
AegisGate MCP
io.github.aegisgatesecurityv1.3.0更新於 Oct 9, 2026
Secure MCP server framework with 22 security layers and ML threat detection. Zero dependencies.
概覽
以 Go 撰寫的強化型 MCP 伺服器框架,為工具呼叫提供身分驗證、RBAC、原則、稽核記錄與機器學習威脅偵測。
- 功能
- AegisGate MCP 是一個自包含的 MCP 伺服器框架,位於 AI 代理與其呼叫的工具之間,對每個請求套用 22 層安全防護。它提供 Bearer 權杖與 API 金鑰身分驗證、具備各工具權限的四級 RBAC、支援允許/拒絕規則的原則引擎、速率限制、用於偵測權限提升與資料外洩鏈的鏈結分析、含機密資訊遮蔽的回應掃描、防竄改稽核記錄,以及選用的神經威脅偵測。它支援 TCP、stdio 與 Streamable HTTP 傳輸、TLS/mTLS、健康檢查端點,並可作為 Go 函式庫嵌入。提供示範工具(ping、system_info、echo)供測試。
- 適用情境
- 當你需要在工具呼叫必須經過身分驗證、授權、速率限制與稽核的環境中執行或建置 MCP 伺服器時使用,例如生產、企業或氣隙部署。它也適合將安全控制嵌入自訂 Go MCP 伺服器,而非從裸 SDK 開始。
- 執行需求
- 以本機程序執行;資訊清單宣告使用 stdio 傳輸,未宣告環境變數或標頭。README 說明需要 Go 1.26+ 建置,或使用 Docker 映像(ghcr.io/aegisgatesecurity/aegisgate-mcp:1.3.0,amd64/arm64)。選用設定包括 Bearer 權杖(MCP_AUTH_TOKEN)、稽核記錄路徑(MCP_AUDIT_LOG)、TLS 憑證與金鑰檔案,以及用於神經偵測的 ONNX 模型路徑(MCP_ML_MODEL)。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 AegisGate MCP,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
🛡️ AegisGate MCP
Secure MCP server framework — 22 layers of defense, zero dependencies.
A hardened, zero-dependency MCP server written in pure Go. Build your MCP server on a foundation that has security built in from line one — not bolted on after a breach.
Apache 2.0 · 22 security layers · 30 regex patterns + CharCNN-BiLSTM (v13) ML detection · Zero CVEs · Zero external module dependencies
[License: Apache 2.0] [Go] [Version] [Coverage] [Dependencies] [Docker] [ML] [Arch] [CI] [Security] [Patent Pending]
Quick Start · Security Layers · RBAC · Architecture · Protocol · Docs · Releases
[GitHub stars] — If AegisGate MCP helps you secure your AI agents, please consider ⭐ starring this repo. It helps others discover it.
AegisGate Security™ is a trademark of AegisGate Security, LLC, filed with the USPTO. "AegisGate MCP" is an unregistered product name. See Trademark below.
Why AegisGate MCP?
38% of MCP servers have no authentication. 590+ security advisories. 3 critical CVEs in the official MCP SDKs in 6 months — including CVSS 9.8 remote code execution and the "Mother of All AI Supply Chains" flaw affecting 150M+ downloads.
The official MCP SDKs give you the protocol. They don't give you security. No authentication. No audit logging. No threat detection. No rate limiting. No RBAC. Every server built on a bare SDK starts with a blank security posture and it's on you to build it — or skip it, as 38% of servers do.
AegisGate MCP is the secure alternative. Build your MCP server on a foundation that has security built in from line one — not bolted on after a breach.
22 security layers. Zero dependencies. Zero CVEs. Apache 2.0.
Need proxy mode, OAuth, SIEM, or compliance frameworks? See When to Upgrade to AegisGate Platform below — or explore AegisGate Rampart for local AI API proxy protection.
Overview
AegisGate MCP is a hardened, zero-dependency MCP server written in pure Go. It sits between AI agents and the tools they call, applying 22 layers of defense to every request — from authentication and RBAC to neural threat detection and chain analysis.
Standard MCP servers assume a trusted local environment. In production — whether that's a cloud SaaS platform, an enterprise data pipeline, or an air-gapped plant network — agents may execute commands, query databases, or interact with critical systems. A single unauthorized or malicious tool call can cause data exfiltration, process disruption, or worse. AegisGate MCP wraps every tool call in defense-in-depth, all with zero external module dependencies so it can run air-gapped.
Quick Start
Build
Run
Docker
The default Docker image uses debian:bookworm-slim with CGO enabled,
including the vendored ONNX Runtime and CharCNN-BiLSTM v13 model for
full neural threat detection. A --build-arg CGO_ENABLED=0 variant
produces a smaller heuristic-only image. Multi-arch builds support
both linux/amd64 and linux/arm64.
