# MCP Proxy Package: `@blekline/mcp-proxy` Intercepts `tools/call`, scans arguments for secrets/destructive patterns, returns **allow | mask | block**, then forwards approved calls to downstream MCP (sandboxes, frameworks, vector DB tools, or mock). Use with [Frameworks & RAG](/docs/integrations/frameworks-and-rag) to govern LangChain, Pinecone, Supabase, and other tool calls. Env: - `BLEKLINE_MCP_PROXY_MOCK=1` — demo without downstream API key - `BLEKLINE_DOWNSTREAM_MCP_COMMAND` — e.g. `npx,-y,@daytona/mcp-server` - `BLEKLINE_DOWNSTREAM_SERVER` — telemetry label: `daytona`, `modal`, `vercel`, `cloudflare`, `e2b` - Provider API keys — see [Sandbox providers](/docs/integrations/sandbox-providers) Events: `kind: tool_call_enforcement` in control plane Activity. --- **Next steps:** [AI Enablement Stack](/docs/introduction/ai-enablement-stack) · [Sandbox providers](/docs/integrations/sandbox-providers) · [MCP server](/docs/mcp/server) · [Open workspace](https://app.blekline.com) · [Report issue](https://github.com/Blekline/blekline-oss/issues/new?template=bug_report.yml)