Guarded MCP Agent
README.md
## Run Locally
### Prerequisites
- Python 3.10+
- Node.js 18+
### Step 1 — Install Python dependencies
```bash
cd Assignment
pip install -r requirements.txt
```
### Step 2 — Install frontend dependencies
```bash
cd frontend
npm install
```
### Step 3 — Start MCP Notes Server (Terminal 1)
```bash
cd Assignment
python -m backend.custom_mcp.notes_server
```
Runs at `http://127.0.0.1:8002/mcp`
### Step 4 — Start Backend (Terminal 2)
```bash
cd Assignment
uvicorn backend.main:app --reload --host 0.0.0.0 --port 8000
```
Runs at `http://localhost:8000`
### Step 5 — Start Frontend (Terminal 3)
```bash
cd frontend
npm run dev
```
Runs at `http://localhost:5173`
---
## Testing the Agent
Type these in the Chat box on the dashboard:
| Command | Tool Called |
|---|---|
| `create note title: X content: Y` | `create_note` |
| `show all notes` | `get_notes` |
| `search milk` | `search_notes` |
| `update note 1 title: X content: Y` | `update_note` |
| `delete note 1` | `delete_note` |
---
## Testing Policy Features
### Block a tool
```powershell
Invoke-RestMethod -Uri "http://localhost:8000/api/settings/" -Method POST -ContentType "application/json" -Body '{"key": "blocked_tools", "value": "delete_note"}'
```
Then type `delete note 1` — will be blocked.
### Unblock
```powershell
Invoke-RestMethod -Uri "http://localhost:8000/api/settings/" -Method POST -ContentType "application/json" -Body '{"key": "blocked_tools", "value": ""}'
```
### Enable human approval
Go to Settings in dashboard → set `enable_human_approval` = `1` → Save.
Then try `delete note 1` — will require approval from the Approvals panel.
### Prompt injection detection
Type this in chat:
Will be blocked automatically with: `Prompt injection detected in user message.`
---
## Policy Engine
The policy engine (`policy_engine.py`) enforces these rules in order:
1. **Global toggle** — `enable_tool_access = 0` blocks all tools
2. **Prompt injection detection** — blocks known injection patterns
3. **Argument size limit** — blocks tool args over 2000 chars
4. **Blocked tools list** — `blocked_tools` = comma-separated tool names
5. **Human approval** — `enable_human_approval = 1` requires approval for delete/update
Rules are checked on every request. Dashboard changes take effect immediately without restart.
---
## Edge Cases
| Scenario | Behavior |
|---|---|
| MCP server crashes mid-call | MCPClient worker reconnects automatically on next request |
| Prompt injection attempt | Detected by regex patterns, blocked before tool execution |
| Conflicting rules | `blocked_tools` takes priority over approval requirement |
| Approver offline | Request stays `pending` in DB indefinitely until approved/denied |
| Tool not recognized | Returns helpful message with supported commands |
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues