{"_id":"@11ai/mcp-gate","_rev":"7-5ab010b5ca614f68c01382a554d6fd16","name":"@11ai/mcp-gate","dist-tags":{"latest":"0.4.2"},"versions":{"0.1.0":{"name":"@11ai/mcp-gate","version":"0.1.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.1.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"b42a348e944c54a414feb354c4f43c564b30f7ea","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.1.0.tgz","fileCount":16,"integrity":"sha512-gKFcgF0/udw7UVIe3ITzggjmnBZpqoooFRf1JRRBKwtNTxCKbE/7XDBTt0NVfxXQfuTFNK4ux8MBomur3OrdqA==","signatures":[{"sig":"MEUCIB/r8lYoNRBrCHZKAG4GMFv9l0KK6jZNzQIWGFpurRGaAiEAiK2lKlLEnTBDdBFEES0MPa0aiT7hdgKo9wvn48Eig/E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30963},"type":"module","engines":{"node":">=18"},"gitHead":"03a1f328ad5a40a8e329ad69454f661f66e1b514","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"10.9.2","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"@11ai/execution-governance":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.1.0_1784435710342_0.5504226591753565","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: depends on an affected @11ai/execution-governance and cannot resolve the fix. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.1.1":{"name":"@11ai/mcp-gate","version":"0.1.1","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.1.1","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"5c228ef248bebca0b794831da6db519234be5df9","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.1.1.tgz","fileCount":16,"integrity":"sha512-47cmZIrYYNkDVljDLpzlcsyXtmYv7/4F3i1QLPP2Po1j/8h4JkMwPMnnxGb8ZU7HKOZxbtG1lhDq8FZSRLQ7qA==","signatures":[{"sig":"MEYCIQD4bDqPlwR62djbpmWEpJzx809cqGU+OEJKl6tj8YpbLwIhAKFvLjQ7okjhNLRAbtY7hzyKkme2IzIlZQclhEMe8P92","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32475},"type":"module","engines":{"node":">=18"},"gitHead":"01c5e00d3a1910e4efdf607fe99349336ea6b8be","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"10.9.2","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"@11ai/execution-governance":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.1.1_1785710097369_0.5343032487052608","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: depends on an affected @11ai/execution-governance and cannot resolve the fix. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.1.2":{"name":"@11ai/mcp-gate","version":"0.1.2","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.1.2","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"dd4ade5df0c1438e67cf47c66a8bccac7efdc29e","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.1.2.tgz","fileCount":16,"integrity":"sha512-uWESNrhMjfKqcjlMKYES+X7PQWY7jaVXsps/57e6B7FM9cJLrGIOAqHBPgN0Nn35WB5JDVq+K6mLXlUQiqyg0A==","signatures":[{"sig":"MEUCIQCLOoa4p00r7kiz1Z+qYEGOw+XUR9XR0qN3FztT3vgFxAIgU78xG2/TUqcUkkgs8595UEyytji4xkJ0WphKAdZbvsw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fmcp-gate@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":42171},"type":"module","engines":{"node":">=18"},"gitHead":"b7580e3f41ee8e2c7e5111de1ae30a6d7a18124d","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f0d1ae29-4bc8-4a30-97d3-929f9a80d9ac"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"11.19.0","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@11ai/execution-governance":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.1.2_1786269753219_0.524242549048261","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: depends on an affected @11ai/execution-governance and cannot resolve the fix. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.2.0":{"name":"@11ai/mcp-gate","version":"0.2.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.2.