starkgate-mcp-server
v0.4.0
Published
MCP server that routes agent tool calls through StarkGate's universal firewall — fail-closed evaluation with offline-verifiable proofs.
Maintainers
Readme
🛡️ starkgate-mcp-server
MCP server (Model Context Protocol) qui fait passer les appels d'outils de tes agents IA par le firewall universel StarkGate — évaluation fail-closed, preuve auditHash vérifiable hors-ligne.
Installation
Aucune installation nécessaire avec npx :
npx starkgate-mcp-serverOu en global :
npm install -g starkgate-mcp-serverConfiguration (Claude Desktop & autres clients MCP)
Ajoute à ton claude_desktop_config.json :
{
"mcpServers": {
"starkgate": {
"command": "npx",
"args": ["-y", "starkgate-mcp-server"],
"env": {
"STARKGATE_API_KEY": "sk_live_votre_cle",
"STARKGATE_API_URL": "https://sentinel-api.wenjoseph16.workers.dev",
"STARKGATE_POLICY_ID": "pol-demo",
"STARKGATE_AGENT_ID": "claude-desktop"
}
}
}
}| Variable | Requis | Défaut | Description |
|---|---|---|---|
| STARKGATE_API_KEY | pour evaluate | — | Clé API (sk_live_…) — sans elle, starkgate_evaluate répond DENY fail-closed |
| STARKGATE_API_URL | non | https://sentinel-api.wenjoseph16.workers.dev | URL de l'API StarkGate |
| STARKGATE_POLICY_ID | non | pol-demo | Policy par défaut |
| STARKGATE_AGENT_ID | non | mcp-agent | Identifiant de l'agent envoyé aux évaluations |
Tools exposés
starkgate_evaluate
Évalue une action avant exécution :
{
"actionType": "terminal.command",
"payload": { "cmd": "rm -rf /" },
"agentId": "mon-agent",
"policyId": "pol-demo"
}Réponse :
{
"decision": "DENY",
"reason": "Destructive command blocked by rule 'no-rm-rf'",
"matchedRule": "no-rm-rf",
"auditHash": "sha256:9f2c…",
"riskScore": 95
}- Fail-closed : erreur réseau/HTTP →
DENY(jamais de fail-open silencieux). - L'
auditHashpermet de vérifier la preuve hors-ligne (voir SDK Pythonstarkgate.local_audit).
starkgate_health
Ping l'API (aucune clé requise) → {"status": "ok", "apiUrl": "…"}.
Usage programmatique (librairie)
Pour wrapper vos propres tools MCP avec le guard StarkGate :
import { createStarkGateMcpServer } from "starkgate-mcp-server";
const server = createStarkGateMcpServer({
apiUrl: "https://sentinel-api.wenjoseph16.workers.dev",
apiKey: "sk_live_…",
policyId: "pol-demo",
});
server.wrapTool({
name: "read_file",
description: "Read a file from the filesystem",
inputSchema: { path: z.string() },
handler: async (args) => fs.readFile(args.path, "utf-8"),
});
await server.start();Liens
- Docs : https://sentinel-api.wenjoseph16.workers.dev/docs
- Quickstart : https://sentinel-api.wenjoseph16.workers.dev/quickstart
- SDK Python :
pip install starkgate-sdk - Repo : https://github.com/wenjoseph16/starkgate
License
MIT
