{"_id":"@agent-monitor/gateway","_rev":"3-5c8edeb4552034252e27743ba45108ed","name":"@agent-monitor/gateway","dist-tags":{"latest":"4.1.1"},"versions":{"0.3.0":{"name":"@agent-monitor/gateway","version":"0.3.0","license":"MIT","_id":"@agent-monitor/gateway@0.3.0","maintainers":[{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"}],"dist":{"shasum":"547712db6692e6966c4569c651259675bfcc8bcb","tarball":"https://registry.npmjs.org/@agent-monitor/gateway/-/gateway-0.3.0.tgz","fileCount":22,"integrity":"sha512-oD0dr7B5kS0FWJIYKZLLzD7o/4owYE577QhM7wWRsUUYFLT7p+BHbZiX6OL1M7WceklD80cfIdToZg0EmSUzgg==","signatures":[{"sig":"MEQCIFzvzb3LbPK1dK5tcEVHNJhiau1/0xKCHrk8kk51AhYtAiBBAk6ibDMoiN67+fBbqOPSuUhNfWT1XDCOSAip3HCT+w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":132803},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"a17f596740cb003dfee6eb6ee1e73589ba7b87ec","scripts":{"build":"tsc","clean":"rm -rf dist"},"_npmUser":{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"},"_npmVersion":"10.9.0","description":"Universal Agent Control Boundary & Transparent MCP Proxy for Agent Monitor (V0.3)","directories":{},"_nodeVersion":"22.11.0","dependencies":{"picocolors":"^1.1.1","@agent-monitor/core":"^0.3.0","@agent-monitor/agent":"^0.3.0","@agent-monitor/server":"^0.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^20.17.0"},"_npmOperationalInternal":{"tmp":"tmp/gateway_0.3.0_1788521708857_0.8316965202366915","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"@agent-monitor/gateway","version":"4.1.0","license":"MIT","_id":"@agent-monitor/gateway@4.1.0","maintainers":[{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"}],"dist":{"shasum":"0ea39f594eba8e2fad10ab0320be4ac464dabd32","tarball":"https://registry.npmjs.org/@agent-monitor/gateway/-/gateway-4.1.0.tgz","fileCount":26,"integrity":"sha512-q54iYbbVwdwMNEahsQP8qKbXIMn0jbDnS2VAnPY5EhNSPbI+rsKc69rdFtT2QUyKyk5zjwKQv9qJu6POQq/gdg==","signatures":[{"sig":"MEQCIFKiATpKxA0BcQ5LM/Ps9IN9dFAWMvHe+sz3FdG4zhfmAiAarxua49V1FGBq9T/JspKfWVg5FsUHjVbymStTc6FEjg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":166415},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"6bd026354267b19131d79bd47afa4fa35eb5c753","scripts":{"build":"tsc","clean":"rm -rf dist"},"_npmUser":{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"},"_npmVersion":"10.9.0","description":"Universal Agent Control Boundary & Transparent MCP Proxy for Agent Monitor (V4.1.0)","directories":{},"_nodeVersion":"22.11.0","dependencies":{"picocolors":"^1.1.1","@agent-monitor/core":"^4.1.0","@agent-monitor/agent":"^4.1.0","@agent-monitor/server":"^4.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^20.17.0"},"_npmOperationalInternal":{"tmp":"tmp/gateway_4.1.0_1788540000189_0.648510329827461","host":"s3://npm-registry-packages-npm-production"}},"4.1.1":{"name":"@agent-monitor/gateway","version":"4.1.1","description":"Universal Agent Control Boundary & Transparent MCP Proxy for Agent Monitor (V4.1.1)","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","publishConfig":{"access":"public"},"license":"MIT","scripts":{"build":"tsc","clean":"rm -rf