Run npx @trigguard/mcp for the public MCP surface. Servers that mutate external state should require a valid decision receipt for the declared frame, same as REST or npm install trigguard SDK paths. Only the gateway enforces policy via authorize().