SecureAgentServer
Secure MCP-Based Agent System
このリポジトリは、サポートチケットと顧客アカウントを扱うMCPサーバーとクライアントを、エンドツーエンドで構築・保護したものです。署名付きトークン認証、プロンプトインジェクションとツールポイズニングに対する2つの独立したガードレール、文書化された脅威モデル、そして唯一の破壊的なツール呼び出しに対するヒューマン・イン・ザ・ループのゲートを備えています。'Secure an MCP-Based Agent System' ラボ用に構築されています。
アーキテクチャ
flowchart TD
HOST["Host application"] --> CLIENT["client.py\n(fastmcp.Client + elicitation_handler)"]
CLIENT <-->|"Streamable HTTP\nAuthorization: Bearer <signed JWT>"| SERVER
subgraph Server["server.py — FastMCP('SecureAgentServer')"]
AUTH["JWTVerifier (HS256)\nissuer + audience + signature checked"]
G1["Guardrail 1: sanitize_untrusted_text()\napplied to ticket body/subject"]
G2["Guardrail 2: verify_tool_manifest()\nchecked at startup, refuses to start on mismatch"]
TOOLS["Tools: search_tickets, lookup_customer_account,\nclose_ticket (elicitation-gated)"]
AUTH --> TOOLS
TOOLS --> G1
end
G2 -.->|startup check| SERVER
TOOLS --> TICKETS[("data/tickets.json\n(untrusted customer text)")]
TOOLS --> CUSTOMERS[("data/customers.json\n('internal API')")]Related MCP server: enterprise-agent-lab
セットアップ
pip install -r requirements.txt
# 1. Set the JWT signing secret (never commit the real value; see .env.example)
export MCP_JWT_SECRET="a-long-random-secret-at-least-32-characters"
# 2. Generate the pinned tool-integrity manifest (a deliberate, manual step —
# see docs/threat-model.md Risk #2)
python generate_manifest.py
# 3. Run the server
python server.py
# 4. In another terminal (same MCP_JWT_SECRET exported)
python client.py --auto-confirm # non-interactive demo
python client.py # interactive: real yes/no confirmation promptsセキュリティ対策の再現
対策 | 確認方法 |
署名付きJWT認証 |
|
ガードレール1: プロンプトインジェクションのサニタイズ | クライアントを実行し、 |
ガレートール2: ツールポイズニングの検出 |
|
破壊的操作に対するヒューマン・イン・ザ・ループ | デモログでは |
最小権限のスコープ |
|
脅威モデル
5つの特定済みリスクと、その緩和策および残存リスクの注記を、ごまかさず明示的に書いた詳細な文書です: docs/threat-model.md。
意図的にスコープ外としていること(明示)
mint_token.pyは、実在のOAuth 2.1アイデンティティプロバイダーの代わりをするものです。本番展開では、ローカルでのトークン発行スクリプトではなく、実際のトークン発行・ローテーション・失効のしくみが必須です。レート制限やネットワーク層の堅牢化(TLS終端、WAF)は行っていません。これはアプリケーション層のセキュリティデモであり、本番向けの完全な堅牢化ガイドではありません。
ガードレール1のうち正規表現ベースの部分は、二次的でベストエフォートなレイヤーとして明示しています。デミリタによるラッピングが実際に依拠している制御である理由は、
docs/threat-model.mdのリスク番号を参照してください。
シークレットはコミットされない
MCP_JWT_SECRET は環境から取得され(.env.example 参照)、ハードコードもコミットも一切行われません。tool_manifest.json は意図的にコミットされています。これは固定されたハッシュマニフェスト(lockfile と同様)であり、シークレットではありません。
This server cannot be deployed
Maintenance
Related MCP Connectors
Supervised API-write gateway for AI agents with policy, human approval and execution receipts.
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceGates agent tool execution with human approval, audit trails, and replay-resistant permits, enabling safe use of tools in agent loops.MIT
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.1-
- AlicenseNot gradedqualityCmaintenanceEnforces authenticated identity on every tool call and SSE frame, rotates vaulted credentials in place, and restricts tools via allowlists.71 npmMIT
- FlicenseNot gradedqualityBmaintenanceEnables support engineers to analyze tickets against a help center with cited retrieval, role-gated and human-confirmed actions, and safety-gated evaluation.1-