
AegisGate MCP
io.github.aegisgatesecurityv1.3.0更新于 Oct 9, 2026
Secure MCP server framework with 22 security layers and ML threat detection. Zero dependencies.
概览
一个用 Go 编写的加固型 MCP 服务器框架,为工具调用提供身份验证、RBAC、策略、审计日志和基于机器学习的威胁检测。
- 功能
- AegisGate MCP 是一个自包含的 MCP 服务器框架,位于 AI 代理与其调用的工具之间,对每个请求应用 22 层安全防护。它提供 Bearer 令牌和 API 密钥身份验证、带按工具权限的四级 RBAC、支持允许/拒绝规则的策略引擎、速率限制、用于检测权限提升和数据外泄链的链式分析、带机密信息脱敏的响应扫描、防篡改审计日志,以及可选的神经威胁检测。它支持 TCP、stdio 和 Streamable HTTP 传输、TLS/mTLS、健康检查端点,并可作为 Go 库嵌入。提供演示工具(ping、system_info、echo)用于测试。
- 适用场景
- 当你需要在工具调用必须经过身份验证、授权、速率限制和审计的环境中运行或构建 MCP 服务器时使用,例如生产、企业或气隙部署。它也适合将安全控制嵌入自定义 Go MCP 服务器,而不是从裸 SDK 开始。
- 运行要求
- 作为本地进程运行;清单声明使用 stdio 传输,未声明环境变量或请求头。README 说明需要 Go 1.26+ 构建,或使用 Docker 镜像(ghcr.io/aegisgatesecurity/aegisgate-mcp:1.3.0,amd64/arm64)。可选配置包括 Bearer 令牌(MCP_AUTH_TOKEN)、审计日志路径(MCP_AUDIT_LOG)、TLS 证书和密钥文件,以及用于神经检测的 ONNX 模型路径(MCP_ML_MODEL)。
安装
在 SourceWeft 中
- 打开 控制台中的 AegisGate MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
🛡️ AegisGate MCP
Secure MCP server framework — 22 layers of defense, zero dependencies.
A hardened, zero-dependency MCP server written in pure Go. Build your MCP server on a foundation that has security built in from line one — not bolted on after a breach.
Apache 2.0 · 22 security layers · 30 regex patterns + CharCNN-BiLSTM (v13) ML detection · Zero CVEs · Zero external module dependencies
[License: Apache 2.0] [Go] [Version] [Coverage] [Dependencies] [Docker] [ML] [Arch] [CI] [Security] [Patent Pending]
Quick Start · Security Layers · RBAC · Architecture · Protocol · Docs · Releases
[GitHub stars] — If AegisGate MCP helps you secure your AI agents, please consider ⭐ starring this repo. It helps others discover it.
AegisGate Security™ is a trademark of AegisGate Security, LLC, filed with the USPTO. "AegisGate MCP" is an unregistered product name. See Trademark below.
Why AegisGate MCP?
38% of MCP servers have no authentication. 590+ security advisories. 3 critical CVEs in the official MCP SDKs in 6 months — including CVSS 9.8 remote code execution and the "Mother of All AI Supply Chains" flaw affecting 150M+ downloads.
The official MCP SDKs give you the protocol. They don't give you security. No authentication. No audit logging. No threat detection. No rate limiting. No RBAC. Every server built on a bare SDK starts with a blank security posture and it's on you to build it — or skip it, as 38% of servers do.
AegisGate MCP is the secure alternative. Build your MCP server on a foundation that has security built in from line one — not bolted on after a breach.
22 security layers. Zero dependencies. Zero CVEs. Apache 2.0.
Need proxy mode, OAuth, SIEM, or compliance frameworks? See When to Upgrade to AegisGate Platform below — or explore AegisGate Rampart for local AI API proxy protection.
Overview
AegisGate MCP is a hardened, zero-dependency MCP server written in pure Go. It sits between AI agents and the tools they call, applying 22 layers of defense to every request — from authentication and RBAC to neural threat detection and chain analysis.
Standard MCP servers assume a trusted local environment. In production — whether that's a cloud SaaS platform, an enterprise data pipeline, or an air-gapped plant network — agents may execute commands, query databases, or interact with critical systems. A single unauthorized or malicious tool call can cause data exfiltration, process disruption, or worse. AegisGate MCP wraps every tool call in defense-in-depth, all with zero external module dependencies so it can run air-gapped.
Quick Start
Build
Run
Docker
The default Docker image uses debian:bookworm-slim with CGO enabled,
including the vendored ONNX Runtime and CharCNN-BiLSTM v13 model for
full neural threat detection. A --build-arg CGO_ENABLED=0 variant
produces a smaller heuristic-only image. Multi-arch builds support
both linux/amd64 and linux/arm64.