dist"},"dependencies":{"@agent-monitor/core":"^4.1.1","@agent-monitor/server":"^4.1.1","@agent-monitor/agent":"^4.1.1","picocolors":"^1.1.1"},"devDependencies":{"@types/node":"^20.17.0","typescript":"^5.6.3"},"_id":"@agent-monitor/gateway@4.1.1","gitHead":"6bebe161c22d341804b4da801d6bb5fcedf1b3f0","_nodeVersion":"22.11.0","_npmVersion":"10.9.0","dist":{"integrity":"sha512-7dZ3Tl7x1WgAmK1gUswtfS2gmwpdZCELf7RrRezop9v8FDcitketP74PMyEDwhGYGCu5FMlitA9ZvhXFr7eOIQ==","shasum":"f02794ed20cb6b066c78f9598a3095b49ad12df1","tarball":"https://registry.npmjs.org/@agent-monitor/gateway/-/gateway-4.1.1.tgz","fileCount":26,"unpackedSize":166415,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDO/nRLEQbzRZLmCMZT8ZHcZOtsQj48QXYKDgOFzhWXxwIhALOUR4yfIiXZkBbzwDKIeGGel4teZ7zGPjfkBwUaHQZw"}]},"_npmUser":{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"},"directories":{},"maintainers":[{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gateway_4.1.1_1788596405385_0.7759042655385981"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-04T11:35:08.664Z","modified":"2026-09-05T08:20:05.676Z","0.3.0":"2026-09-04T11:35:09.005Z","4.1.0":"2026-09-04T16:40:00.372Z","4.1.1":"2026-09-05T08:20:05.513Z"},"license":"MIT","description":"Universal Agent Control Boundary & Transparent MCP Proxy for Agent Monitor (V4.1.1)","maintainers":[{"name":"ssarthak.s","email":"ssarthakxd@gmail.com"}],"readme":"# `@agent-monitor/gateway`\n\nUniversal Agent Control Boundary & Transparent Model Context Protocol (MCP) Stdio Proxy for Agent Monitor (V4.1.0).\n\n---\n\n## Overview\n\n`@agent-monitor/gateway` provides a transparent, zero-overhead stdio interceptor that sits between any MCP client (such as Claude Desktop, Cursor, Continue, or custom agent runtimes) and downstream MCP servers.\n\nIt enforces the non-negotiable **Core Security Invariant** across all tool calls and resource accesses:\n\n$$\\text{REQUEST} \\longrightarrow \\text{KILL SWITCH} \\longrightarrow \\text{QUARANTINE} \\longrightarrow \\text{RATE LIMIT} \\longrightarrow \\text{NORMALIZATION} \\longrightarrow \\text{GUARDRAILS} \\longrightarrow \\text{RISK/MUTATION} \\longrightarrow \\text{POLICY} \\longrightarrow \\text{APPROVAL} \\longrightarrow \\text{REVALIDATION} \\longrightarrow \\text{EXECUTION} \\longrightarrow \\text{INSPECTION} \\longrightarrow \\text{SQLITE} \\longrightarrow \\text{INCIDENT}$$\n\n---\n\n## Key Features\n\n- **Universal Stdio Interception**: Intercepts JSON-RPC 2.0 frames over `stdin`/`stdout` without requiring modifications to agent or server code.\n- **Sticky Source Quarantine & Trust**: Blocks calls from quarantined MCP sources fail-closed; quarantine status persists across process restarts until manually trusted.\n- **Sliding-Window Rate Limiting**: Enforces requests-per-minute bounds to protect downstream systems from prompt loops.\n- **Bounded Downstream Execution Timeouts**: Terminates hanging requests with 30s defaults and timer resource cleanup.\n- **Strict RFC 8089 URI & Path Normalization**: Resolves `file://localhost/...`, UNC network shares, and custom URIs with fail-closed security.\n- **Tool Fingerprinting & Rug-Pull Detection**: Computes cryptographic SHA-256 signatures of tool definitions discovered via `tools/list`. Flags runtime mutations and schema alterations before execution.\n- **Authoritative Pre- & Post-Execution Kill Switch**: Checks SQLite-backed circuit breaker state before and immediately after human approval to eliminate race conditions.\n- **Human-in-the-Loop Approvals**: Prompts operators via terminal or web dashboard when policies evaluate to `ASK`.\n- **Deep Result & Secret Inspection**: Catches leaked API keys, AWS credentials, JWT tokens, and private SSH/TLS keys before returning to the agent.\n- **Behavioral Sequence Integration V2**: Correlates multi-step sequences across sessions (`SEC_MUTATION_TO_READ`, `SEC_TRAVERSAL_TO_EXEC`, `SEC_DENIAL_TO_ALTERNATIVE`, `SEC_SENSITIVE_TO_NETWORK`).