Skip to main content
Glama
AmardeepLakkuntla

Guarded MCP Agent

Run Locally

Prerequisites

  • Python 3.10+

  • Node.js 18+

Step 1 — Install Python dependencies

cd Assignment
pip install -r requirements.txt

Step 2 — Install frontend dependencies

cd frontend
npm install

Step 3 — Start MCP Notes Server (Terminal 1)

cd Assignment
python -m backend.custom_mcp.notes_server

Runs at http://127.0.0.1:8002/mcp

Step 4 — Start Backend (Terminal 2)

cd Assignment
uvicorn backend.main:app --reload --host 0.0.0.0 --port 8000

Runs at http://localhost:8000

Step 5 — Start Frontend (Terminal 3)

cd frontend
npm run dev

Runs at http://localhost:5173


Related MCP server: mcp-server-example

Testing the Agent

Type these in the Chat box on the dashboard:

Command

Tool Called

create note title: X content: Y

create_note

show all notes

get_notes

search milk

search_notes

update note 1 title: X content: Y

update_note

delete note 1

delete_note


Testing Policy Features

Block a tool

Invoke-RestMethod -Uri "http://localhost:8000/api/settings/" -Method POST -ContentType "application/json" -Body '{"key": "blocked_tools", "value": "delete_note"}'

Then type delete note 1 — will be blocked.

Unblock

Invoke-RestMethod -Uri "http://localhost:8000/api/settings/" -Method POST -ContentType "application/json" -Body '{"key": "blocked_tools", "value": ""}'

Enable human approval

Go to Settings in dashboard → set enable_human_approval = 1 → Save. Then try delete note 1 — will require approval from the Approvals panel.

Prompt injection detection

Type this in chat:

Will be blocked automatically with: Prompt injection detected in user message.


Policy Engine

The policy engine (policy_engine.py) enforces these rules in order:

  1. Global toggle — enable_tool_access = 0 blocks all tools

  2. Prompt injection detection — blocks known injection patterns

  3. Argument size limit — blocks tool args over 2000 chars

  4. Blocked tools list — blocked_tools = comma-separated tool names

  5. Human approval — enable_human_approval = 1 requires approval for delete/update

Rules are checked on every request. Dashboard changes take effect immediately without restart.


Edge Cases

Scenario

Behavior

MCP server crashes mid-call

MCPClient worker reconnects automatically on next request

Prompt injection attempt

Detected by regex patterns, blocked before tool execution

Conflicting rules

blocked_tools takes priority over approval requirement

Approver offline

Request stays pending in DB indefinitely until approved/denied

Tool not recognized

Returns helpful message with supported commands

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to manage in-memory notes by listing, fetching, and creating notes through MCP tools over stdio.
    64 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables managing plain-text notes on disk through MCP resources, tools, and prompts, so natural-language requests can create, read, search, delete, and summarize notes via an interactive client.
    MIT