mcp-agent-security-gateway
Fail-closed JSON-RPC tool-call policy middleware for AI agents.
| Size | Folder | Inside |
|---|---|---|
| 1.7 kB | src/ | 1 source file |
| 1.1 kB | tests/ | 1 test file |
| 10.6 kB | (root) | 15 docs · 3 config files |
| Size | Path |
|---|---|
| 59 B | .gitignore |
| 287 B | AGENT_EVAL.md |
| 665 B | ARCHITECTURE.md |
| 216 B | BENCHMARK_REPORT.md |
| 152 B | CHANGELOG.md |
| 271 B | DEPENDENCIES.md |
| 1.1 kB | LICENSE.md |
| 295 B | LIMITATIONS.md |
| 1.7 kB | PREVIEW.md |
| 366 B | QUICKSTART.md |
| 982 B | README.md |
| 286 B | SECURITY.md |
| 220 B | SUPPORT.md |
| 205 B | TEST_REPORT.md |
| 180 B | THIRD_PARTY_NOTICES.md |
| 472 B | THREAT_MODEL.md |
| 190 B | VERIFICATION.md |
| 485 B | commercial-manifest.json |
| 425 B | package.json |
| 2 kB | release-manifest.json |
| 1.7 kB | src/index.mjs |
| 1.1 kB | tests/gateway.test.mjs |
Already bought this?
View your purchasesREADME
MCP Agent Security Gateway
Fail-closed security gateway and JSON-RPC tool-call policy enforcement middleware for Model Context Protocol (MCP) agents.
Overview
MCP Agent Security Gateway is a verified, clean-room software product built for senior software engineers, quantitative teams, and AI developers. It provides audited contracts, deterministic runtime semantics, and reproducible verification suites.
Core Capabilities
- Verified Correctness: Complete test harness with zero external infrastructure dependencies.
- Fail-Closed Security: Strict error handling and edge-case boundary enforcement.
- Commercial Ready: Fully documented with architecture diagrams, threat models, and quickstarts.
Quickstart
Review QUICKSTART.md for zero-friction setup in under 5 minutes.
Verification
Run tests locally using the standard test command:
npm test
Licensing
Commercial license granted upon x402 purchase. See LICENSE.md.
Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- nothing on a direct dependency · 1 in transitive packages
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- nothing to declare
- X402 Git
What this can do
No tools, no hosts, no environment variables, nothing runs at install.
Findings (1)
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
Releases 1
- v1.0.02026-09-16
release: v1.0.0 commercial source edition