io.github.AAH20/agent-action-gate
Agent Action Gate
用于 agent 和 MCP 工具调用 的 Gate/Prove 运行时。
规范化工具意图 → 拒绝未知 → 绝不将模型置信度视为批准 → 对破坏性 / 供应 / 停用操作进行 HITL 证明 → Action Ledger(哈希链)。
提取自 GRC_Claw @grc-claw/agent-policy-firewall。本仓库是锋利精简的切片:一条命令,无需大教堂式架构。
商业(如何销售): $499 Instant Audit 和 咨询,见 a2zsoc.com。
为什么存在(收益 + 成本)
AI-agent 公司不会为“另一个 MCP”付费。他们付费是为了阻止无人值守的破坏性工具,并在 SOC 2 Type I、PE 尽职调查或保险续保之前证明 Gate/Prove 差距。
成本驱动因素 | 此 Gate 的作用 | 买家结果 |
无门禁的 | 除非有 HITL 证明令牌 + | 避免生产事故 |
Agent “95% 确定” |
| 意图 ≠ 账本证明 |
写入工具在首次念头时触发 | 默认 SIMULATE(无副作用) | FDE 分钟,而非事件成本 |
无审计跟踪 | 带哈希链的追加式 Action Ledger | 尽职调查文件包 |
硬性规则:绝不将 agent 意图或模型分数等同于人工批准。
示例性成本估算(非报价):make bench。
Related MCP server: agent-security-gateway
快速开始
make demoPYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench无人值守的高层级调用即使置信度为 0.99 也会 DENY。ALLOW 需要 AAG_PROVE_TOKEN(或 --prove-token)以及 approved: true。
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"急停开关:AAG_KILL_SWITCH=1 或 touch artifacts/KILL。
MCP stdio 服务器
此进程绝不执行工具。客户端在调用破坏性工具之前会调用 gate_check。
PYTHONPATH=. python3 -m aag serveCursor / Claude 示例(mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}Docker / registry 镜像:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0官方 MCP Registry 名称:io.github.AAH20/agent-action-gate
封套
每个决策都包含:
never_equate_intent_to_approval: trueallow_auto_execute(在无人值守的高层级下为 false)mode:deny|simulate|allowledger_id/receipt_hashCTAs:Instant Audit + 咨询
库映射器
无需 stdio 循环,即可在 Python 中获得相同的 Gate/Prove 策略:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})测试夹具(已标记,非负载)
文件 | 技术 | 预期结果 |
| T1059 | 拒绝无人值守的破坏性操作 |
| T1078 | 允许读取 |
| T1562 | 拒绝无人值守的破坏性操作 |
| — | 模拟写入 |
| T1578 | 仅在有 HITL 令牌时允许 |
布局
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contract付费评估(非免费证明)
如果你部署了 agents 或 MCP 服务器,并且需要在 SOC 2、PE 尽职调查或保险之前获得 Gate/Prove 审查:
→ $499 Instant Audit
→ 咨询(sprint / vCISO)
免费带走的结论:拒绝 — 运行 make demo 并购买 Instant Audit。
许可证
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceMCP server that provides human-in-the-loop approval for risky AI agent actions, with durable state and audit logs.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.-
- FlicenseNot gradedqualityBmaintenanceAn MCP server that acts as an authorization gateway between an AI agent and external systems, deterministically refusing actions that exceed granted authority and sealing every decision into an auditable chain of custody.-
- AlicenseNot gradedqualityBmaintenanceMCP server for tracking and verifying AI reasoning state, with signed action receipts, repo-history records, and preflight gating for tool calls.Apache 2.0