\n\n---\n\n## Architecture\n\n```text\n┌─────────────────┐\n│   MCP Client    │ (Claude Desktop, Cursor, Custom Agent)\n└────────┬────────┘\n         │ JSON-RPC (stdio)\n         ▼\n┌─────────────────────────────────────────────────────────────┐\n│                   McpStdioProxy (Gateway)                   │\n│                                                             │\n│  1. Authoritative Pre-Kill Switch Check                     │\n│  2. Sticky MCP Source Quarantine Check                      │\n│  3. Sliding-Window Rate Limiter Check                       │\n│  4. Action Normalization & Canonical Classification         │\n│  5. RFC 8089 & Workspace Guardrail Validation               │\n│  6. Deterministic Risk Scoring (0–100)                      │\n│  7. Policy Evaluation (ALLOW / DENY / ASK)                  │\n│  8. Human-in-the-Loop Approval Workflow                     │\n│  9. Post-Approval Kill Switch Verification                  │\n│ 10. Tool Schema Mutation Check (Rug-Pull Detection)         │\n│ 11. Downstream Execution with Bounded Timeouts              │\n│ 12. McpResultInspector (Secret Leak Redaction & 500KB Cap)  │\n│ 13. Monotonic Event Sequencing to Chained SQLite Audit Log  │\n└────────┬────────────────────────────────────────────────────┘\n\n         │ JSON-RPC (stdio)\n         ▼\n┌─────────────────┐\n│ Downstream MCP  │ (Filesystem, Postgres, Shell, GitHub, etc.)\n│ Server Process  │\n└─────────────────┘\n```\n\n---\n\n## Method Security Table\n\n| JSON-RPC Method   | Security Handling                                                                                                                      |\n| :---------------- | :------------------------------------------------------------------------------------------------------------------------------------- |\n| `tools/call`      | Full invariant: Kill switch, normalization, workspace check, risk, policy, approval, execution, result inspection, SQLite persistence. |\n| `resources/read`  | Full invariant: URI normalized via `fileURLToPath`, workspace containment, risk, policy, approval, execution, inspection.              |\n| `tools/list`      | Discovers tools, computes SHA-256 fingerprint, persists baselines, detects runtime mutations (`TOOL_CHANGED`).                         |\n| `resources/list`  | Audited and forwarded downstream.                                                                                                      |\n| `notifications/*` | Validated for well-formed JSON-RPC; bypasses execution pipeline without triggering actions.                                            |\n| Batch Requests    | Each request inside a batch is evaluated individually with full security guarantees.                                                   |\n\n---\n\n## Installation\n\n```bash\nnpm install @agent-monitor/gateway @agent-monitor/core @agent-monitor/server @agent-monitor/agent\n```\n\n---\n\n## Programmatic Usage\n\n```typescript\nimport { McpStdioProxy } from \"@agent-monitor/gateway\";\nimport { PolicyEngine } from \"@agent-monitor/core\";\nimport { SessionRepository, createDatabase } from \"@agent-monitor/server\";\n\nconst db = createDatabase(\"./data.db\");\nconst repository = new SessionRepository(db);\n\nconst proxy = new McpStdioProxy({\n  command: \"npx\",\n  args: [\"-y\", \"@modelcontextprotocol/server-filesystem\", \"/safe/workspace\"],\n  sessionId: \"ses_mcp_prod\",\n  workspaceRoot: \"/safe/workspace\",\n  repository,\n  policyEngine: new PolicyEngine(),\n  eventSink: {\n    emit: async (event) => console.log(\"Audit Event:\", event.type),\n  },\n  clientInputStream: process.stdin,\n  clientOutputStream: process.stdout,\n});\n\nawait proxy.start();\n```\n","readmeFilename":"README.md"}