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"20f6b66dd331af8c299460df08e39ccc8ee44e73","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.2.0.tgz","fileCount":16,"integrity":"sha512-F5USOui7+lwTiViDJRO9DJwO6E+N2Efbql5h5aYL4qu7uSDvJpiWko/MrkC5FovCByKfnPkOeKOMojSsMQuCiA==","signatures":[{"sig":"MEYCIQC8sU79eI0FteUeDqVfRu+maLnl2zNkloLbIkXoAWolzAIhAIy8mI+sXjkbBmBWoTFpS/KyPi5w8muNEmwGOsiMj5E6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fmcp-gate@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":42171},"type":"module","engines":{"node":">=18"},"gitHead":"c1441567183b214955d723fbaeb6bcb30ce33a84","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f0d1ae29-4bc8-4a30-97d3-929f9a80d9ac"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"11.19.0","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@11ai/execution-governance":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.2.0_1786307456169_0.555290309211165","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: depends on an affected @11ai/execution-governance and cannot resolve the fix. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.2.1":{"name":"@11ai/mcp-gate","version":"0.2.1","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.2.1","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"774426f7218f45adeee41d4e424468b50edf9640","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.2.1.tgz","fileCount":17,"integrity":"sha512-RtKbSIBoYpExVuvy4OJWcrVIVz+B+M8yUQng8gqzceA0T0pttnSCz2HoFcGuXHyGtFnomlGS/Xiqp8Dy+eu57A==","signatures":[{"sig":"MEUCIQCLAakiXzSlAwyN6ONb0ceppzndVo7XRHC2mFlBbRJZawIgCyHoyZolgm3kYWbax7TyhbJqI1rE+lXZiSDHBuSqAGk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fmcp-gate@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":45624},"type":"module","engines":{"node":">=18"},"gitHead":"6073a8ffad336f3d7f2f393a544aea35e8e2b9d6","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f0d1ae29-4bc8-4a30-97d3-929f9a80d9ac"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"11.19.0","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@11ai/execution-governance":"^0.2.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.2.1_1787714365744_0.15747714303008564","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: depends on an affected @11ai/execution-governance and cannot resolve the fix. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.4.2":{"name":"@11ai/mcp-gate","version":"0.4.2","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/mcp-gate@0.4.2","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"mcp-gate":"dist/cli.js"},"dist":{"shasum":"17c89cc64de80a332ffb243f0ce8fa866ce2ad83","tarball":"https://registry.npmjs.org/@11ai/mcp-gate/-/mcp-gate-0.4.2.tgz","fileCount":17,"integrity":"sha512-F8gPrAAfakTJ4FeW5kg2R855IGgYxZy0pPHvZuIu6HdOlf0p0qcf333S/p/CEOpegzvfj4fUyvvfm3aHwuJ69w==","signatures":[{"sig":"MEQCIH/SRO92Rg+LRPQt5p9VQmXaBVIr7nPm6K3XhckWSNmLAiAJbc5Wwlss05q34V/+MF/Ltlk6/FG4FGPzBvI77Hn70w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICWDja5c5FGE6deeheQNJuLh1ZgweVu1RsEyjJZ/7ucKAiAkLSxMUEMfhEIISjKwNaIYN3+FN9arx7GrlI+t0Lqogg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fmcp-gate@0.4.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":45624},"type":"module","engines":{"node":">=18"},"gitHead":"f2efb313d113149c6ddc9656307a605a7619f8ea","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f0d1ae29-4bc8-4a30-97d3-929f9a80d9ac"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"_npmVersion":"11.19.1","description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"@11ai/execution-governance":"^0.4.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-gate_0.4.2_1789670861850_0.8536682396946784","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-07-19T04:35:10.126Z","modified":"2026-09-17T19:12:41.117Z","0.1.0":"2026-07-19T04:35:10.479Z","0.1.1":"2026-08-02T22:34:57.515Z","0.1.2":"2026-08-09T10:02:33.378Z","0.2.0":"2026-08-09T20:30:56.312Z","0.2.1":"2026-08-26T03:19:25.900Z","0.4.2":"2026-09-17T18:47:41.920Z"},"bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"license":"Apache-2.0","homepage":"https://github.com/11-11AI/execution-governance#readme","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/mcp-gate"},"description":"Fail-closed MCP proxy that gates agent tool calls with Execution Governance.","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://11aiblockchain.com/npm-banner.png\" alt=\"11/11 AI — Execution Governance\" width=\"480\" />\n</p>\n\n# @11ai/mcp-gate\n\n[![npm version](https://img.shields.io/npm/v/@11ai/mcp-gate.svg)](https://www.npmjs.com/package/@11ai/mcp-gate)\n[![npm downloads](https://img.shields.io/npm/dm/@11ai/mcp-gate.svg)](https://www.npmjs.com/package/@11ai/mcp-gate)\n[![CI](https://github.com/11-11AI/execution-governance/actions/workflows/ci.yml/badge.svg)](https://github.com/11-11AI/execution-governance/actions/workflows/ci.yml)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](https://github.com/11-11AI/execution-governance/blob/main/LICENSE)\n\n**A firewall for MCP tool calls. Add one line to your config — no code changes.