Gate/Prove: deny unattended destructive agent tools. Instant Audit $499 on a2zsoc.com.
Gate/Prove runtime for agent and MCP tool calls.
Normalize tool intent → deny unknown → never treat model confidence as approval → HITL prove on destructive / provision / decommission → Action Ledger (hash chain).
Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.
Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.
AI-agent companies do not pay for “another MCP.” They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.
| Cost driver | What this gate does | Buyer outcome |
|---|---|---|
Ungated shell.exec / disable-control / decommission | DENY unless HITL prove token + approved | Avoid production blast |
| Agent “95% sure” | never_equate_intent_to_approval: true | Intent ≠ ledger proof |
| Write tools fire on first thought | Default SIMULATE (no side effects) | FDE minutes, not incident cost |
| No audit trail | Append-only Action Ledger with hash chain | Diligence packet |
Hard rule: never equate agent intent or model score to human approval.
Illustrative cost sketch (not a quote): make bench.
make demo
PYTHONPATH=. python3 -m aag demo
PYTHONPATH=. python3 -m aag check fixtures/t1059_unattended_shell.json
PYTHONPATH=. python3 -m aag bench
Unattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.
export AAG_PROVE_TOKEN='replace-me'
PYTHONPATH=. python3 -m aag check fixtures/proved_decommission.json --prove-token "$AAG_PROVE_TOKEN"
Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.
This process never executes tools. Clients call gate_check before they would invoke a destructive tool.
PYTHONPATH=. python3 -m aag serve
Cursor / Claude example (mcpServers):
{
"agent-action-gate": {
"command": "python3",
"args": ["-m", "aag", "serve"],
"cwd": "/path/to/agent-action-gate",
"env": { "PYTHONPATH": ".", "AAG_PROVE_TOKEN": "replace-me" }
}
}
Docker / registry image:
docker run --rm -i ghcr.io/aah20/agent-action-gate:0.2.0
Official MCP Registry name: io.github.AAH20/agent-action-gate
Every decision includes:
never_equate_intent_to_approval: trueallow_auto_execute (false on unattended high tiers)mode: deny | simulate | allowledger_id / receipt_hashSame Gate/Prove policy from Python without the stdio loop:
from aag.gate import AgentActionGate
from aag.mcp import evaluate_mcp_call
gate = AgentActionGate(prove_token="replace-me")
evaluate_mcp_call(gate, {"params": {"name": "shell.exec", "arguments": {"note": "no payload"}}})
| File | Technique | Expected |
|---|---|---|
t1059_unattended_shell.json | T1059 | DENY unattended destructive |
t1078_read_identity.json | T1078 | ALLOW read |
t1562_impair_defenses.json | T1562 | DENY unattended destructive |
write_ticket_simulate.json | — | SIMULATE write |
proved_decommission.json | T1578 | ALLOW only with HITL token |
aag/
gate.py HITL + kill-switch + unknown deny
ledger.py hash-chained JSONL
server.py MCP stdio (gate_check, ledger_verify)
mcp.py MCP tools/call mapper (no execution)
cost.py illustrative avoidance sketch
demo.py fixture runner
fixtures/ ATT&CK-tagged cases
server.json MCP Registry metadata
tests/ Gate/Prove + MCP contract
If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:
→ $499 Instant Audit
→ consultation (sprint / vCISO)
Unpaid take-homes: refuse — run make demo and buy Instant Audit.
MIT
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.
https://github.com/AAH20/agent-action-gate/releases/download/v0.2.0/agent-action-gate.mcpbotherAgent Action Gate works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.