SecureAgentServer
Безопасная система агентов MCP
Сервер и клиент MCP для тикетов поддержки и клиентских аккаунтов, созданные и защищённые сквозным образом: аутентификация по подписанным токенам, два независимых рубежа защиты от prompt-инъекций и подмены инструментов, документированная модель угроз и обязательный контроль человеком для единственного разрушительного вызова инструмента. Разработано для лабораторной работы «Secure an MCP-Based Agent System».
Архитектура
flowchart TD
HOST["Host application"] --> CLIENT["client.py\n(fastmcp.Client + elicitation_handler)"]
CLIENT <-->|"Streamable HTTP\nAuthorization: Bearer <signed JWT>"| SERVER
subgraph Server["server.py — FastMCP('SecureAgentServer')"]
AUTH["JWTVerifier (HS256)\nissuer + audience + signature checked"]
G1["Guardrail 1: sanitize_untrusted_text()\napplied to ticket body/subject"]
G2["Guardrail 2: verify_tool_manifest()\nchecked at startup, refuses to start on mismatch"]
TOOLS["Tools: search_tickets, lookup_customer_account,\nclose_ticket (elicitation-gated)"]
AUTH --> TOOLS
TOOLS --> G1
end
G2 -.->|startup check| SERVER
TOOLS --> TICKETS[("data/tickets.json\n(untrusted customer text)")]
TOOLS --> CUSTOMERS[("data/customers.json\n('internal API')")]Related MCP server: permitd MCP Server
Настройка
pip install -r requirements.txt
# 1. Set the JWT signing secret (never commit the real value; see .env.example)
export MCP_JWT_SECRET="a-long-random-secret-at-least-32-characters"
# 2. Generate the pinned tool-integrity manifest (a deliberate, manual step —
# see docs/threat-model.md Risk #2)
python generate_manifest.py
# 3. Run the server
python server.py
# 4. In another terminal (same MCP_JWT_SECRET exported)
python client.py --auto-confirm # non-interactive demo
python client.py # interactive: real yes/no confirmation promptsВоспроизведение мер безопасности
Мера безопасности | Как её проверить |
Аутентификация на основе подписанных JWT | Два последних демонстрационных примера в |
Рубеж 1: санитизация prompt-инъекций | Запустите клиент и посмотрите результат |
Рубеж 2: обнаружение подмены инструментов |
|
Обязательный контроль человека над разрушительными действиями | в демонстрационном журнале |
Разграничение по принципу наименьших привилегий |
|
Модель угроз
Полное описание, включающее 5 выявленных рисков с мерами смягчения и явно указанными замечаниями об остаточных рисках, а не замолчаянных: docs/threat-model.md.
Что намеренно вынесено за рамки, сказано прямо
mint_token.pyзаменяет реального провайдера удостоверений OAuth 2.1 — в продакшене нужно настоящее выпуск/перевыпуск/отзыв токенов, а не локальный скрипт.Нет ограничения скорости или усиления на сетевом уровне (завершение TLS, WAF) — это демонстрация безопасности на прикладном уровне, а не полное руководство по защите развёртывания.
Основанная на regex-часть рубежа 1 явно вспомогательная, работающая по принципу best-effort — см. риск № 1 в
docs/threat-model.mdо том, почему именно обёртка разделителем является основной действующей мерой.
Без секретов в репозитории
MCP_JWT_SECRET считывается из окружения (см. .env.example) и никогда не захардкожен и не коммитится. tool_manifest.json намеренно находится в коммите — это зафиксированный хэш-манифест (вроде lockfile), а не секрет.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseNot gradedqualityCmaintenanceProvides a set of tools with a security verification layer that assesses risk and requires human approval for high-risk actions, reducing prompt injection and tool-poisoning attacks.
- AlicenseNot gradedqualityCmaintenanceGates agent tool execution with human approval, audit trails, and replay-resistant permits, enabling safe use of tools in agent loops.MIT
- FlicenseNot gradedqualityBmaintenanceProvides a secure MCP boundary for AI agents, intercepting and validating tool calls, redacting secrets, and requiring human approval for sensitive actions with a tamper-evident audit trail.
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.
Related MCP Connectors
Runtime permission, approval, and audit layer for AI agent tool execution.
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Responsible-AI guardrails for agents: scoring with policy, injection & PII detection, DPDP.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bhargavlukka/secure-mcp-agent'
If you have feedback or need assistance with the MCP directory API, please join our Discord server