Agent Runtime Proxy
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Agent Runtime Proxydelete all files in /tmp"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agent Runtime Proxy · Agent 运行时拦截代理
在 MCP 服务器前面站一道独立的保安:不相信宿主里的任何插件,危险调用一律不放行。
宿主内的插件有加载顺序问题——一个恶意或先注册的插件,可能赶在安全检查之前动手。agent-runtime-proxy 是一条透明 stdio 代理,包住目标 MCP server,在进程外、网络边界独立拦截:
MCP Client ←stdio→ agent-runtime-proxy ←stdio→ 目标 MCP Server
(只拦 tools/call)对客户端而言,它就是一个普通 MCP server;initialize / tools/list / ping 及所有 notification 双向透传,只有 tools/call 被拦截并先做运行时验证。
✅ fail-closed:判为危险、验证器出错/不可用、超时——都不转发,返回 MCP
isError+ 签名拒付收据✅ 放行才转发,结果在
result._meta.ccs附带 Ed25519 双收据,不动 MCP content 协议✅ 两模式:
enforce(默认真拦)/shadow(全转发,仅标记观测到的拦截,用于灰度)✅ 零依赖,纯 Node.js 标准库(Node ≥ 18)
⚡ 使用
# 全局安装
npm install -g agent-runtime-proxy把客户端的 MCP server 启动命令包在代理后面:
agent-runtime-proxy -- <原 MCP server 启动命令>例如包住一个本地 server:
{
"mcpServers": {
"my-tool-guarded": {
"command": "agent-runtime-proxy",
"args": ["--", "node", "/path/to/original-server.js"]
}
}
}Related MCP server: resolve-guard
验证器从哪来
代理在拦截时需要一个运行时验证器,按以下顺序自动发现:
--verifier-module/CCS_VERIFIER_MODULE指定的模块require("agent-runtime-guard")(推荐,与本代理配套)旧包
ccs-mcp-server兜底相邻项目
ccs-mcp-server-m8ven-fix/src(开发环境)
自定义模块需导出 verifyCall(call, policy)。找不到验证器时默认 fail-closed,不转发。
选项
选项 / 环境变量 | 作用 |
| 拦截模式,默认 enforce |
| 合成的调用方身份 |
| 显式指定验证器模块 |
| 验证预算,超时 fail-closed |
边界(如实说明)
仅 stdio 传输,SSE / streamable-HTTP 暂不支持
调用方身份是合成的(MCP 协议本身无可认证身份),Identity 维度要硬需上游提供已核验身份
签名密钥的固定/轮换/HSM 待部署方案落实;自动生成密钥仅限开发
Links
License
Elastic License 2.0 (ELv2). See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Fail-closed action authorization, MCP risk scanning, x402 checks, and signed receipts.
MCP enforcement layer that intercepts AI agent actions and blocks rule violations before execution.
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceSelf-hosted MCP gateway that applies deterministic, compiled policy to tool discovery, invocation, and outbound data flow, with no model in the enforcement path. Every decision emits a hash-chained receipt sealed with Ed25519 and verifiable using public keys only.Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables deterministic policy enforcement for MCP and WebMCP tool calls, blocking boundary-crossing invocations and requiring exact human approval for consequential actions.MIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP clients to govern downstream tool servers by enforcing default-deny authority and attestation on every tool call, with live monitoring, approval, and mid-session revocation.3Apache 2.0
- AlicenseBqualityBmaintenanceEnforces consensus-hardened tool approval with HMAC-signed receipts, policy gates, and host-bound argument checks for MCP clients.1246 npmMIT