AAH20

Agent Action Gate

Community AAH20
Updated

Gate/Prove runtime for agent and MCP tool calls. Unattended destructive tools DENY. Instant Audit + consultation on a2zsoc.com.

Agent Action Gate

Gate/Prove runtime for agent and MCP tool calls.

Normalize tool intent → deny unknown → never treat model confidence as approval → HITL prove on destructive / provision / decommission → Action Ledger (hash chain).

Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.

Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.

Why this exists (revenue + cost)

AI-agent companies do not pay for “another MCP.” They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.

Cost driver What this gate does Buyer outcome
Ungated shell.exec / disable-control / decommission DENY unless HITL prove token + approved Avoid production blast
Agent “95% sure” never_equate_intent_to_approval: true Intent ≠ ledger proof
Write tools fire on first thought Default SIMULATE (no side effects) FDE minutes, not incident cost
No audit trail Append-only Action Ledger with hash chain Diligence packet

Hard rule: never equate agent intent or model score to human approval.

Illustrative cost sketch (not a quote): make bench.

Quick start

make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench

Unattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.

export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"

Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.

MCP stdio server

This process never executes tools. Clients call gate_check before they would invoke a destructive tool.

PYTHONPATH=. python3 -m aag serve

Cursor / Claude example (mcpServers):

{
  "agent-action-gate": {
    "command": "python3",
    "args": ["-m", "aag", "serve"],
    "cwd": "/path/to/agent-action-gate",
    "env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
  }
}

Docker / registry image:

docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0

Official MCP Registry name: io.github.AAH20/agent-action-gate

Envelope

Every decision includes:

  • never_equate_intent_to_approval: true
  • allow_auto_execute (false on unattended high tiers)
  • mode: deny | simulate | allow
  • ledger_id / receipt_hash
  • CTAs: Instant Audit + consultation

Library mapper

Same Gate/Prove policy from Python without the stdio loop:

from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call

gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})

Fixtures (labeled, not payloads)

File Technique Expected
t1059_unattended_shell.json T1059 DENY unattended destructive
t1078_read_identity.json T1078 ALLOW read
t1562_impair_defenses.json T1562 DENY unattended destructive
write_ticket_simulate.json SIMULATE write
proved_decommission.json T1578 ALLOW only with HITL token

Layout

aag/
  gate.py      HITL + kill-switch + unknown deny
  ledger.py    hash-chained JSONL
  server.py    MCP stdio (gate_check, ledger_verify)
  mcp.py       MCP tools/call mapper (no execution)
  cost.py      illustrative avoidance sketch
  demo.py      fixture runner
fixtures/      ATT&CK-tagged cases
server.json    MCP Registry metadata
tests/         Gate/Prove + MCP contract

Paid evaluation (not free prove)

If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:

$499 Instant Auditconsultation (sprint / vCISO)

Unpaid take-homes: refuse — run make demo and buy Instant Audit.

License

MIT

MCP Server · Populars

MCP Server · New

    byenzyme

    🧬 Enzyme

    A compile step for knowledge bases. Gives your agent a concept graph of your content — under 20s to index, 8ms queries on device.

    Community byenzyme
    Vladimir-Human

    ru-marketplace-mcp

    Девять российских маркетплейсов и китайский Taobao как MCP-серверы: Wildberries, Ozon, Яндекс Маркет, Детский мир, Авито, Мегамаркет, Lamoda, DNS, Ситилинк. Плюс сравнение цен по всем сразу. Только чтение, ключи не нужны.

    Community Vladimir-Human
    JanYork

    LWC — Proactive Memory for AI Agents

    Agent-driven proactive memory CLI for AI agents — autonomously recall, maintain, and evolve persistent, source-grounded knowledge across sessions.

    Community JanYork
    mixelpixx

    Konnect *BETA Release

    AI-assisted PCB design for KiCAD 10. Native KiCAD plugin — a single Rust binary exposing 171 schematic, layout, routing, design-review, and manufacturing tools to Claude, or the LLM of your choosing

    Community mixelpixx
    mixelpixx

    Nimrod

    Web research for Claude over MCP: quality-scored Google search, clean extraction, deep research. Hosted connector for claude.ai/Desktop/Code + Nimrod Desktop toolkit (skills, agent, hooks).

    Community mixelpixx