ATALAIA
  1. Home
  2. Services
  3. Toolchain Hardening
04Station 04 · Build

Toolchain Hardening

The developer laptop is the first factory floor. We harden the IDEs, extensions, AI agents and MCP servers your team runs before code even exists.

Why it matters

“So a web page the agent reads could tell it to run commands as you.”

ATALAIA · step 2, Rank the exposure

A malicious extension or an over-trusted AI agent runs with the developer's keys, tokens and repos. It never touches your pipeline, so your pipeline controls never see it.

What you get

  • An inventory of extensions, agents and MCP servers in use
  • An allow-list and a review path for new tools
  • Scoped, short-lived credentials for local work
  • A local firewall and egress baseline for dev machines

Typical shape: Two to three weeks, then a light monthly check.

What each tool can reach

A slice of the inventory. The rows that light up across are the ones that get a gate first.

ToolReads codeHolds tokensRuns shellTalks to internetExposure
AI coding agent●yes●yes●yes●yesHigh
Database MCP server·no●yes·no●yesHigh
Docker extension·no●yes●yes●yesMedium
Git extension●yes●yes·no●yesMedium
Linter●yes·no·no·noLow
Colour theme·no·no·no·noLow

A morning on the dev floor

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Take the inventory

What runs on developer machines today, and with which permissions.

ATALAIAFirst, what runs on your laptops? Extensions, agents, MCP servers.

DEVELOPERI use an AI agent with a database MCP server. It saves me hours.

DEV LEADWe never listed any of it. Everyone installs their own.

Leaves the roomInventory: 41 extensions, 6 agents, 9 MCP servers

Step 2Rank the exposure

Which tools can read code, keys or tokens, and which talk to the internet.

ATALAIAThat MCP server holds a read-write token for the staging database.

DEVELOPERAnd the agent can run any shell command I can.

ATALAIASo a web page the agent reads could tell it to run commands as you.

Leaves the room3 tools can reach production keys

Step 3Set the gate

An allow-list, a review path and sane defaults for agents and MCP.

PLATFORMWe ship an allow-list. New extensions get a short review.

ATALAIAMCP tokens become read-only and expire daily. Shell commands need a confirm.

DEVELOPERFine, as long as a review takes a day, not a month.

Leaves the roomAllow-list, review path, scoped tokens

Step 4Keep it current

Telemetry and a monthly review so the list doesn't rot.

ATALAIATelemetry lists what's installed. We review the new ones every month.

DEV LEADAnd the local firewall blocks unknown traffic from dev machines.

Leaves the roomMonthly review, telemetry on

  • ATALAIA
  • DEV LEAD
  • DEVELOPER
  • DEVELOPER 2
  • DEVELOPER 3
  • PLATFORM

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.