What happened
On Sept 30, 2026 Snyk made Govern Agent Behavior GA within Evo Agentic Development Security, starting with MCP Governance: discover MCP servers across the fleet, define approved-server policies, and log or block out-of-policy MCP usage at runtime across Claude Code, Cursor, Codex, and GitHub Copilot via lightweight local hooks (no proxy traffic rerouting).
Why it matters
Directly addresses the agent supply-chain risk where 1 in 12 developers with MCP installed has a confirmed high/critical finding; enforcement happens at the call site rather than after the fact, natively in the developer workflow.
Applicability
AppSec/platform engineering teams standardizing AI coding agents should evaluate Evo ADS MCP Governance for allowed-list enforcement; GA now across the four major coding-agent CLIs.