Skip to main content
Glama
AAH20

io.github.AAH20/agent-action-gate

by AAH20

Agent Action Gate

Gate/Prove runtime for agent and MCP tool calls.

Normalize tool intent → deny unknown → never treat model confidence as approval → HITL prove on destructive / provision / decommission → Action Ledger (hash chain).

Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.

Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.

Why this exists (revenue + cost)

AI-agent companies do not pay for “another MCP.” They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.

Cost driver

What this gate does

Buyer outcome

Ungated shell.exec / disable-control / decommission

DENY unless HITL prove token + approved

Avoid production blast

Agent “95% sure”

never_equate_intent_to_approval: true

Intent ≠ ledger proof

Write tools fire on first thought

Default SIMULATE (no side effects)

FDE minutes, not incident cost

No audit trail

Append-only Action Ledger with hash chain

Diligence packet

Hard rule: never equate agent intent or model score to human approval.

Illustrative cost sketch (not a quote): make bench.

Related MCP server: approval-gate

Quick start

make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench

Unattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.

export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"

Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.

MCP stdio server

This process never executes tools. Clients call gate_check before they would invoke a destructive tool.

PYTHONPATH=. python3 -m aag serve

Cursor / Claude example (mcpServers):

{
  "agent-action-gate": {
    "command": "python3",
    "args": ["-m", "aag", "serve"],
    "cwd": "/path/to/agent-action-gate",
    "env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
  }
}

Docker / registry image:

docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0

Official MCP Registry name: io.github.AAH20/agent-action-gate

Envelope

Every decision includes:

  • never_equate_intent_to_approval: true

  • allow_auto_execute (false on unattended high tiers)

  • mode: deny | simulate | allow

  • ledger_id / receipt_hash

  • CTAs: Instant Audit + consultation

Library mapper

Same Gate/Prove policy from Python without the stdio loop:

from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call

gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})

Fixtures (labeled, not payloads)

File

Technique

Expected

t1059_unattended_shell.json

T1059

DENY unattended destructive

t1078_read_identity.json

T1078

ALLOW read

t1562_impair_defenses.json

T1562

DENY unattended destructive

write_ticket_simulate.json

SIMULATE write

proved_decommission.json

T1578

ALLOW only with HITL token

Layout

aag/
  gate.py      HITL + kill-switch + unknown deny
  ledger.py    hash-chained JSONL
  server.py    MCP stdio (gate_check, ledger_verify)
  mcp.py       MCP tools/call mapper (no execution)
  cost.py      illustrative avoidance sketch
  demo.py      fixture runner
fixtures/      ATT&CK-tagged cases
server.json    MCP Registry metadata
tests/         Gate/Prove + MCP contract

Paid evaluation (not free prove)

If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:

$499 Instant Audit
consultation (sprint / vCISO)

Unpaid take-homes: refuse — run make demo and buy Instant Audit.

License

MIT

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Security-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical
    21
    12
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server that provides human-in-the-loop approval for risky AI agent actions, with durable state and audit logs.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    MCP server that provides a security gateway for AI agents, enforcing allow/confirm/deny policies on tool calls and requiring human approval for risky operations, with full audit logging.
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    An MCP server that acts as an authorization gateway between an AI agent and external systems, deterministically refusing actions that exceed granted authority and sealing every decision into an auditable chain of custody.
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/AAH20/agent-action-gate'

If you have feedback or need assistance with the MCP directory API, please join our Discord server