Sunaiva Gate — Agent Rule Enforcement

MCP enforcement layer that intercepts AI agent actions and blocks rule violations before execution.

Should I use this

Quality & Safety

A
Description quality
97%
Schema completeness
80%
Naming quality
96%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'ship_confidence_check' description lacks action verbin ship_confidence_check

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,411Tokens (tool definitions)
~659 BTypical response size
Moderate attention impact (1.10% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "gate": {
      "command": "npx",
      "args": [
        "@sunaiva/gate"
      ]
    }
  }
}

Runnable packages

npm@sunaiva/gate2.0.4stdio

Remote endpoints

https://mcp.sunaivacore.iostreamable-http

What it can do

Tool inventory

Tools (16)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢validate_action(action, context)

Check if a proposed action passes all active validation rules. Returns allowed/blocked with rule violations.

Input Schema

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "description": "The action to validate"
    },
    "context": {
      "type": "string",
      "description": "Optional additional context, appended to `action` before rule matching — it can change which rules match and therefore the verdict."
    }
  },
  "required": [
    "action"
  ]
}
⚪log_bypass(rule_id, reason)

Record an intentional rule bypass with justification. Cannot bypass constitutional rules.

Input Schema

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "ID of the rule to bypass"
    },
    "reason": {
      "type": "string",
      "description": "Justification for the bypass"
    }
  },
  "required": [
    "rule_id",
    "reason"
  ]
}
🟡get_rules(category, preset)

List active validation rules — the customer's TRUE enforced set (constitutional + recommended-default metadata on dev tier, all 69 premium rules on pro+). `category`/`preset` filter args are accepted but not applied server-side.

Input Schema

{
  "type": "object",
  "properties": {
    "category": {
      "type": "string",
      "description": "Filter by category"
    },
    "preset": {
      "type": "string",
      "description": "Filter by preset name"
    }
  }
}
🟡update_rules(enable, disable)

[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Enable/disable is not backed by any route in this API; use set_rule_mode (shadow/advisory/enforce) instead, or the local `npx @sunaiva/gate` package.

Input Schema

{
  "type": "object",
  "properties": {
    "enable": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Rule IDs to enable"
    },
    "disable": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Rule IDs to disable"
    }
  }
}
🟢get_audit_log(limit, rule_id)

View recent gate decisions — blocks, warnings, passes, and bypasses.

Input Schema

{
  "type": "object",
  "properties": {
    "limit": {
      "type": "number",
      "description": "Max entries to return (default 50)"
    },
    "rule_id": {
      "type": "string",
      "description": "Accepted for forward-compatibility but NOT applied server-side — the backend only honors limit/cursor. Filter the returned entries client-side."
    }
  }
}
🟢ship_confidence_check(artifact_id, command_preview, label)

[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Ship Confidence Gate (Rule 42) dual-tier authorization is not yet built in this backend.

Input Schema

{
  "type": "object",
  "properties": {
    "artifact_id": {
      "type": "string",
      "description": "The artifact being shipped (e.g. '@sunaiva/[email protected]')"
    },
    "command_preview": {
      "type": "string",
      "description": "First 300 chars of the command that triggered the check (optional)"
    },
    "label": {
      "type": "string",
      "description": "Human-readable label of the publish action (optional)"
    }
  },
  "required": [
    "artifact_id"
  ]
}
⚪audit_verify

[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Forward-linked hash-chain / ed25519 audit-log verification is not yet built in this backend.

Input Schema

{
  "type": "object",
  "properties": {}
}
🟡set_rule_mode(rule_id, mode, agent_id)

Set enforcement mode (shadow/advisory/enforce) for a specific rule. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "Rule ID to configure"
    },
    "mode": {
      "type": "string",
      "enum": [
        "shadow",
        "advisory",
        "enforce"
      ],
      "description": "Enforcement mode"
    },
    "agent_id": {
      "type": "string",
      "description": "Optional: scope override to a specific agent ID"
    }
  },
  "required": [
    "rule_id",
    "mode"
  ]
}
🟢get_rule_modes

List all enforcement-mode overrides configured for the authenticated customer. Requires an account (Dev+).

Input Schema

{
  "type": "object",
  "properties": {}
}
🔴reset_rule_mode(rule_id)

Remove a mode override for a rule, reverting it to its default enforcement mode. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "Rule ID whose override to remove"
    }
  },
  "required": [
    "rule_id"
  ]
}
🟡add_custom_rule(name, description, detection_pattern, severity, tier)

Create a custom detection rule in the backend. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Rule name"
    },
    "description": {
      "type": "string",
      "description": "Rule description (required — the backend 400s on a missing/empty description)"
    },
    "detection_pattern": {
      "type": "string",
      "description": "Compiled regex detection pattern (required — the backend 400s on a missing/empty detection_pattern). There is no 'pattern' field: 'detection_pattern' is the only field name the evaluator reads; the backend explicitly rejects 'pattern'."
    },
    "severity": {
      "type": "string",
      "enum": [
        "block",
        "warn"
      ],
      "description": "Severity on match"
    },
    "tier": {
      "type": "string",
      "description": "Optional tier restriction"
    }
  },
  "required": [
    "name",
    "description",
    "detection_pattern",
    "severity"
  ]
}
🟡update_custom_rule(id, name, description, detection_pattern, severity, ...)

Update an existing custom rule. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "Rule ID to update"
    },
    "name": {
      "type": "string"
    },
    "description": {
      "type": "string"
    },
    "detection_pattern": {
      "type": "string",
      "description": "There is no 'pattern' field — 'detection_pattern' is the only field name the evaluator reads; the backend explicitly rejects 'pattern'."
    },
    "severity": {
      "type": "string",
      "enum": [
        "block",
        "warn"
      ]
    },
    "tier": {
      "type": "string"
    }
  },
  "required": [
    "id"
  ]
}
🔴delete_custom_rule(id)

Delete a custom rule. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "Rule ID to delete"
    }
  },
  "required": [
    "id"
  ]
}
🟢list_custom_rules

List all custom rules for the authenticated customer. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {}
}
🟢list_presets

List available rule preset bundles. Requires API key (Dev+).

Input Schema

{
  "type": "object",
  "properties": {}
}
⚪apply_preset(preset_id)

Apply a preset bundle, activating all its included rules. Requires API key (Pro+).

Input Schema

{
  "type": "object",
  "properties": {
    "preset_id": {
      "type": "string",
      "description": "ID of the preset to apply"
    }
  },
  "required": [
    "preset_id"
  ]
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded16 tools
verifiedversion not recorded16 tools
verifiedversion not recorded16 tools