Gate/Prove: deny unattended destructive agent tools. Instant Audit $499 on a2zsoc.com.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Gate/Prove runtime for agent and MCP tool calls.
Normalize tool intent β deny unknown β never treat model confidence as approval β HITL prove on destructive / provision / decommission β Action Ledger (hash chain).
Extracted from GRC_Claw @grc-claw/agent-policy-firewall. This repo is the sharp foundry slice: one command, no cathedral.
Commercial (how this is sold): $499 Instant Audit and consultation on a2zsoc.com.
AI-agent companies do not pay for βanother MCP.β They pay to stop unattended destructive tools and to prove Gate/Prove gaps before SOC 2 Type I, PE diligence, or insurance renewal.
| Cost driver | What this gate does | Buyer outcome |
|---|---|---|
Ungated shell.exec / disable-control / decommission | DENY unless HITL prove token + approved | Avoid production blast |
| Agent β95% sureβ | never_equate_intent_to_approval: true | Intent β ledger proof |
| Write tools fire on first thought | Default SIMULATE (no side effects) | FDE minutes, not incident cost |
| No audit trail | Append-only Action Ledger with hash chain | Diligence packet |
Hard rule: never equate agent intent or model score to human approval.
Illustrative cost sketch (not a quote): make bench.
Unattended high-tier calls DENY even at 0.99 confidence. ALLOW needs AAG_PROVE_TOKEN (or --prove-token) and approved: true.
Kill-switch: AAG_KILL_SWITCH=1 or touch artifacts/KILL.
This process never executes tools. Clients call gate_check before they would invoke a destructive tool.
Cursor / Claude example (mcpServers):
Docker / registry image:
Official MCP Registry name: io.github.AAH20/agent-action-gate
Every decision includes:
never_equate_intent_to_approval: trueallow_auto_execute (false on unattended high tiers)mode: deny | simulate | allowledger_id / receipt_hashSame Gate/Prove policy from Python without the stdio loop:
| File | Technique | Expected |
|---|---|---|
t1059_unattended_shell.json | T1059 | DENY unattended destructive |
t1078_read_identity.json | T1078 | ALLOW read |
t1562_impair_defenses.json | T1562 | DENY unattended destructive |
write_ticket_simulate.json | β | SIMULATE write |
proved_decommission.json | T1578 | ALLOW only with HITL token |
If you deploy agents or MCP servers and need a Gate/Prove read before SOC 2, PE diligence, or insurance:
β $499 Instant Audit
β consultation (sprint / vCISO)
Unpaid take-homes: refuse β run make demo and buy Instant Audit.
MIT
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/agent-action-gate)<a href="https://allmcps.com/mcp/agent-action-gate"><img src="https://allmcps.com/api/badge/agent-action-gate?style=directory" alt="Agent Action Gate on AllMCPs" /></a>