ML Threat Detection (L3)
AegisGate MCP includes the same CharCNN-BiLSTM v13 neural model used by AegisGate Platform and Rampart — vendored with zero external module dependencies. The model provides:
- Semantic attack detection — catches prompt injection and jailbreak attempts that bypass regex pattern matching
- Evasion resistance — detects obfuscation techniques (leetspeak, Unicode homoglyphs, character transposition, vowel deletion, word reversal)
- Two-tier blocking — scores ≥0.95 block independently; scores 0.50–0.94 block only if L1 (regex) or L2 (input scanner) corroboration is present
- Shadow mode — log predictions without blocking (for calibration)
- Heuristic fallback — when CGO is unavailable, heuristic scoring provides baseline detection without ONNX
Library Usage
AegisGate MCP can be embedded as a Go library:
See examples/simple-server/ for a complete working example that registers a tool, resource, and prompt.
ML Model Hot-Swap
Reload the neural threat detection model at runtime without restarting the server:
Tool Poisoning Detection
All tools registered via RegisterTool() are automatically scanned for prompt injection in their descriptions and inputSchema. To scan manually:
Security Layers
AegisGate MCP applies 22 security layers to every request, in order:
⚙️ Configuration
Configuration Priority
Configuration is resolved in order of highest to lowest priority:
- CLI flags — override everything
- Environment variables — override config file
- JSON config file (
--config) — overrides built-in defaults - Built-in defaults
CLI Flags
All CLI flags have environment variable equivalents:
JSON Config File
Transport Modes
Health Endpoints
When --health-addr is set, a separate HTTP listener provides observability endpoints:
🔐 RBAC & Policy Engine
RBAC Roles
AegisGate MCP enforces a 4-tier role hierarchy. Roles are ordered: restricted < standard < privileged < admin.
Role comparison uses AgentRole.AtLeast() — a privileged agent can access any tool that requires standard or restricted, but not tools that require admin.
Policy Engine
The Policy Engine evaluates allow/deny rules before any tool executes. Rules support:
- Tool name matching — exact names and wildcard patterns
- Agent role conditions — apply rules only to specific roles
- Risk score thresholds — trigger on
RiskAbovevalues - Priorities — higher-priority rules evaluated first
- Time windows — restrict tools to specific time ranges
- Parameter patterns — match against tool call parameters
- Actions — allow, deny (with reason), log level, risk modifiers
Built-in Policy Rules
Loaded via LoadDefaultPolicies():
Custom rules can be added programmatically:
Chain Analysis
The Chain Analyzer tracks sequences of tool calls within a session (rolling window of 20 calls) and flags suspicious patterns:
When any flag is raised, the chain risk is set to High and the event is logged at WARN level with the session ID, flags, and call count.
✍️ Signature Verification
AegisGate MCP supports ECDSA P-256 message signing to prevent request forgery and tampering.
Clients sign the canonical JSON of each request (with Signature and KeyID fields zeroed out)
and include the signature in the request header.
Server Setup
Client Signing (example)
The server verifies the signature using ecdsa.VerifyASN1 against the trusted public key.
If no KeyID or Signature is present, verification is skipped — allowing interoperability
with unsigned clients while enforcing signatures for clients that provide them.
🧪 Testing & Performance
Test Coverage
Running Tests
Performance Characteristics
Validated via the load test suite (//go:build load):
📦 Zero Module Dependencies
AegisGate MCP has zero external module dependencies. The go.mod file contains
no require directives. All third-party code (ONNX Runtime bindings, Unicode
normalization, ML model) is vendored into internal/, lib/, and models/.
Vendored components (see NOTICE for full attribution):
Why this matters:
- Air-gapped deployment — no
go mod downloadneeded, no supply chain risk - No transitive dependencies — nothing to audit beyond vendored code
- Reproducible builds — the binary is identical across builds
- Minimal attack surface — all third-party code is visible and auditable
- Fast compilation — no dependency resolution overhead
🏗️ Architecture & Protocol
Architecture
Request flow:
- TCP Client connects (optionally over TLS/mTLS) or stdio sends JSON-RPC via stdin
- Auth Middleware validates bearer token/API key (constant-time), verifies ECDSA signature, creates/validates session
- Guardrails enforce rate limits, session limits, and run chain analysis
- Response Scan (pre-execution parameter validation happens in handler)
- Request Handler checks RBAC permissions, evaluates Policy Engine rules, validates required parameters against
inputSchema, executes tool with timeout - Response Scan (post-execution) scans tool output for PII, secrets, XSS, prompt injection; redacts if enabled
- Audit Log records the complete action chain
MCP Protocol Support
AegisGate MCP implements the following JSON-RPC methods (MCP Protocol 2025-06-18):
Streamable HTTP session management (v1.2.2+):
POST /mcpwithinitialize→ response includesMcp-Session-IdheaderPOST /mcpwith subsequent requests → must includeMcp-Session-IdheaderDELETE /mcpwithMcp-Session-Idheader → terminates session (204 No Content)- Sessions expire after 30 minutes of inactivity
🏭 Use Cases & Deployment Scenarios
AegisGate MCP serves any environment where AI agents interact with tools — from cloud SaaS platforms to enterprise data pipelines to OT/ICS plant networks. The same 21 security layers apply regardless of deployment context.