ML Threat Detection (L3)
AegisGate MCP includes the same CharCNN-BiLSTM v13 neural model used by AegisGate Platform and Rampart — vendored with zero external module dependencies. The model provides:
- Semantic attack detection — catches prompt injection and jailbreak attempts that bypass regex pattern matching
- Evasion resistance — detects obfuscation techniques (leetspeak, Unicode homoglyphs, character transposition, vowel deletion, word reversal)
- Two-tier blocking — scores ≥0.95 block independently; scores 0.50–0.94 block only if L1 (regex) or L2 (input scanner) corroboration is present
- Shadow mode — log predictions without blocking (for calibration)
- Heuristic fallback — when CGO is unavailable, heuristic scoring provides baseline detection without ONNX
Library Usage
AegisGate MCP can be embedded as a Go library:
See examples/simple-server/ for a complete working example that registers a tool, resource, and prompt.
ML Model Hot-Swap
Reload the neural threat detection model at runtime without restarting the server:
Tool Poisoning Detection
All tools registered via RegisterTool() are automatically scanned for prompt injection in their descriptions and inputSchema. To scan manually:
Security Layers
AegisGate MCP applies 22 security layers to every request, in order:
⚙️ Configuration
Configuration Priority
Configuration is resolved in order of highest to lowest priority:
- CLI flags — override everything
- Environment variables — override config file
- JSON config file (
--config) — overrides built-in defaults - Built-in defaults
CLI Flags
All CLI flags have environment variable equivalents:
JSON Config File
Transport Modes
Health Endpoints
When --health-addr is set, a separate HTTP listener provides observability endpoints:
🔐 RBAC & Policy Engine
RBAC Roles
AegisGate MCP enforces a 4-tier role hierarchy. Roles are ordered: restricted < standard < privileged < admin.
Role comparison uses AgentRole.AtLeast() — a privileged agent can access any tool that requires standard or restricted, but not tools that require admin.
Policy Engine
The Policy Engine evaluates allow/deny rules before any tool executes. Rules support:
- Tool name matching — exact names and wildcard patterns
- Agent role conditions — apply rules only to specific roles
- Risk score thresholds — trigger on
RiskAbovevalues - Priorities — higher-priority rules evaluated first
- Time windows — restrict tools to specific time ranges
- Parameter patterns — match against tool call parameters
- Actions — allow, deny (with reason), log level, risk modifiers
Built-in Policy Rules
Loaded via LoadDefaultPolicies():
Custom rules can be added programmatically:
Chain Analysis
The Chain Analyzer tracks sequences of tool calls within a session (rolling window of 20 calls) and flags suspicious patterns:
When any flag is raised, the chain risk is set to High and the event is logged at WARN level with the session ID, flags, and call count.
✍️ Signature Verification
AegisGate MCP supports ECDSA P-256 message signing to prevent request forgery and tampering.
Clients sign the canonical JSON of each request (with Signature and KeyID fields zeroed out)
and include the signature in the request header.
Server Setup
Client Signing (example)
The server verifies the signature using ecdsa.VerifyASN1 against the trusted public key.
If no KeyID or Signature is present, verification is skipped — allowing interoperability
with unsigned clients while enforcing signatures for clients that provide them.
🧪 Testing & Performance
Test Coverage
Running Tests
Performance Characteristics
Validated via the load test suite (//go:build load):
📦 Zero Module Dependencies
AegisGate MCP has zero external module dependencies. The go.mod file contains
no require directives. All third-party code (ONNX Runtime bindings, Unicode
normalization, ML model) is vendored into internal/, lib/, and models/.
Vendored components (see NOTICE for full attribution):
Why this matters:
- Air-gapped deployment — no
go mod downloadneeded, no supply chain risk - No transitive dependencies — nothing to audit beyond vendored code
- Reproducible builds — the binary is identical across builds
- Minimal attack surface — all third-party code is visible and auditable
- Fast compilation — no dependency resolution overhead
🏗️ Architecture & Protocol
Architecture
Request flow:
- TCP Client connects (optionally over TLS/mTLS) or stdio sends JSON-RPC via stdin
- Auth Middleware validates bearer token/API key (constant-time), verifies ECDSA signature, creates/validates session
- Guardrails enforce rate limits, session limits, and run chain analysis
- Response Scan (pre-execution parameter validation happens in handler)
- Request Handler checks RBAC permissions, evaluates Policy Engine rules, validates required parameters against
inputSchema, executes tool with timeout - Response Scan (post-execution) scans tool output for PII, secrets, XSS, prompt injection; redacts if enabled
- Audit Log records the complete action chain
MCP Protocol Support
AegisGate MCP implements the following JSON-RPC methods (MCP Protocol 2025-06-18):
Streamable HTTP session management (v1.2.2+):
POST /mcpwithinitialize→ response includesMcp-Session-IdheaderPOST /mcpwith subsequent requests → must includeMcp-Session-IdheaderDELETE /mcpwithMcp-Session-Idheader → terminates session (204 No Content)- Sessions expire after 30 minutes of inactivity
🏭 Use Cases & Deployment Scenarios
AegisGate MCP serves any environment where AI agents interact with tools — from cloud SaaS platforms to enterprise data pipelines to OT/ICS plant networks. The same 21 security layers apply regardless of deployment context.
