io.github.AAH20/agent-action-gate
Agent Action Gate
Runtime de Gate/Prove para llamadas a herramientas de agentes y MCP.
Normaliza la intención de la herramienta → deniega lo desconocido → nunca trates la confianza del modelo como aprobación → prueba HITL en destructivo / aprovisionamiento / retirada → Registro de Acciones (cadena hash).
Extraído de GRC_Claw @grc-claw/agent-policy-firewall. Este repo es la tajada afilada de la fundición: un comando, sin catedral.
Comercial (cómo se vende): $499 Instant Audit y consulta en a2zsoc.com.
Por qué existe esto (ingresos + coste)
Las empresas de agentes de IA no pagan por «otro MCP». Pagan para detener herramientas destructivas no supervisadas y para probar las brechas de Gate/Prove antes de SOC 2 Tipo I, diligencia de capital privado o renovación de seguro.
Factor de coste | Qué hace esta compuerta | Resultado para el comprador |
| DENY salvo token de prueba HITL + | Evitar incidente de producción |
Agente «95 % seguro» |
| Intención ≠ prueba de registro |
Las herramientas de escritura se disparan al primer pensamiento | Por defecto SIMULATE (sin efectos secundarios) | Minutos de FDE, no coste de incidente |
Sin rastro de auditoría | Registro de Acciones de solo añadir con cadena hash | Paquete de diligencia |
Regla dura: nunca equipares la intención del agente o la puntuación del modelo con la aprobación humana.
Bosquejo de coste ilustrativo (no es una cotización): make bench.
Related MCP server: SINT Protocol
Inicio rápido
make demoPYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag benchLas llamadas no supervisadas de alto nivel DENY incluso con confianza 0,99. ALLOW necesita AAG_PROVE_TOKEN (o --prove-token) y approved: true.
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"Interruptor de emergencia: AAG_KILL_SWITCH=1 o toca artifacts/KILL.
Servidor stdio de MCP
Este proceso nunca ejecuta herramientas. Los clientes llaman a gate_check antes de invocar una herramienta destructiva.
PYTHONPATH=. python3 -m aag serveEjemplo para Cursor / Claude (mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}Imagen de Docker / registro:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0Nombre oficial del Registro MCP: io.github.AAH20/agent-action-gate
Envoltura
Cada decisión incluye:
never_equate_intent_to_approval: trueallow_auto_execute(false en niveles altos no supervisados)mode:deny|simulate|allowledger_id/receipt_hashCTAs: Instant Audit + consulta
Mapeador de biblioteca
Misma política de Gate/Prove desde Python sin el bucle stdio:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})Fixtures (etiquetados, no payloads)
Archivo | Técnica | Esperado |
| T1059 | DENY destructivo no supervisado |
| T1078 | ALLOW lectura |
| T1562 | DENY destructivo no supervisado |
| — | SIMULATE escritura |
| T1578 | ALLOW solo con token HITL |
Estructura
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contractEvaluación de pago (no prove gratuito)
Si despliegas agentes o servidores MCP y necesitas una lectura de Gate/Prove antes de SOC 2, diligencia de capital privado o seguro:
→ $499 Instant Audit
→ consulta (sprint / vCISO)
Encargos no remunerados: recházalos — ejecuta make demo y compra Instant Audit.
Licencia
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityCmaintenanceSecurity gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed decision receipts. Shadow mode logs every tool call without blocking; enforce mode applies block, rate-limit, and minimum-tier rules. Receipts are independently verifiable offline with no accounts needed.54699MIT
- AlicenseAqualityAmaintenanceSecurity-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical2112Apache 2.0
- Alicense-qualityBmaintenanceSelf-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.Apache 2.0
- Alicense-qualityBmaintenanceA policy-enforcing MCP gateway that intercepts all tool calls to downstream MCP servers, applying allow/deny/ask rules with human approval and audit logging for safe access to dangerous tools.23MIT
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/AAH20/agent-action-gate'
If you have feedback or need assistance with the MCP directory API, please join our Discord server