Claude Desktop exposes no hook API, so node9 governs what goes through its MCP servers, and nothing the editor does on its own. That is the honest answer, and it is the first thing to know before you rely on it.
| Surface | How node9 is wired | What it does |
|---|---|---|
| MCP servers | entries in claude_desktop_config.json are wrapped through the node9 gateway | per-tool allow / review / block |
Set it up
node9 agents add claudeDesktop
node9 init does this for every agent it detects on the machine. Either command is safe to
re-run; it repairs a hook that an agent update removed and leaves everything else alone.
What is not covered
- No prompt scan and no cost tracking.
node9 doctorandnode9 statusdo not list Claude Desktop yet.
Verify it on this machine
node9 doctor # is the hook (or MCP wrap) actually in place?
node9 explain Bash 'cat ~/.ssh/id_rsa' # shows the verdict the live hook enforces: BLOCK
node9 explain prints the exact rule that fires and where the decision came from. If doctor
says the agent is not wired, the guard is not running, whatever the config looks like.
Every agent, side by side
node9 wires into twelve agents and the depth differs. The coverage matrix shows all of them in one table, including which ones node9 cannot see the shell of.