SecureAgentServer
보안 MCP 기반 에이전트 시스템
지원 티켓 + 고객 계정 MCP 서버 및 클라이언트를 종단 간 보안을 갖추어 구축했습니다. 서명된 토큰 인증, 프롬프트 인젝션과 도구 중독에 대한 두 개의 독립적인 가드레일, 문서화된 위협 모델, 그리고 하나뿐인 파괴적 도구 호출에 대한 인간 개입(HITL) 게이트까지 포함합니다. "Secure an MCP-Based Agent System" 랩을 위해 제작되었습니다.
아키텍처
flowchart TD
HOST["Host application"] --> CLIENT["client.py\n(fastmcp.Client + elicitation_handler)"]
CLIENT <-->|"Streamable HTTP\nAuthorization: Bearer <signed JWT>"| SERVER
subgraph Server["server.py — FastMCP('SecureAgentServer')"]
AUTH["JWTVerifier (HS256)\nissuer + audience + signature checked"]
G1["Guardrail 1: sanitize_untrusted_text()\napplied to ticket body/subject"]
G2["Guardrail 2: verify_tool_manifest()\nchecked at startup, refuses to start on mismatch"]
TOOLS["Tools: search_tickets, lookup_customer_account,\nclose_ticket (elicitation-gated)"]
AUTH --> TOOLS
TOOLS --> G1
end
G2 -.->|startup check| SERVER
TOOLS --> TICKETS[("data/tickets.json\n(untrusted customer text)")]
TOOLS --> CUSTOMERS[("data/customers.json\n('internal API')")]Related MCP server: enterprise-agent-lab
설정
pip install -r requirements.txt
# 1. Set the JWT signing secret (never commit the real value; see .env.example)
export MCP_JWT_SECRET="a-long-random-secret-at-least-32-characters"
# 2. Generate the pinned tool-integrity manifest (a deliberate, manual step —
# see docs/threat-model.md Risk #2)
python generate_manifest.py
# 3. Run the server
python server.py
# 4. In another terminal (same MCP_JWT_SECRET exported)
python client.py --auto-confirm # non-interactive demo
python client.py # interactive: real yes/no confirmation prompts보안 통제 재현
제어 | 검증 방법 |
Signed-JWT 인증 |
|
가드레일 1: 프롬프트 인젝션 정화 | 클라이언트를 실행하고 |
가드레일 2: 도구 중독 탐지 |
|
파괴적 작업에 대한 인간 개입(HITL) | 데모 로그에서 |
최소 권한 범위 지정 |
|
위협 모델
완전한 문서에는 완화 조치와 남은 위험 메모가 애매모호하게 넘어가기 않도록 명시된 5가지 위험이 포함되어 있습니다: docs/threat-model.md
의도적으로 범위 밖에 둔 것, 명확하게 밝힘
mint_token.py는 실제 OAuth 2.1 식별 공급자 대신 임시로 사용되는 대체물입니다. 프로덕션 배포에는 로컬 발행 스크립트가 아니라 실제 토큰 발급/회전/폐기가 필요합니다.비율 제한이나 네트워크 계층 강화(TLS 종료, WAF)는 없습니다. 이 프로젝트는 응용 계층 보안 데모이지 전체 배포 강화 가이드가 아닙니다.
가드레일 1의 정규식 기반 부분은 명시적으로 보조적이고 가능한 최선의 계층입니다. 실제로 의존하는 통제가 구분자 래핑인 이유는
docs/threat-model.md의 위험 #1을 참조하세요.
커밋된 비밀 정보 없음
MCP_JWT_SECRET은 환경에서 읽으며(.env.example 참고) 하드코딩되거나 커밋되지 않습니다. template_manifest.json은 의도적으로 커밋됩니다. 감사용 해시 매니페스트(lockfile처럼)이지 비밀 정보가 아닙니다.
This server cannot be deployed
Maintenance
Related MCP Connectors
Supervised API-write gateway for AI agents with policy, human approval and execution receipts.
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceGates agent tool execution with human approval, audit trails, and replay-resistant permits, enabling safe use of tools in agent loops.MIT
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.1-
- AlicenseNot gradedqualityCmaintenanceEnforces authenticated identity on every tool call and SSE frame, rotates vaulted credentials in place, and restricts tools via allowlists.71 npmMIT
- FlicenseNot gradedqualityBmaintenanceEnables support engineers to analyze tickets against a help center with cited retrieval, role-gated and human-confirmed actions, and safety-gated evaluation.1-