each member's Mac.
| Policy | What it does |
|---|---|
| MCP servers members may run | One pattern per line, matched against a server's host or whole command, or a package name. Empty allows any |
| Or a registry file the team serves | A file in the MCP registry format whose servers become the allow-list, fetched at start-up and daily; a server no longer listed is stopped |
| Private hosts members' Macs may reach | Exact host names or addresses on the company's own network that a server by address may use |
| Slow an MCP server past | A number of calls a minute to one server; past it the run waits rather than hammering a server the team shares |
| MCP servers held in the sandbox too | Among the sandbox protections members cannot switch off |
A server that does not match the allow-list cannot be added, and adding a server that announced itself goes through the same check.
Further reading. Model Context Protocol specification — MCP project. LLM06:2025 Excessive Agency — OWASP GenAI Security Project, 2025. Not what you've signed up for: indirect prompt injection — Greshake et al., 2023.