Agent Utility MCP
Stop your agent before it runs rm -rf /etc or emails your .env. Deterministic preflight checks.
使うべきか
品質と安全性
検出事項(1)
- LOWanalyze_url_risk 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"agent-utility-mcp": {
"url": "https://agent-utility-mcp.insivotron.workers.dev/mcp"
}
}
}リモートエンドポイント
https://agent-utility-mcp.insivotron.workers.dev/mcpstreamable-httpできること
ツール一覧
ツール(4)
🟢analyze_url_risk(url, policy, context)
Analyze a URL for structural and security risk signals and return a deterministic, policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
入力スキーマ
{
"type": "object",
"properties": {
"url": {
"type": "string",
"minLength": 1,
"description": "The absolute URL to analyze."
},
"policy": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
],
"description": "Optional policy used to compute the decision: permissive, balanced or strict (default: balanced)."
},
"context": {
"type": "object",
"properties": {
"workspace_root": {
"type": "string",
"description": "Accepted for contract consistency; URL analysis has no filesystem paths to scope, so it has no effect here."
}
},
"additionalProperties": false,
"description": "Optional declarative context."
}
},
"required": [
"url"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}出力スキーマ
{
"type": "object",
"properties": {
"valid": {
"type": "boolean"
},
"input": {
"type": "string"
},
"normalized_url": {
"type": [
"string",
"null"
]
},
"hostname": {
"type": [
"string",
"null"
]
},
"domain": {
"type": [
"string",
"null"
]
},
"public_suffix": {
"type": [
"string",
"null"
]
},
"subdomain": {
"type": [
"string",
"null"
]
},
"protocol": {
"type": [
"string",
"null"
]
},
"port": {
"type": [
"string",
"null"
]
},
"risk": {
"type": "string",
"enum": [
"safe",
"low",
"medium",
"high",
"critical"
]
},
"risk_score": {
"type": "number"
},
"decision": {
"type": "string",
"enum": [
"allow",
"notice",
"confirm",
"block"
]
},
"policy_applied": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
]
},
"ruleset_version": {
"type": "string"
},
"schema_version": {
"type": "string"
},
"context_completeness": {
"type": "string",
"enum": [
"full",
"partial",
"none"
]
},
"signals": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"info",
"low",
"medium",
"high",
"critical"
]
},
"score": {
"type": "number"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"severity",
"score",
"message"
],
"additionalProperties": false
}
},
"checks": {
"type": "object",
"properties": {
"dangerous_scheme": {
"type": "boolean"
},
"embedded_credentials": {
"type": "boolean"
},
"raw_ip_host": {
"type": "boolean"
},
"private_or_local_host": {
"type": "boolean"
},
"cloud_metadata_host": {
"type": "boolean"
},
"unicode_or_punycode_host": {
"type": "boolean"
},
"suspicious_port": {
"type": "boolean"
},
"excessive_subdomains": {
"type": "boolean"
},
"suspicious_keywords": {
"type": "boolean"
},
"executable_path": {
"type": "boolean"
},
"url_shortener": {
"type": "boolean"
},
"excessive_length": {
"type": "boolean"
}
},
"required": [
"dangerous_scheme",
"embedded_credentials",
"raw_ip_host",
"private_or_local_host",
"cloud_metadata_host",
"unicode_or_punycode_host",
"suspicious_port",
"excessive_subdomains",
"suspicious_keywords",
"executable_path",
"url_shortener",
"excessive_length"
],
"additionalProperties": false
}
},
"required": [
"valid",
"input",
"normalized_url",
"hostname",
"domain",
"public_suffix",
"subdomain",
"protocol",
"port",
"risk",
"risk_score",
"decision",
"policy_applied",
"ruleset_version",
"schema_version",
"context_completeness",
"signals",
"checks"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢inspect_command(command, shell, cwd, policy, context)
Analyze a shell command before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) without running it, under the applicable policy — permissive, balanced or strict, balanced by default. Paths outside a known workspace_root are treated as higher risk than paths inside it.
入力スキーマ
{
"type": "object",
"properties": {
"command": {
"type": "string",
"minLength": 1,
"maxLength": 16384,
"description": "The complete command text to inspect without executing it."
},
"shell": {
"type": "string",
"enum": [
"bash",
"sh",
"zsh",
"powershell",
"cmd",
"unknown"
],
"description": "The command shell, when known."
},
"cwd": {
"type": "string",
"maxLength": 4096,
"description": "Optional working-directory context. It is never accessed."
},
"policy": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
],
"description": "Optional policy used to compute the decision: permissive, balanced or strict (default: balanced)."
},
"context": {
"type": "object",
"properties": {
"workspace_root": {
"type": "string",
"maxLength": 4096,
"description": "Optional workspace root. Paths that resolve outside it are treated as higher risk than paths inside it."
