SecureAgentServer
Secure MCP-Based Agent System
このリポジトリは、サポートチケットと顧客アカウントを扱うMCPサーバーとクライアントを、エンドツーエンドで構築・保護したものです。署名付きトークン認証、プロンプトインジェクションとツールポイズニングに対する2つの独立したガードレール、文書化された脅威モデル、そして唯一の破壊的なツール呼び出しに対するヒューマン・イン・ザ・ループのゲートを備えています。'Secure an MCP-Based Agent System' ラボ用に構築されています。
アーキテクチャ
flowchart TD
HOST["Host application"] --> CLIENT["client.py\n(fastmcp.Client + elicitation_handler)"]
CLIENT <-->|"Streamable HTTP\nAuthorization: Bearer <signed JWT>"| SERVER
subgraph Server["server.py — FastMCP('SecureAgentServer')"]
AUTH["JWTVerifier (HS256)\nissuer + audience + signature checked"]
G1["Guardrail 1: sanitize_untrusted_text()\napplied to ticket body/subject"]
G2["Guardrail 2: verify_tool_manifest()\nchecked at startup, refuses to start on mismatch"]
TOOLS["Tools: search_tickets, lookup_customer_account,\nclose_ticket (elicitation-gated)"]
AUTH --> TOOLS
TOOLS --> G1
end
G2 -.->|startup check| SERVER
TOOLS --> TICKETS[("data/tickets.json\n(untrusted customer text)")]
TOOLS --> CUSTOMERS[("data/customers.json\n('internal API')")]Related MCP server: permitd MCP Server
セットアップ
pip install -r requirements.txt
# 1. Set the JWT signing secret (never commit the real value; see .env.example)
export MCP_JWT_SECRET="a-long-random-secret-at-least-32-characters"
# 2. Generate the pinned tool-integrity manifest (a deliberate, manual step —
# see docs/threat-model.md Risk #2)
python generate_manifest.py
# 3. Run the server
python server.py
# 4. In another terminal (same MCP_JWT_SECRET exported)
python client.py --auto-confirm # non-interactive demo
python client.py # interactive: real yes/no confirmation promptsセキュリティ対策の再現
対策 | 確認方法 |
署名付きJWT認証 |
|
ガードレール1: プロンプトインジェクションのサニタイズ | クライアントを実行し、 |
ガレートール2: ツールポイズニングの検出 |
|
破壊的操作に対するヒューマン・イン・ザ・ループ | デモログでは |
最小権限のスコープ |
|
脅威モデル
5つの特定済みリスクと、その緩和策および残存リスクの注記を、ごまかさず明示的に書いた詳細な文書です: docs/threat-model.md。
意図的にスコープ外としていること(明示)
mint_token.pyは、実在のOAuth 2.1アイデンティティプロバイダーの代わりをするものです。本番展開では、ローカルでのトークン発行スクリプトではなく、実際のトークン発行・ローテーション・失効のしくみが必須です。レート制限やネットワーク層の堅牢化(TLS終端、WAF)は行っていません。これはアプリケーション層のセキュリティデモであり、本番向けの完全な堅牢化ガイドではありません。
ガードレール1のうち正規表現ベースの部分は、二次的でベストエフォートなレイヤーとして明示しています。デミリタによるラッピングが実際に依拠している制御である理由は、
docs/threat-model.mdのリスク番号を参照してください。
シークレットはコミットされない
MCP_JWT_SECRET は環境から取得され(.env.example 参照)、ハードコードもコミットも一切行われません。tool_manifest.json は意図的にコミットされています。これは固定されたハッシュマニフェスト(lockfile と同様)であり、シークレットではありません。
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceProvides a set of tools with a security verification layer that assesses risk and requires human approval for high-risk actions, reducing prompt injection and tool-poisoning attacks.
- AlicenseNot gradedqualityCmaintenanceGates agent tool execution with human approval, audit trails, and replay-resistant permits, enabling safe use of tools in agent loops.MIT
- FlicenseNot gradedqualityBmaintenanceProvides a secure MCP boundary for AI agents, intercepting and validating tool calls, redacting secrets, and requiring human approval for sensitive actions with a tamper-evident audit trail.
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.
Related MCP Connectors
Runtime permission, approval, and audit layer for AI agent tool execution.
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Responsible-AI guardrails for agents: scoring with policy, injection & PII detection, DPDP.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bhargavlukka/secure-mcp-agent'
If you have feedback or need assistance with the MCP directory API, please join our Discord server