io.github.AAH20/agent-action-gate
Agent Action Gate
Gate/Prove ランタイム(エージェントおよび MCP ツール呼び出し向け)。
ツール意図の正規化 → 未知のものは拒否 → モデルの信頼度を承認とみなさない → 破壊的/プロビジョニング/廃止操作に対する HITL 検証 → Action Ledger(ハッシュチェーン)。
GRC_Claw @grc-claw/agent-policy-firewall から抽出。このリポジトリはシャープな鋳造の一片です。単一コマンド、大聖堂なし。
商用(販売方法): $499 Instant Audit と コンサルテーション は a2zsoc.com にあります。
存在理由(収益とコスト)
AIエージェント企業は「また別のMCP」にはお金を払いません。彼らが払うのは、無人で動作する破壊的ツールを止めることと、SOC 2 Type I、PEデューデリジェンス、保険更新の前に Gate/Prove のギャップを証明するためです。
コスト要因 | このゲートの働き | 購入者の成果 |
ゲートなしの | HITL 証明トークン + | 本番環境の爆発を回避 |
エージェントの「95%確信」 |
| 意図 ≠ 台帳の証明 |
書き込みツールが最初の思考で発火 | デフォルト SIMULATE(副作用なし) | FDE 数分、インシデントコストではない |
監査証跡なし | 追記専用 Action Ledger とハッシュチェーン | デューデリジェンスパケット |
ハードルール:エージェントの意図やモデルのスコアを人間の承認と同一視しない。
参考コスト試算(見積もりではありません):make bench。
Related MCP server: SINT Protocol
クイックスタート
make demoPYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench無人での高階層呼び出しは、信頼度0.99でも DENY されます。ALLOW には AAG_PROVE_TOKEN(または --prove-token)かつ approved: true が必要です。
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"キルスイッチ:AAG_KILL_SWITCH=1 または artifacts/KILL に touch する。
MCP stdio サーバー
このプロセスはツールを決して実行しません。クライアントは破壊的ツールを呼び出す前に gate_check を呼び出します。
PYTHONPATH=. python3 -m aag serveCursor / Claude の例(mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}Docker / レジストリイメージ:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0公式 MCP レジストリ名:io.github.AAH20/agent-action-gate
エンベロープ
すべての決定には以下が含まれます:
never_equate_intent_to_approval: trueallow_auto_execute(無人での高階層では false)mode:deny|simulate|allowledger_id/receipt_hashCTAs:Instant Audit + コンサルテーション
ライブラリマッパー
stdio ループなしで Python から同じ Gate/Prove ポリシーを使用:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})フィクスチャ(ラベル付き、ペイロードではない)
ファイル | テクニック | 期待される結果 |
| T1059 | 無人破壊的操作を DENY |
| T1078 | 読み取りを ALLOW |
| T1562 | 無人破壊的操作を DENY |
| — | 書き込みを SIMULATE |
| T1578 | HITL トークンのみで ALLOW |
レイアウト
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contract有償評価(無料の証明ではない)
エージェントまたはMCPサーバーを導入しており、SOC 2、PEデューデリジェンス、保険の前に Gate/Prove の評価(read)が必要な場合:
→ $499 Instant Audit
→ コンサルテーション(スプリント / vCISO)
無償の持ち帰りは拒否します。make demo を実行して Instant Audit を購入してください。
ライセンス
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityCmaintenanceSecurity gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed decision receipts. Shadow mode logs every tool call without blocking; enforce mode applies block, rate-limit, and minimum-tier rules. Receipts are independently verifiable offline with no accounts needed.54699MIT
- AlicenseAqualityAmaintenanceSecurity-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical2112Apache 2.0
- Alicense-qualityBmaintenanceSelf-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.Apache 2.0
- Alicense-qualityBmaintenanceA policy-enforcing MCP gateway that intercepts all tool calls to downstream MCP servers, applying allow/deny/ask rules with human approval and audit logging for safe access to dangerous tools.23MIT
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...
Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/AAH20/agent-action-gate'
If you have feedback or need assistance with the MCP directory API, please join our Discord server