**\n\n`mcp-gate` is a fail-closed stdio proxy that sits between any MCP client\n(Claude Desktop, Claude Code, Cursor, anything) and any MCP server. Every\n`tools/call` is checked against your policy before it's forwarded. Denied\ncalls never reach the server — the client gets a JSON-RPC error and a\nsigned receipt records the attempt.\n\nNo API key. No network. No telemetry.\n\n## One-line install\n\nWrap any MCP server by changing its command in your client config:\n\n**Before**\n\n```json\n{\n  \"command\": \"node\",\n  \"args\": [\"their-server.js\"]\n}\n```\n\n**After**\n\n```json\n{\n  \"command\": \"npx\",\n  \"args\": [\"-y\", \"@11ai/mcp-gate\", \"--policy\", \"eg-policy.yaml\", \"--\", \"node\", \"their-server.js\"]\n}\n```\n\nThat's it. `initialize`, `tools/list`, resources, and notifications pass\nthrough untouched. Only `tools/call` is gated.\n\n## Why you want this\n\nMCP servers run with your credentials and your filesystem. A\nprompt-injected agent can call any tool the server exposes — exfiltrate\nsecrets, POST data to attacker URLs, delete files. Reviewing logs\nafterward doesn't undo it.\n\n`mcp-gate` decides **before** the call runs:\n\n- **Deny by policy** — block outbound calls carrying secret material,\n  writes outside allowed paths, dangerous shell commands, whatever your\n  policy says.\n- **Fail-closed** — engine error, timeout, malformed policy? The call is\n  denied. There is no fail-open path.\n- **Signed receipts** — every allow and every deny is Ed25519-signed,\n  SHA3-512 hashed, and chained. Verify the file offline with `eg-verify`,\n  no access to the machine required.\n\n## What a denial looks like\n\nThe client receives a JSON-RPC error instead of a tool result, and the\nreceipt log records:\n\n```json\n{\n  \"tool\": \"http.post\",\n  \"decision\": \"deny\",\n  \"reason\": \"exfiltration: outbound call carrying secret material\",\n  \"policyVersion\": \"starter-1\",\n  \"sig\": \"…\"\n}\n```\n\n## Policy\n\nStart from the canonical starter policy and edit YAML — allow/deny rules\nper tool, argument matching, path and URL constraints. Full schema:\n[docs/POLICY.md](https://github.com/11-11AI/execution-governance/blob/main/docs/POLICY.md).\n\n## CLI reference\n\n```\nmcp-gate --policy <file> [options] -- <server-command> [args...]\n```\n\n| Flag                | Purpose                                                                                                                           |\n| ------------------- | --------------------------------------------------------------------------------------------------------------------------------- |\n| `--policy <path>`   | Policy file. Required unless `EG_CONTROL_PLANE_URL` is set. Malformed policy = every call denied.                                 |\n| `--receipts <path>` | Append signed receipts here (default `./eg-receipts.jsonl`).                                                                      |\n| `--key <path>`      | Ed25519 seed for a stable signing key. Without it a key is generated per run and receipts are not verifiable across restarts.     |\n| `--timeout <ms>`    | Policy evaluation timeout. A timeout is a deny.                                                                                   |\n| `--name <name>`     | Tool namespace prefix. Defaults to a name derived from the wrapped command. See the warning below — this affects policy matching. |\n| `--validate`        | Check the policy and exit. Starts no server, writes no receipts. Safe in CI.                                                      |\n| `-h`, `--help`      | Show usage and exit 0.                                                                                                            |\n| `--`                | Everything after is the wrapped server command, verbatim.                                                                         |\n\n> **Set `--key` before you rely on the receipts.** Without it, a new signing\n> key is generated per run and receipts cannot be verified across restarts.\n> Each run's receipts still verify against that run's own key, so nothing looks\n> broken — the failure only appears later, when you try to verify an older file\n> and no longer have the key it was signed with. The gate warns on startup when\n> it generates an ephemeral key.\n\n> **`--name` is part of what your policy matches on.** Tool calls are evaluated\n> as `<name>.<tool>`, so a rule written for `their-server.http_post` stops\n> matching if the prefix changes. The default is derived from the wrapped\n> command, which means editing the command in your client config can change the\n> prefix as a side effect — and a rule that no longer matches is a rule that no\n> longer denies. Set `--name` explicitly and the prefix stops depending on how\n> the server happens to be launched.\n\nValidate a policy before you depend on it:\n\n```bash\nnpx @11ai/mcp-gate --validate --policy eg-policy.yaml\n```\n\nExits 0 with the policy version, or 1 naming the fault. This runs the engine's\nown parser rather than a schema check, so it catches what a schema cannot: a\nrule naming an `actionClass` that was never declared, and an `argsPattern` that\nis not a compilable regex. Both produce a policy that loads as valid YAML and\nthen denies every call, which looks identical to a very strict policy.\n\nExit behavior: if the wrapped server exits, the gate exits with the same\ncode. If the gate cannot start (bad policy, missing binary), it exits\nnonzero and **no server starts** — fail-closed extends to process\nlifecycle.\n\n## Works with\n\n- **Claude Desktop / Claude Code** — wrap any server in\n  `claude_desktop_config.json` or `.mcp.json`\n- **Cursor, Windsurf, any MCP client** — anything that launches stdio MCP\n  servers\n- **Any MCP server** — filesystem, GitHub, databases, browsers; the gate\n  is server-agnostic\n\n## Versioning\n\nSemver, tracks `@11ai/execution-governance` minors. The receipt format is\nversioned independently; old receipt files stay verifiable.\n\n## The @11ai packages\n\n| Package                                                                                  | What it is                                       |\n| ---------------------------------------------------------------------------------------- | ------------------------------------------------ |\n| [`@11ai/execution-governance`](https://www.npmjs.com/package/@11ai/execution-governance) | SDK: gate any function call, not just MCP.       |\n| [`@11ai/mcp-gate`](https://www.npmjs.com/package/@11ai/mcp-gate)                         | This package.                                    |\n| `@11ai/identity-oidc` _(coming)_                                                         | OIDC-verified principals bound to every receipt. |\n| `execution-governance` on PyPI _(coming)_                                                | Python SDK, cross-verifiable receipts.           |\n\n## Part of Execution Governance\n\nBuilt on\n[`@11ai/execution-governance`](https://www.npmjs.com/package/@11ai/execution-governance)\n— the SDK for gating any function call (not just MCP) with the same policy\nengine and receipt chain. Try the prompt-injection demo:\n\n```bash\ngit clone https://github.com/11-11AI/execution-governance && cd execution-governance\nnpm install && npm run demo\n```\n\n## License\n\nApache-2.0. Fully functional locally — no account, no hosted dependency.\nSee [LICENSE](https://github.com/11-11AI/execution-governance/blob/main/LICENSE).\n[LICENSING.md](https://github.com/11-11AI/execution-governance/blob/main/LICENSING.md)\nsets out, per component, what is open permanently and what is commercial: every\npart needed to verify a receipt is Apache-2.0 and stays that way.\n","readmeFilename":"README.md"}