policy-gate

Deterministic allow/require_approval/deny verdicts for agent actions, before they happen.

我该使用它吗

质量与安全性

B
描述质量
88%
模式完整度
46%
命名质量
85%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(1)

  • LOWTool 'policy_rules' description lacks action verb在 policy_rules 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~548token 数(工具定义)
~1.1 KB典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.43%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "policy-gate": {
      "url": "https://policy-gate.3labsio.workers.dev/mcp"
    }
  }
}

远程端点

https://policy-gate.3labsio.workers.dev/mcpstreamable-http

它能做什么

工具清单

工具(4)

🟢 只读🟡 写入🔴 删除⚪ 未知
⚪policy_example

Free. Worked allow/require_approval/deny verdicts from the live policy engine, so you can judge the service before paying for it.

输入模式

{
  "type": "object",
  "properties": {}
}
⚪policy_rules

Free. The full built-in policy: every tier, rule, condition and rationale. Nothing about how a verdict is reached is hidden.

输入模式

{
  "type": "object",
  "properties": {}
}
🟢policy_check(request, policy_id, policy, ledger)

Evaluate a proposed agent action against a policy and return allow / require_approval / deny with the matched rule and rationale. Paid per call via x402 ($0.005 USDC on Base); returns signing instructions when unpaid.

输入模式

{
  "type": "object",
  "properties": {
    "request": {
      "type": "object",
      "required": [
        "action"
      ],
      "properties": {
        "action": {
          "type": "string",
          "description": "Dotted action id, e.g. payments.send"
        },
        "actor": {
          "type": "string"
        },
        "params": {
          "type": "object"
        }
      }
    },
    "policy_id": {
      "type": "string",
      "description": "Built-in policy id; see policy_rules. \"default-action-tiers-capped\" adds a cumulative spend bound."
    },
    "policy": {
      "type": "object",
      "description": "Your own policy document, evaluated instead of ours"
    },
    "ledger": {
      "type": "object",
      "description": "Optional cumulative exposure for the window. A per-action gate cannot see repetition: 49 payments of $40 each pass a $50 rule individually. Omit it and any policy declaring a cumulative bound returns deny with ledger_required — a cap you can skip by omitting state is decorative. Explicit zeros are an answer; an absent object is not.",
      "properties": {
        "committed_usd": {
          "type": "number",
          "description": "Spend already known to have happened in the window"
        },
        "intended_usd": {
          "type": "number",
          "description": "Dispatched and not yet confirmed. Counts toward the bound, so a burst in flight is not invisible to it."
        },
        "unknown_usd": {
          "type": "number",
          "description": "Dispatched and never resolved. Any value above zero denies with unresolved_intent, regardless of headroom: the system has lost track of this quantity. It closes by observing the target, never by a clock."
        }
      }
    }
  },
  "required": [
    "request"
  ]
}
🟡first_42_sponsor

Pay Fieldproof $42. Returns every live rail: Stripe card_uri, EIP-681 usdc_uri, BIP-21 btc_uri, x402 POST /v1/sponsor, Zelle, and GET /v1/invoice. One settlement meets the first-$42 bar.

输入模式

{
  "type": "object",
  "properties": {}
}

社区

评价此服务器

证据

最近观测

已验证未记录版本4 个工具
已验证未记录版本4 个工具
已验证未记录版本4 个工具