Skip to main content
Glama
AAH20

io.github.AAH20/agent-action-gate

by AAH20

Agent Action Gate

Gate/Prove ランタイム(エージェントおよび MCP ツール呼び出し向け)。

ツール意図の正規化 → 未知のものは拒否 → モデルの信頼度を承認とみなさない → 破壊的/プロビジョニング/廃止操作に対する HITL 検証 → Action Ledger(ハッシュチェーン)。

GRC_Claw @grc-claw/agent-policy-firewall から抽出。このリポジトリはシャープな鋳造の一片です。単一コマンド、大聖堂なし。

商用(販売方法): $499 Instant Auditコンサルテーションa2zsoc.com にあります。

存在理由(収益とコスト)

AIエージェント企業は「また別のMCP」にはお金を払いません。彼らが払うのは、無人で動作する破壊的ツールを止めることと、SOC 2 Type I、PEデューデリジェンス、保険更新の前に Gate/Prove のギャップを証明するためです。

コスト要因

このゲートの働き

購入者の成果

ゲートなしの shell.exec / 制御無効化 / 廃止

HITL 証明トークン + approved がない限り DENY

本番環境の爆発を回避

エージェントの「95%確信」

never_equate_intent_to_approval: true

意図 ≠ 台帳の証明

書き込みツールが最初の思考で発火

デフォルト SIMULATE(副作用なし)

FDE 数分、インシデントコストではない

監査証跡なし

追記専用 Action Ledger とハッシュチェーン

デューデリジェンスパケット

ハードルール:エージェントの意図やモデルのスコアを人間の承認と同一視しない

参考コスト試算(見積もりではありません):make bench

Related MCP server: SINT Protocol

クイックスタート

make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench

無人での高階層呼び出しは、信頼度0.99でも DENY されます。ALLOW には AAG_PROVE_TOKEN(または --prove-tokenかつ approved: true が必要です。

export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"

キルスイッチ:AAG_KILL_SWITCH=1 または artifacts/KILL に touch する。

MCP stdio サーバー

このプロセスはツールを決して実行しません。クライアントは破壊的ツールを呼び出す前に gate_check を呼び出します。

PYTHONPATH=. python3 -m aag serve

Cursor / Claude の例(mcpServers):

{
  "agent-action-gate": {
    "command": "python3",
    "args": ["-m", "aag", "serve"],
    "cwd": "/path/to/agent-action-gate",
    "env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
  }
}

Docker / レジストリイメージ:

docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0

公式 MCP レジストリ名:io.github.AAH20/agent-action-gate

エンベロープ

すべての決定には以下が含まれます:

  • never_equate_intent_to_approval: true

  • allow_auto_execute(無人での高階層では false)

  • modedeny | simulate | allow

  • ledger_id / receipt_hash

  • CTAs:Instant Audit + コンサルテーション

ライブラリマッパー

stdio ループなしで Python から同じ Gate/Prove ポリシーを使用:

from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call

gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})

フィクスチャ(ラベル付き、ペイロードではない)

ファイル

テクニック

期待される結果

t1059_unattended_shell.json

T1059

無人破壊的操作を DENY

t1078_read_identity.json

T1078

読み取りを ALLOW

t1562_impair_defenses.json

T1562

無人破壊的操作を DENY

write_ticket_simulate.json

書き込みを SIMULATE

proved_decommission.json

T1578

HITL トークンのみで ALLOW

レイアウト

aag/
  gate.py      HITL + kill-switch + unknown deny
  ledger.py    hash-chained JSONL
  server.py    MCP stdio (gate_check, ledger_verify)
  mcp.py       MCP tools/call mapper (no execution)
  cost.py      illustrative avoidance sketch
  demo.py      fixture runner
fixtures/      ATT&CK-tagged cases
server.json    MCP Registry metadata
tests/         Gate/Prove + MCP contract

有償評価(無料の証明ではない)

エージェントまたはMCPサーバーを導入しており、SOC 2、PEデューデリジェンス、保険の前に Gate/Prove の評価(read)が必要な場合:

$499 Instant Audit
コンサルテーション(スプリント / vCISO)

無償の持ち帰りは拒否します。make demo を実行して Instant Audit を購入してください。

ライセンス

MIT

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    B
    quality
    C
    maintenance
    Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed decision receipts. Shadow mode logs every tool call without blocking; enforce mode applies block, rate-limit, and minimum-tier rules. Receipts are independently verifiable offline with no accounts needed.
    5
    469
    9
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Security-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical
    21
    12
    Apache 2.0
  • A
    license
    -
    quality
    B
    maintenance
    Self-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.
    Apache 2.0
  • A
    license
    -
    quality
    B
    maintenance
    A policy-enforcing MCP gateway that intercepts all tool calls to downstream MCP servers, applying allow/deny/ask rules with human approval and audit logging for safe access to dangerous tools.
    23
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...

  • Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AAH20/agent-action-gate'

If you have feedback or need assistance with the MCP directory API, please join our Discord server