MCP Human Approval Gateway
A public-safe research prototype for controlling AI-agent tool actions with deterministic policy, risk-based human approval, time-bound authorization and a tamper-evident audit chain.
README
MCP Human Approval Gateway
A public-safe research prototype for controlling AI-agent tool actions with deterministic policy, risk-based human approval, time-bound authorization and a tamper-evident audit chain.
The project demonstrates a strict separation of responsibility:
- AI explains and recommends. Its analysis is advisory and cannot change a policy outcome.
- Deterministic policy decides. Registered tools, actions, scopes, environments and data classifications produce a reproducible decision.
- Humans authorize high-impact actions. Role-qualified reviewers approve or deny requests with a recorded rationale.
- The execution guard enforces the result. Approvals expire, can be consumed once and cannot be replayed.
All included names, resources, identities and actions are synthetic. The prototype contains no employer architecture, production credentials, customer data or confidential control implementations.
What the lab demonstrates
- Low-risk public research can be auto-approved.
- Private source access enters a human-review queue.
- Restricted credential metadata requires elevated review while secret values remain unavailable to the AI analyst.
- Production privilege changes require a security lead.
- Prompt-injected context is treated as untrusted data and denied.
- Runtime scope expansion is denied and must be submitted as a new request.
- Unregistered tools fail closed.
- Expired or already-consumed approvals cannot execute.
- Audit-event modification is detected by hash-chain verification.
Run locally
Prerequisite: Node.js 24 or newer. The prototype uses the built-in
node:sqlite API.
npm install
npm run build
npm start
Open http://localhost:4174.
For frontend development:
npm run dev:server
npm run dev:client
The Vite client runs on http://localhost:5174 and proxies API calls to port
4174.
Verify
npm run check
The automated suite covers policy outcomes, reviewer authorization, atomic decision commits, approval expiry, single-use execution, audit tamper detection, HTTP validation and browser security headers.
Optional AI analyst
The lab works fully offline with a deterministic analyst. An OpenAI-compatible chat-completions endpoint can be configured through environment variables:
cp .env.example .env
The external analyst receives sanitized request metadata, never raw credential values. Provider failure falls back to the offline analyst. In every mode, the model output remains advisory.
Design documents
- Architecture
- Workflows
- Threat model
- Evaluation plan and evidence
- Deployment guide
- Security assumptions and production gaps
- API contract
Standards and research basis
The control design is informed by:
- NIST AI RMF Generative AI Profile
- NIST AI RMF Playbook
- NIST Cyber AI Profile preliminary draft
- OWASP MCP Top 10: Privilege Escalation via Scope Creep
- OWASP MCP Top 10: Context Injection and Over-Sharing
- OWASP Top 10 for Agentic Applications
- CISA JCDC AI Cybersecurity Collaboration Playbook
- NIST SP 800-63-4 Digital Identity Guidelines
These references inform the design; they do not constitute certification or formal compliance.
GitHub Pages browser demonstration
The GitHub Pages edition is a browser-only synthetic simulation. It allows visitors to explore deterministic policy decisions, human approval, time-limited authorization, guarded execution, replay blocking and audit-chain verification without connecting to real systems.
Each visitor has independent demonstration state stored only in their browser. Use Reset Lab to remove that state.
The browser demonstration does not provide enterprise identity proofing, shared approval queues, server-side policy enforcement, durable audit storage, multi-user coordination or cross-tab transaction locking. The Node.js and SQLite implementation remains the reference full-stack research prototype.
No production systems, company information, customer data, credentials or API keys are used by the demonstration.
Important scope boundary
This is an educational security prototype, not a production authorization service. It simulates tool execution and intentionally omits enterprise identity proofing, durable key management, multi-node transaction coordination and append-only external audit storage. See SECURITY.md before adapting any part of it.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。