Agentโ™ฅ๏ธŽAge
Catalog

io.github.Rul1an/assay

Officialdeprecated

by Rul1an ยท Rust

The firewall for MCP tool calls. Block, audit, replay with evidence bundles.

The firewall for MCP tool calls. Block, audit, replay with evidence bundles. A deterministic, fail-closed gate for MCP tool calls that provides kernel-level enforcement on Linux and offline-verifiable evidence, with CI-native use and no backend by design.

๐Ÿ› ๏ธ Key Features

  • Policy-as-code enforcement for MCP tool calls
  • Fail-closed, deterministic gate that blocks unauthorized tool actions
  • Kernel-level enforcement concepts (eBPF/LSM) on Linux
  • Evidence bundles for offline verification and auditing
  • CI-native integration with no backend required

๐Ÿš€ Use Cases

  • Enforce what MCP agents can do and prove what they did
  • Audit MCP tool calls and generate verifiable evidence
  • Replay tool calls for incident investigation
  • Ensure provenance and supply-chain security for MCP workflows

โšก Developer Benefits

  • Ground-truth enforcement with verifiable evidence
  • Lightweight, CI-native, no backend architecture
  • Integrates with policy-as-code workflows for MCP
  • Supports offline verification and deterministic behavior

โš ๏ธ Limitations

  • Kernel-level enforcement relies on Linux capabilities (eBPF/LSM)
  • May require platform-specific setup for evidence capture
  • Documentation and examples may evolve with ongoing updates

Topics

rustai-agentsmcppolicy-as-codeai-securitymcp-serverpolicy-enforcementagent-securitycicyclonedxevidence-bundlesgithub-actionsopenfeaturepromptfooprovenancesbomsupply-chain-securityebpfllm-securitymcp-security

Related servers

More in Security