Skip to main content
Back to all repositories

Policy-as-code for MCP agents: deny risky tool calls before they run, prove what ran with verifiable evidence, and enforce egress in the kernel (eBPF/LSM, Linux). Deterministic, offline-first, bounded claims.

9stars1forks1watchers/subscribers51issues
agent-securityai-agentsai-securitycicyclonedxebpfevidence-bundlesgithub-actionsllm-securitymcpmcp-securitymcp-serveropenfeaturepolicy-as-codepolicy-enforcementpromptfooprovenancerustsbomsupply-chain-security
Language
Rust
License
MIT License
Size
225.1 MB
Created
Dec 20, 2025
Last Updated
Sep 4, 2026
Last Pushed
Sep 4, 2026

Available Plugins

Loading plugins...

Evaluate before installing

  1. Review the source repository, recent maintenance, and license on GitHub.
  2. Read the marketplace manifest and plugin source files before running commands.
  3. Start with the smallest required permission set and validate behavior in a safe environment.