Pranaxis Mcp Gateway

io.github.Anaciberv0.3.1更新於 Oct 8, 2026

Consistency verdicts for MCP tool calls: no two agents consume the same resource version twice.

概覽

AI 產生的概覽

一個本機 stdio 代理,對消耗共享資源的 MCP 工具呼叫進行仲裁,拒絕重複消耗並附上憑證。

功能
Pranaxis MCP Gateway 以透明 stdio 代理的身分介於 MCP 用戶端與 MCP 伺服器之間。唯讀呼叫原樣通過,而會消耗共享資源的呼叫(啟動一次執行、支付訂單、依指定版本寫入檔案、更新某一列資料)會先被仲裁。若另一個代理已持有該資源版本,呼叫不會到達工具,代理會收到附有憑證且可讀的錯誤。工具描述會被標註,讓代理知道寫入會被仲裁,每次裁決都會附加到 JSONL 日誌。
適用情境
當多個代理共用同一個 MCP 伺服器、可能重複消耗同一資源版本時使用,例如同時寫入儲存庫檔案或更新資料庫某一列。它用來避免多代理情境中的遺失更新問題,也就是每個代理各自依自己的策略行動。
執行需求
以 Python 套件在本機透過 stdio 執行(pip install pranaxis-mcp-gateway,或 uvx pranaxis-mcp-gateway)。在 MCP 用戶端註冊此閘道而非伺服器,並把伺服器作為子命令,為每個代理指定各自的 --agent-id。規則為 JSON 檔案,內建規則涵蓋 vivado-ross、github-official 與 postgres-generic。選用的實體驗證器需要另外購買的硬體產品與 --fam-endpoint host:port。
安裝前請注意
閘道位於工具呼叫路徑中,可攔截其判定為消耗性的呼叫,被拒絕的呼叫不會到達工具。它會把裁決寫入可設定的 JSONL 日誌(代理、資源、版本、決定、原因、衝突請求、憑證 id、延遲)。已完成的資源會一直由持有者保留,直到其下一次呼叫或寬限期(預設 600 秒)結束。實體驗證器是另外的產品,本儲存庫只包含閘道及其通訊的 HTTP 契約。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Pranaxis Mcp Gateway,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

Pranaxis MCP Gateway

Consistency verdicts for MCP tool calls. A transparent stdio proxy that sits between any MCP client (Claude Code, Cursor, Codex, custom agents) and any MCP server. Reads pass through untouched. Calls that consume a shared resource (launch a run, pay an order, write a file at a given sha, update a row) are arbitrated first: if another agent already holds that resource version, the call never reaches the tool and the agent gets a readable error with a certificate.

It solves the lost update of multi-agent systems: two agents, each inside its own policy, consuming the same thing twice.

agent ──stdio──▶ pranaxis-mcp ──stdio──▶ your MCP server ──▶ tool                     │                     └── verdict (software, or the Pranaxis chip)

Install

pip install pranaxis-mcp-gateway      # or: uvx pranaxis-mcp-gateway

Use

Register the gateway in your MCP client instead of the server, with the server as the child command. One gateway per agent, each with its own --agent-id; all gateways on a machine share the version state. Claude Code example, AMD Ross Vivado server:

claude mcp add vivado-mcp --scope project --transport stdio --env VIVADO_PATH=/path/to/vivado -- \  pranaxis-mcp --agent-id agent-a --rules vivado-ross -- vivado-mcp-server --stdio-bridge

GitHub MCP server:

pranaxis-mcp --agent-id agent-a --rules github-official -- npx -y @modelcontextprotocol/server-github

A denied call returns isError: true with a message like:

DENIED by the Pranaxis consistency verifier.Resource 'owner/repo/main/README.md' version abc123 is being consumed by another agent(holder: agent-a; their request: agent-a-3f2c...). Certificate: ...Your call did NOT reach the tool. Do not retry the same write; read the current state and work from it.

Tool descriptions are annotated so the agent knows writes are arbitrated. In our tests, agents (two different models) did not retry blindly after a denial: they read the state and chose another action.

Rules: what counts as consumption

Rules are data, one JSON file per MCP server (src/pranaxis_gateway/rules/). Each rule names the tool, matches arguments with regexes (named groups become fields), builds the resource name from a template, and optionally takes the version from an argument (e.g. GitHub's previous blob sha). release rules say which responses show a resource complete. A completed resource stays with its holder until the holder makes its next call (it collected the result) or a grace period expires (--grace, default 600 s): nobody wipes someone else's result before they read it.

Bundled: vivado-ross (AMD Ross Vivado MCP server), github-official, postgres-generic. Calls matching no rule pass through and are logged as passthrough. Contributions of rules for other servers are welcome.

Verifiers

  • --verifier stub (default): software reference. Holders shared through the state file; verdicts carry no physical measurement.
  • --verifier fam --fam-endpoint host:port: the Pranaxis physical verifier, a ring-oscillator block on an AMD Zynq UltraScale+ / Kria device that measures the arbitration and returns a certificate with sieve, frequencies, tolerance and timing. The hardware is a separate product (https://pranaxis.eu); this repository contains only the gateway and the HTTP contract it speaks.

Certificates

Every verdict is appended to ross_demo_YYYYMMDD.jsonl (name configurable with --log-file): agent, resource, version, decision, reason, conflicting request, certificate id, measurement data when physical, proxy latency. Read-only calls are logged as passthrough.

Tests

python tests/test_two_agents.py --verifier stub        # two agents, Vivado-like server: P1..P4python tests/test_rules_generic.py                      # GitHub and SQL rule files

Status and roadmap

0.3: local mode (one proxy per agent, stdio), declarative rules, holder release / grace, jsonl log. Measured with the physical verifier on a ZUBoard 1CG (10/10 preregistered runs) and with two real agents on AMD Ross. Next: central mode (one network gateway for all agents, audit API), embedded mode on Kria K26.

Intellectual property and licence

Code: Apache-2.0. The arbitration procedure and the physical device are covered by Spanish patent applications P202631184 and P202631345 (Arignatxa S.L. as licensee); using this gateway with the software verifier is free; the physical verifier bitstream is not part of this repository. "Pranaxis" is a trademark application (M4406608).

來源:README.md,提交 88fb87e

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.1最新Oct 8, 2026