MCP¶
pip install "agentguard-oss[mcp]"
Expose guarded tools from an MCP Python SDK
1.x FastMCP server:
"""Run from the repository root after installing .[mcp]. Audit goes to disk, not stdout."""
from pathlib import Path
from mcp.server.fastmcp import FastMCP
from agentguard import Guard
from agentguard.adapters.mcp import register_tool
from agentguard.execution import FilesystemExecutor
root = Path("workspace").resolve()
root.mkdir(exist_ok=True)
guard = Guard("examples/policy.yaml")
server = FastMCP("AgentGuard")
def read_file(path: str) -> str:
"""Read a workspace file through AgentGuard."""
raise AssertionError("The controlled executor handles the read")
register_tool(
server, guard, read_file, capability="filesystem.read", executor=FilesystemExecutor(root)
)
if __name__ == "__main__":
server.run(transport="stdio")
register_tool(server, guard, function, capability=..., **options) decorates the function
and adds only the guarded version to the server. Run the example from the repository root
with python examples/mcp_server.py.
MCP validates arguments against the tool schema first; AgentGuard validates again. Requests MCP rejects before dispatch never reach AgentGuard and are not in its audit log. Denials come back to the client as tool errors with AgentGuard's reasons. Keep the audit log on disk, not stdout, when using the stdio transport.