Skip to main content
Glama
AAH20

io.github.AAH20/agent-action-gate

by AAH20

Agent Action Gate

用于 agent 和 MCP 工具调用 的 Gate/Prove 运行时。

规范化工具意图 → 拒绝未知 → 绝不将模型置信度视为批准 → 对破坏性 / 供应 / 停用操作进行 HITL 证明 → Action Ledger(哈希链)。

提取自 GRC_Claw @grc-claw/agent-policy-firewall。本仓库是锋利精简的切片:一条命令,无需大教堂式架构。

商业(如何销售): $499 Instant Audit咨询,见 a2zsoc.com

为什么存在(收益 + 成本)

AI-agent 公司不会为“另一个 MCP”付费。他们付费是为了阻止无人值守的破坏性工具,并在 SOC 2 Type I、PE 尽职调查或保险续保之前证明 Gate/Prove 差距

成本驱动因素

此 Gate 的作用

买家结果

无门禁的 shell.exec / 禁用控制 / 停用

除非有 HITL 证明令牌 + approved,否则 DENY

避免生产事故

Agent “95% 确定”

never_equate_intent_to_approval: true

意图 ≠ 账本证明

写入工具在首次念头时触发

默认 SIMULATE(无副作用)

FDE 分钟,而非事件成本

无审计跟踪

带哈希链的追加式 Action Ledger

尽职调查文件包

硬性规则:绝不将 agent 意图或模型分数等同于人工批准。

示例性成本估算(非报价):make bench

Related MCP server: SINT Protocol

快速开始

make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench

无人值守的高层级调用即使置信度为 0.99 也会 DENY。ALLOW 需要 AAG_PROVE_TOKEN(或 --prove-token以及 approved: true

export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"

急停开关:AAG_KILL_SWITCH=1 或 touch artifacts/KILL

MCP stdio 服务器

此进程绝不执行工具。客户端在调用破坏性工具之前会调用 gate_check

PYTHONPATH=. python3 -m aag serve

Cursor / Claude 示例(mcpServers):

{
  "agent-action-gate": {
    "command": "python3",
    "args": ["-m", "aag", "serve"],
    "cwd": "/path/to/agent-action-gate",
    "env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
  }
}

Docker / registry 镜像:

docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0

官方 MCP Registry 名称:io.github.AAH20/agent-action-gate

封套

每个决策都包含:

  • never_equate_intent_to_approval: true

  • allow_auto_execute(在无人值守的高层级下为 false)

  • modedeny | simulate | allow

  • ledger_id / receipt_hash

  • CTAs:Instant Audit + 咨询

库映射器

无需 stdio 循环,即可在 Python 中获得相同的 Gate/Prove 策略:

from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call

gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})

测试夹具(已标记,非负载)

文件

技术

预期结果

t1059_unattended_shell.json

T1059

拒绝无人值守的破坏性操作

t1078_read_identity.json

T1078

允许读取

t1562_impair_defenses.json

T1562

拒绝无人值守的破坏性操作

write_ticket_simulate.json

模拟写入

proved_decommission.json

T1578

仅在有 HITL 令牌时允许

布局

aag/
  gate.py      HITL + kill-switch + unknown deny
  ledger.py    hash-chained JSONL
  server.py    MCP stdio (gate_check, ledger_verify)
  mcp.py       MCP tools/call mapper (no execution)
  cost.py      illustrative avoidance sketch
  demo.py      fixture runner
fixtures/      ATT&CK-tagged cases
server.json    MCP Registry metadata
tests/         Gate/Prove + MCP contract

付费评估(非免费证明)

如果你部署了 agents 或 MCP 服务器,并且需要在 SOC 2、PE 尽职调查或保险之前获得 Gate/Prove 审查:

$499 Instant Audit
咨询(sprint / vCISO)

免费带走的结论:拒绝 — 运行 make demo 并购买 Instant Audit。

许可证

MIT

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    B
    quality
    C
    maintenance
    Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed decision receipts. Shadow mode logs every tool call without blocking; enforce mode applies block, rate-limit, and minimum-tier rules. Receipts are independently verifiable offline with no accounts needed.
    5
    469
    9
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Security-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical
    21
    12
    Apache 2.0
  • A
    license
    -
    quality
    B
    maintenance
    Self-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.
    Apache 2.0
  • A
    license
    -
    quality
    B
    maintenance
    A policy-enforcing MCP gateway that intercepts all tool calls to downstream MCP servers, applying allow/deny/ask rules with human approval and audit logging for safe access to dangerous tools.
    23
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-ha...

  • Control plane for autonomous software labor. Agents claim objectives over MCP with audit trail.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AAH20/agent-action-gate'

If you have feedback or need assistance with the MCP directory API, please join our Discord server