General Deployments
- Cloud SaaS — protect user-facing AI features from prompt injection and data exfiltration
- Enterprise data access — enforce RBAC and audit logging on agent-driven database queries
- CI/CD automation — restrict what AI-assisted pipelines can execute
- Air-gapped networks — zero dependencies means the server runs with no internet access
OT/ICS Environments
In an OT/ICS environment, AegisGate MCP sits between AI agents and critical infrastructure tools:
Typical deployment scenarios:
- Read-only monitoring agent —
restrictedrole, can query SCADA status and historian data but cannot issue commands - Maintenance agent —
standardrole, can read files and search code during troubleshooting - Operations agent —
privilegedrole, can interact with most tools but cannot execute shell commands - Admin agent —
adminrole, full access for authorized maintenance windows
Security features particularly relevant to OT/ICS:
- TLS/mTLS encrypts all traffic on the plant network
- Time-window policies restrict high-risk tools to maintenance windows
- Chain analysis detects if an agent reads sensitive process data then attempts an external network write (exfiltration)
- Audit logging provides a complete chain of custody for compliance (NERC CIP, IEC 62443)
- Air-gapped operation — zero dependencies means the server can be deployed on isolated networks with no internet access
Demo Tools
Enable demo tools with the --demo flag or by calling RegisterDemoTools() in library mode.
These are safe, read-only tools that do not access the filesystem, network, or any external resources.
Example — system_info response:
Documentation
Detailed documentation is available in the docs/ directory:
Changelog
See CHANGELOG.md for version history and notable changes.
When to Upgrade to AegisGate Platform
AegisGate MCP is a standalone secure MCP server framework — perfect for building and running MCP servers with security built in. It's free, open source, and has zero external dependencies.
When your needs grow beyond a single server, AegisGate Platform is the natural upgrade path:
Think of it this way: AegisGate MCP is the secure foundation you build MCP servers on. AegisGate Platform is the enterprise gateway that secures all AI traffic across your organization — including MCP, HTTP, A2A, and ACP.
Other AegisGate products:
- AegisGate Rampart — Free local proxy for developers using Claude, Cursor, or Copilot
- AegisGate Lens — Free browser extension for everyday AI conversations
License
Apache-2.0. See LICENSE for the full text and NOTICE for attribution.
Security
See SECURITY.md for vulnerability reporting.
Contributing
See CONTRIBUTING.md. All commits must be signed off (git commit -s) per the DCO.
IP Notice
AegisGate's core technologies are patent pending with the USPTO (Provisional App. Nos. 64/153,573–64/153,577, filed September 12, 2026). Source code is © 2025-2026 AegisGate Security, LLC. Licensed under Apache 2.0.
Trademark
AegisGate Security™ is a trademark of AegisGate Security, LLC, filed with the United States Patent and Trademark Office (USPTO). The mark was published for opposition on October 13, 2026.
AegisGate MCP is an unregistered product name of AegisGate Security, LLC. The ™ symbol is not used for this product name, as it has not been separately filed as a trademark application. Use of the "AegisGate Security" mark is governed by the Lanham Act (15 U.S.C. § 1126) and applicable state trademark law.
Permission is granted to use the AegisGate name and marks in connection with the unmodified open-source software distribution as published on GitHub. Use of the AegisGate name, logo, or other brand assets in derivative works, commercial products, service offerings, or marketing materials requires prior written permission from AegisGate Security, LLC.
Contact: [email protected]
🌐 AegisGate Security · 💬 Discord · ✉️ [email protected] · 𝕏 @aegisgate · 📱 Telegram · 🐘 @[email protected]
Made with 🖤 by AegisGate Security developers to secure the AI attack surface.
来源:README.md,提交 f8ad7fa
工具
0版本历史
1- v1.3.0最新Oct 9, 2026

