X402 Git

mcp-agent-security-gateway

Fail-closed JSON-RPC tool-call policy middleware for AI agents.

Top level of the repository
SizeFolderInside
1.7 kBsrc/1 source file
1.1 kBtests/1 test file
10.6 kB(root)15 docs · 3 config files
22 files · 13.4 kB · computed 2026-09-16
SizePath
59 B.gitignore
287 BAGENT_EVAL.md
665 BARCHITECTURE.md
216 BBENCHMARK_REPORT.md
152 BCHANGELOG.md
271 BDEPENDENCIES.md
1.1 kBLICENSE.md
295 BLIMITATIONS.md
1.7 kBPREVIEW.md
366 BQUICKSTART.md
982 BREADME.md
286 BSECURITY.md
220 BSUPPORT.md
205 BTEST_REPORT.md
180 BTHIRD_PARTY_NOTICES.md
472 BTHREAT_MODEL.md
190 BVERIFICATION.md
485 Bcommercial-manifest.json
425 Bpackage.json
2 kBrelease-manifest.json
1.7 kBsrc/index.mjs
1.1 kBtests/gateway.test.mjs
computed 2026-09-16 21:31 UTC · analyzer 0.1.0

Already bought this?

View your purchases

README

MCP Agent Security Gateway

Fail-closed security gateway and JSON-RPC tool-call policy enforcement middleware for Model Context Protocol (MCP) agents.


Overview

MCP Agent Security Gateway is a verified, clean-room software product built for senior software engineers, quantitative teams, and AI developers. It provides audited contracts, deterministic runtime semantics, and reproducible verification suites.

Core Capabilities

  • Verified Correctness: Complete test harness with zero external infrastructure dependencies.
  • Fail-Closed Security: Strict error handling and edge-case boundary enforcement.
  • Commercial Ready: Fully documented with architecture diagrams, threat models, and quickstarts.

Quickstart

Review QUICKSTART.md for zero-friction setup in under 5 minutes.

Verification

Run tests locally using the standard test command:

npm test

Licensing

Commercial license granted upon x402 purchase. See LICENSE.md.

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
nothing to declare
X402 Git

What this can do

No tools, no hosts, no environment variables, nothing runs at install.

Findings (1)
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible

Releases 1

  1. v1.0.02026-09-16

    release: v1.0.0 commercial source edition

$149updates $39

Buy — go to the order block