@agentlaw/gateway
v0.1.0
Published
The agentlaw CLI and MCP policy gateway: enforce a signed policy manifest on every tool call an AI agent makes.
Maintainers
Readme
@agentlaw/gateway
The agentlaw CLI and MCP policy gateway — the enforcement point of AgentLaw. Wraps any MCP server behind a signed policy manifest: every tool call is checked by the deterministic engine in @agentlaw/core and allowed, paused for human approval, or denied — fail-closed, hash-chain audited.
Quickstart
npx @agentlaw/gateway wizard .Scaffolds a signed, ready-to-run policy.yaml (template + thresholds + keypair) and prints the .mcp.json snippet to wrap your MCP servers:
{
"mcpServers": {
"safe-fs": {
"command": "npx",
"args": ["-y", "@agentlaw/gateway", "--policy", "policy.yaml", "--trust", "policy.pub",
"--", "npx", "-y", "@modelcontextprotocol/server-filesystem", "/sandbox"]
}
}
}CLI
| Command | What it does |
| --- | --- |
| agentlaw wizard . | Guided setup: template, thresholds, signed policy + keypair. |
| agentlaw sign | Sign a manifest with your Ed25519 private key. |
| agentlaw verify | Verify a manifest's signature against a trusted public key. |
| agentlaw explain | Dry-run: the verdict a tool call would receive, naming the rule. |
| agentlaw audit verify | Check the integrity of the hash-chained audit log. |
Human-in-the-loop approve rules prompt on the enforcement host's own terminal — no external service; no terminal means deny, never silent allow.
Spec and threat model: RFC-0001.
Apache-2.0.