General Deployments
- Cloud SaaS — protect user-facing AI features from prompt injection and data exfiltration
- Enterprise data access — enforce RBAC and audit logging on agent-driven database queries
- CI/CD automation — restrict what AI-assisted pipelines can execute
- Air-gapped networks — zero dependencies means the server runs with no internet access
OT/ICS Environments
In an OT/ICS environment, AegisGate MCP sits between AI agents and critical infrastructure tools:
Typical deployment scenarios:
- Read-only monitoring agent —
restrictedrole, can query SCADA status and historian data but cannot issue commands - Maintenance agent —
standardrole, can read files and search code during troubleshooting - Operations agent —
privilegedrole, can interact with most tools but cannot execute shell commands - Admin agent —
adminrole, full access for authorized maintenance windows
Security features particularly relevant to OT/ICS:
- TLS/mTLS encrypts all traffic on the plant network
- Time-window policies restrict high-risk tools to maintenance windows
- Chain analysis detects if an agent reads sensitive process data then attempts an external network write (exfiltration)
- Audit logging provides a complete chain of custody for compliance (NERC CIP, IEC 62443)
- Air-gapped operation — zero dependencies means the server can be deployed on isolated networks with no internet access
Demo Tools
Enable demo tools with the --demo flag or by calling RegisterDemoTools() in library mode.
These are safe, read-only tools that do not access the filesystem, network, or any external resources.
Example — system_info response:
Documentation
Detailed documentation is available in the docs/ directory:
Changelog
See CHANGELOG.md for version history and notable changes.
When to Upgrade to AegisGate Platform
AegisGate MCP is a standalone secure MCP server framework — perfect for building and running MCP servers with security built in. It's free, open source, and has zero external dependencies.
When your needs grow beyond a single server, AegisGate Platform is the natural upgrade path:
Think of it this way: AegisGate MCP is the secure foundation you build MCP servers on. AegisGate Platform is the enterprise gateway that secures all AI traffic across your organization — including MCP, HTTP, A2A, and ACP.
Other AegisGate products:
- AegisGate Rampart — Free local proxy for developers using Claude, Cursor, or Copilot
- AegisGate Lens — Free browser extension for everyday AI conversations
License
Apache-2.0. See LICENSE for the full text and NOTICE for attribution.
Security
See SECURITY.md for vulnerability reporting.
Contributing
See CONTRIBUTING.md. All commits must be signed off (git commit -s) per the DCO.
IP Notice
AegisGate's core technologies are patent pending with the USPTO (Provisional App. Nos. 64/153,573–64/153,577, filed September 12, 2026). Source code is © 2025-2026 AegisGate Security, LLC. Licensed under Apache 2.0.
Trademark
AegisGate Security™ is a trademark of AegisGate Security, LLC, filed with the United States Patent and Trademark Office (USPTO). The mark was published for opposition on October 13, 2026.
AegisGate MCP is an unregistered product name of AegisGate Security, LLC. The ™ symbol is not used for this product name, as it has not been separately filed as a trademark application. Use of the "AegisGate Security" mark is governed by the Lanham Act (15 U.S.C. § 1126) and applicable state trademark law.
Permission is granted to use the AegisGate name and marks in connection with the unmodified open-source software distribution as published on GitHub. Use of the AegisGate name, logo, or other brand assets in derivative works, commercial products, service offerings, or marketing materials requires prior written permission from AegisGate Security, LLC.
Contact: [email protected]
🌐 AegisGate Security · 💬 Discord · ✉️ [email protected] · 𝕏 @aegisgate · 📱 Telegram · 🐘 @[email protected]
Made with 🖤 by AegisGate Security developers to secure the AI attack surface.
來源:README.md,提交 f8ad7fa
工具
0版本歷史
1- v1.3.0最新Oct 9, 2026