}
},
"additionalProperties": false,
"description": "Optional declarative context."
}
},
"required": [
"command"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}出力スキーマ
{
"type": "object",
"properties": {
"valid": {
"type": "boolean"
},
"command": {
"type": [
"string",
"null"
]
},
"shell": {
"type": "string",
"enum": [
"bash",
"sh",
"zsh",
"powershell",
"cmd",
"unknown"
]
},
"cwd": {
"type": [
"string",
"null"
]
},
"risk": {
"type": "string",
"enum": [
"safe",
"low",
"medium",
"high",
"critical"
]
},
"risk_score": {
"type": "number"
},
"decision": {
"type": "string",
"enum": [
"allow",
"notice",
"confirm",
"block"
]
},
"policy_applied": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
]
},
"ruleset_version": {
"type": "string"
},
"schema_version": {
"type": "string"
},
"context_completeness": {
"type": "string",
"enum": [
"full",
"partial",
"none"
]
},
"signals": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"info",
"low",
"medium",
"high",
"critical"
]
},
"score": {
"type": "number"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"severity",
"score",
"message"
],
"additionalProperties": false
}
},
"checks": {
"type": "object",
"properties": {
"destructive_filesystem": {
"type": "boolean"
},
"root_target": {
"type": "boolean"
},
"privilege_escalation": {
"type": "boolean"
},
"network_access": {
"type": "boolean"
},
"network_download": {
"type": "boolean"
},
"network_transfer": {
"type": "boolean"
},
"remote_code_execution": {
"type": "boolean"
},
"sensitive_file_access": {
"type": "boolean"
},
"possible_exfiltration": {
"type": "boolean"
},
"permission_change": {
"type": "boolean"
},
"persistence_change": {
"type": "boolean"
},
"system_modification": {
"type": "boolean"
},
"obfuscated_execution": {
"type": "boolean"
},
"command_chaining": {
"type": "boolean"
},
"shell_spawning": {
"type": "boolean"
}
},
"required": [
"destructive_filesystem",
"root_target",
"privilege_escalation",
"network_access",
"network_download",
"network_transfer",
"remote_code_execution",
"sensitive_file_access",
"possible_exfiltration",
"permission_change",
"persistence_change",
"system_modification",
"obfuscated_execution",
"command_chaining",
"shell_spawning"
],
"additionalProperties": false
}
},
"required": [
"valid",
"command",
"shell",
"cwd",
"risk",
"risk_score",
"decision",
"policy_applied",
"ruleset_version",
"schema_version",
"context_completeness",
"signals",
"checks"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢inspect_file(filename, content_base64, policy, context)
Inspect a Base64-encoded file locally for deterministic structural and security risk signals without executing it, and return a policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
入力スキーマ
{
"type": "object",
"properties": {
"filename": {
"type": "string",
"minLength": 1,
"description": "The original filename, including its extension."
},
"content_base64": {
"type": "string",
"description": "The complete file content encoded as canonical Base64 (maximum decoded size: 1 MiB)."
},
"policy": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
],
"description": "Optional policy used to compute the decision: permissive, balanced or strict (default: balanced)."
},
"context": {
"type": "object",
"properties": {
"workspace_root": {
"type": "string",
"description": "Accepted for contract consistency; file inspection has no filesystem paths to scope, so it has no effect here."
}
},
"additionalProperties": false,
"description": "Optional declarative context."
}
},
"required": [
"filename",
"content_base64"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}出力スキーマ
{
"type": "object",
"properties": {
"valid": {
"type": "boolean"
},
"filename": {
"type": [
"string",
"null"
]
},
"detected_type": {
"type": [
"string",
"null"
]
},
"declared_extension": {
"type": [
"string",
"null"
]
},
"size_bytes": {
"type": [
"number",
"null"
]
},
"sha256": {
"type": [
"string",
"null"
]
},
"risk": {
"type": "string",
"enum": [
"safe",
"low",
"medium",
"high",
"critical"
]
},
"risk_score": {
"type": "number"
},
"decision": {
"type": "string",
"enum": [
"allow",
"notice",
"confirm",
"block"
]
},
"policy_applied": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
]
},
"ruleset_version": {
"type": "string"
},
"schema_version": {
"type": "string"
},
"context_completeness": {
"type": "string",
"enum": [
"full",
"partial",
"none"
]
},
"signals": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"info",
"low",
"medium",
"high",
"critical"
]
},
"score": {
"type": "number"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"severity",
"score",
"message"
],
"additionalProperties": false
}
},
"checks": {
"type": "object",
"properties": {
"empty_file": {
"type": "boolean"
},
"exceeds_size_limit": {
"type": "boolean"
},
"dangerous_extension": {
"type": "boolean"
},
"double_extension": {
"type": "boolean"
},
"executable_content": {
"type": "boolean"
},
"extension_type_mismatch": {
"type": "boolean"
},
"suspicious_filename": {
"type": "boolean"
}
},
"required": [
"empty_file",
"exceeds_size_limit",
"dangerous_extension",
"double_extension",
"executable_content",
"extension_type_mismatch",
"suspicious_filename"
],
"additionalProperties": false
}
},
"required": [
"valid",
"filename",
"detected_type",
"declared_extension",
"size_bytes",
"sha256",
"risk",
"risk_score",
"decision",
"policy_applied",
"ruleset_version",
"schema_version",
"context_completeness",
"signals",
"checks"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢analyze_tool_call(tool_name, arguments, policy, context)
Analyze a proposed AI-agent tool call before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) covering destructive actions, sensitive-data exposure, external transmission, privilege changes and irreversible operations, under the applicable policy — permissive, balanced or strict, balanced by default. Filesystem paths outside a known workspace_root are treated as higher risk than paths inside it.
