Every file an agent opens is content it did not write, arriving already inside the model. Subtext is zero trust file inspection: the same tools your agent calls today, with every byte of file content run through the engine before any of it is returned.
The enforcement is not a system prompt, a rule in the agent’s instructions, or a classifier the model consults. It is the tool itself. When the agent calls for a file, the bytes are read, inspected, and either returned or withheld. The model never gets a chance to decide.
The read and metadata tools carry the same names your agent already calls, so they go in as a replacement for the uninspected ones rather than as an addition. One entry in your MCP config, restart the client, done. Python standard library only: no package install and no build step. It is a client of the engine rather than a copy of it, so Subtext runs alongside it and has to be reachable.
Validated on Claude Code, OpenAI Codex, xAI Grok, GitHub Copilot, Microsoft VS Code Copilot and Google Antigravity, each on the same connector with no changes between them. Any client that speaks MCP over standard input and output should work, but those six are what we have tested. Tell us which one you run and we will tell you honestly whether it is on the list.
The same inspection core also runs as a proxy that sits in front of an MCP server you do not own, parsing the protocol frames and applying the same verdicts to whatever that server returns. Ask us about it if the connector you need to gate is somebody else’s.
Each one is an operator dial, not a fixed opinion. The policy lives in the engine, so a change applies to every consumer of it at once, and the tools honor that decision rather than second-guessing it. You set what each verdict does here, including whether a review verdict returns the file or refuses the read.
All four run against the same extracted content. A rule about file types is worth little if the file was never opened.
Injection is the one this boundary creates. The other three are policy you would want anywhere files move, enforced here as well.
Content has no direction. A payload arriving and a secret leaving are the same inspection. Here is exactly which tools inspect content and which do not, stated plainly so a demo does not imply coverage it does not have. The connector reads; it has no write tool.
Gateways in this space read the text of a response, and some also have a document path. As of August 2026, we have not found one that documents checking the declared type against the actual bytes, or failing closed on a format it cannot parse. Those two gaps are where the following live. Hover a card.
Same engine as the file and mail boundaries. The transport changed. The question did not.
Failing silently leaves the agent guessing. Rewriting the file destroys the evidence. Subtext returns something the model can read, marked as a tool error so the agent treats it as a failed read rather than as data, and names the file it refused.
Adding a security component should not add attack surface, and it should not add a second thing to keep in sync. We spend a good deal of time reporting bugs in other people’s MCP integrations, and the recurring ones are network-facing: a service bound wider than intended, a missing authentication check, an origin nobody validated. This opens no port, and it needs no list of approved paths to keep current.
Enforcement is only as complete as the tools it covers, and inspection is only as complete as what the content can show. Worth stating before you deploy it, not after.
Point it at a directory your agents already read, leave it in monitor mode, and let it record. It returns everything and logs a verdict for each file. Then decide what you want blocked.