What's new
- Guardian now identifies the resource, credential and verb (read, write, delete) in MCP tool calls, so policy rules apply to them. Supported: Postgres, SQLite, filesystem, AWS, GitHub, Slack, Fetch, Firecrawl, Chrome DevTools, Playwright, Puppeteer and Claude in Chrome.
- guardian proxy status gives a fast view of the proxy's health in one command.
- Guardian Toolbar gets a Start Menu entry on Windows.
Bug fixes
- guardian hook install and guardian hook uninstall are removed — a hand-run install could race the daemon's own reconciler and break a working session, so hook installation now has exactly one source: the daemon.
- A credential dragged into a claude.ai chat is now scanned before it can reach Anthropic's servers.
- A Cursor check that can't finish now lets the command run, instead of blocking it.
- A machine could keep Guardian's proxy switched off locally even after the tenant turned it back on — fixed.