入力スキーマ
{
"type": "object",
"properties": {
"tool_name": {
"type": "string",
"minLength": 1,
"maxLength": 256,
"description": "The exact name of the proposed tool."
},
"arguments": {
"anyOf": [
{
"type": "object",
"additionalProperties": {}
},
{
"type": "array",
"items": {}
},
{
"type": "string"
},
{
"type": "number"
},
{
"type": "boolean"
},
{
"type": "null"
}
],
"description": "The proposed tool arguments. They are analyzed as data and never executed."
},
"policy": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
],
"description": "Optional policy used to compute the decision: permissive, balanced or strict (default: balanced)."
},
"context": {
"type": "object",
"properties": {
"description": {
"type": "string",
"maxLength": 4096
},
"target_type": {
"type": "string",
"maxLength": 4096
},
"destination": {
"type": "string",
"maxLength": 4096
},
"operation": {
"type": "string",
"maxLength": 4096
},
"workspace_root": {
"type": "string",
"maxLength": 4096,
"description": "Optional workspace root. Filesystem paths that resolve outside it are treated as higher risk than paths inside it."
}
},
"additionalProperties": false,
"description": "Optional declarative context about the proposed operation."
}
},
"required": [
"tool_name",
"arguments"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}出力スキーマ
{
"type": "object",
"properties": {
"valid": {
"type": "boolean"
},
"tool_name": {
"type": [
"string",
"null"
]
},
"risk": {
"type": "string",
"enum": [
"safe",
"low",
"medium",
"high",
"critical"
]
},
"risk_score": {
"type": "number"
},
"decision": {
"type": "string",
"enum": [
"allow",
"notice",
"confirm",
"block"
]
},
"policy_applied": {
"type": "string",
"enum": [
"permissive",
"balanced",
"strict"
]
},
"ruleset_version": {
"type": "string"
},
"schema_version": {
"type": "string"
},
"context_completeness": {
"type": "string",
"enum": [
"full",
"partial",
"none"
]
},
"signals": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string",
"enum": [
"info",
"low",
"medium",
"high",
"critical"
]
},
"score": {
"type": "number"
},
"message": {
"type": "string"
}
},
"required": [
"code",
"severity",
"score",
"message"
],
"additionalProperties": false
}
},
"checks": {
"type": "object",
"properties": {
"destructive_action": {
"type": "boolean"
},
"irreversible_action": {
"type": "boolean"
},
"privilege_change": {
"type": "boolean"
},
"permission_change": {
"type": "boolean"
},
"sensitive_data_present": {
"type": "boolean"
},
"possible_secret_exposure": {
"type": "boolean"
},
"external_destination": {
"type": "boolean"
},
"possible_exfiltration": {
"type": "boolean"
},
"financial_action": {
"type": "boolean"
},
"communication_action": {
"type": "boolean"
},
"account_or_identity_action": {
"type": "boolean"
},
"code_execution": {
"type": "boolean"
},
"filesystem_mutation": {
"type": "boolean"
},
"network_action": {
"type": "boolean"
}
},
"required": [
"destructive_action",
"irreversible_action",
"privilege_change",
"permission_change",
"sensitive_data_present",
"possible_secret_exposure",
"external_destination",
"possible_exfiltration",
"financial_action",
"communication_action",
"account_or_identity_action",
"code_execution",
"filesystem_mutation",
"network_action"
],
"additionalProperties": false
}
},
"required": [
"valid",
"tool_name",
"risk",
"risk_score",
"decision",
"policy_applied",
"ruleset_version",
"schema_version",
"context_completeness",
"signals",
"checks"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}コミュニティ
エビデンス