io.github.AAH20/agent-action-gate
Agent Action Gate
Gate/Prove ランタイム(エージェントおよび MCP ツール呼び出し向け)。
ツール意図の正規化 → 未知のものは拒否 → モデルの信頼度を承認とみなさない → 破壊的/プロビジョニング/廃止操作に対する HITL 検証 → Action Ledger(ハッシュチェーン)。
GRC_Claw @grc-claw/agent-policy-firewall から抽出。このリポジトリはシャープな鋳造の一片です。単一コマンド、大聖堂なし。
商用(販売方法): $499 Instant Audit と コンサルテーション は a2zsoc.com にあります。
存在理由(収益とコスト)
AIエージェント企業は「また別のMCP」にはお金を払いません。彼らが払うのは、無人で動作する破壊的ツールを止めることと、SOC 2 Type I、PEデューデリジェンス、保険更新の前に Gate/Prove のギャップを証明するためです。
コスト要因 | このゲートの働き | 購入者の成果 |
ゲートなしの | HITL 証明トークン + | 本番環境の爆発を回避 |
エージェントの「95%確信」 |
| 意図 ≠ 台帳の証明 |
書き込みツールが最初の思考で発火 | デフォルト SIMULATE(副作用なし) | FDE 数分、インシデントコストではない |
監査証跡なし | 追記専用 Action Ledger とハッシュチェーン | デューデリジェンスパケット |
ハードルール:エージェントの意図やモデルのスコアを人間の承認と同一視しない。
参考コスト試算(見積もりではありません):make bench。
Related MCP server: agent-security-gateway
クイックスタート
make demoPYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench無人での高階層呼び出しは、信頼度0.99でも DENY されます。ALLOW には AAG_PROVE_TOKEN(または --prove-token)かつ approved: true が必要です。
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"キルスイッチ:AAG_KILL_SWITCH=1 または artifacts/KILL に touch する。
MCP stdio サーバー
このプロセスはツールを決して実行しません。クライアントは破壊的ツールを呼び出す前に gate_check を呼び出します。
PYTHONPATH=. python3 -m aag serveCursor / Claude の例(mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}Docker / レジストリイメージ:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0公式 MCP レジストリ名:io.github.AAH20/agent-action-gate
エンベロープ
すべての決定には以下が含まれます:
never_equate_intent_to_approval: trueallow_auto_execute(無人での高階層では false)mode:deny|simulate|allowledger_id/receipt_hashCTAs:Instant Audit + コンサルテーション
ライブラリマッパー
stdio ループなしで Python から同じ Gate/Prove ポリシーを使用:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})フィクスチャ(ラベル付き、ペイロードではない)
ファイル | テクニック | 期待される結果 |
| T1059 | 無人破壊的操作を DENY |
| T1078 | 読み取りを ALLOW |
| T1562 | 無人破壊的操作を DENY |
| — | 書き込みを SIMULATE |
| T1578 | HITL トークンのみで ALLOW |
レイアウト
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contract有償評価(無料の証明ではない)
エージェントまたはMCPサーバーを導入しており、SOC 2、PEデューデリジェンス、保険の前に Gate/Prove の評価(read)が必要な場合:
→ $499 Instant Audit
→ コンサルテーション(スプリント / vCISO)
無償の持ち帰りは拒否します。make demo を実行して Instant Audit を購入してください。
ライセンス
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceMCP server that provides human-in-the-loop approval for risky AI agent actions, with durable state and audit logs.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.-
- FlicenseNot gradedqualityBmaintenanceAn MCP server that acts as an authorization gateway between an AI agent and external systems, deterministically refusing actions that exceed granted authority and sealing every decision into an auditable chain of custody.-
- AlicenseNot gradedqualityBmaintenanceMCP server for tracking and verifying AI reasoning state, with signed action receipts, repo-history records, and preflight gating for tool calls.Apache 2.0