io.github.AAH20/agent-action-gate
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@io.github.AAH20/agent-action-gateCheck if shell.exec 'rm -rf /tmp' is approved"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agent Action Gate
Gate/Prove runtime for agent and MCP tool calls.
Normalize tool intent → deny unknown → never treat model confidence as approval → HITL prove on destructive / provision / decommission → Action Ledger (hash chain).
Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.
Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.
Why this exists (revenue + cost)
AI-agent companies do not pay for “another MCP.” They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.
Cost driver | What this gate does | Buyer outcome |
Ungated | DENY unless HITL prove token + | Avoid production blast |
Agent “95% sure” |
| Intent ≠ ledger proof |
Write tools fire on first thought | Default SIMULATE (no side effects) | FDE minutes, not incident cost |
No audit trail | Append-only Action Ledger with hash chain | Diligence packet |
Hard rule: never equate agent intent or model score to human approval.
Illustrative cost sketch (not a quote): make bench.
Related MCP server: approval-gate
Quick start
make demoPYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag benchUnattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.
MCP stdio server
This process never executes tools. Clients call gate_check before they would invoke a destructive tool.
PYTHONPATH=. python3 -m aag serveCursor / Claude example (mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}Docker / registry image:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0Official MCP Registry name: io.github.AAH20/agent-action-gate
Envelope
Every decision includes:
never_equate_intent_to_approval: trueallow_auto_execute(false on unattended high tiers)mode:deny|simulate|allowledger_id/receipt_hashCTAs: Instant Audit + consultation
Library mapper
Same Gate/Prove policy from Python without the stdio loop:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})Fixtures (labeled, not payloads)
File | Technique | Expected |
| T1059 | DENY unattended destructive |
| T1078 | ALLOW read |
| T1562 | DENY unattended destructive |
| — | SIMULATE write |
| T1578 | ALLOW only with HITL token |
Layout
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contractPaid evaluation (not free prove)
If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:
→ $499 Instant Audit
→ consultation (sprint / vCISO)
Unpaid take-homes: refuse — run make demo and buy Instant Audit.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Hosted MCP server for AI agent identity, permissions, verification, and reusable proof.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Related MCP Servers
- AlicenseAqualityAmaintenanceSecurity-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical2113Apache 2.0
- AlicenseNot gradedqualityCmaintenanceMCP server that provides human-in-the-loop approval for risky AI agent actions, with durable state and audit logs.MIT
- FlicenseNot gradedqualityCmaintenanceMCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.-
- FlicenseNot gradedqualityBmaintenanceAn MCP server that acts as an authorization gateway between an AI agent and external systems, deterministically refusing actions that exceed granted authority and sealing every decision into an auditable chain of custody.-