Skip to content

MCP

pip install "agentguard-oss[mcp]"

Expose guarded tools from an MCP Python SDK 1.x FastMCP server:

"""Run from the repository root after installing .[mcp]. Audit goes to disk, not stdout."""

from pathlib import Path

from mcp.server.fastmcp import FastMCP

from agentguard import Guard
from agentguard.adapters.mcp import register_tool
from agentguard.execution import FilesystemExecutor

root = Path("workspace").resolve()
root.mkdir(exist_ok=True)
guard = Guard("examples/policy.yaml")
server = FastMCP("AgentGuard")


def read_file(path: str) -> str:
    """Read a workspace file through AgentGuard."""
    raise AssertionError("The controlled executor handles the read")


register_tool(
    server, guard, read_file, capability="filesystem.read", executor=FilesystemExecutor(root)
)

if __name__ == "__main__":
    server.run(transport="stdio")

register_tool(server, guard, function, capability=..., **options) decorates the function and adds only the guarded version to the server. Run the example from the repository root with python examples/mcp_server.py.

MCP validates arguments against the tool schema first; AgentGuard validates again. Requests MCP rejects before dispatch never reach AgentGuard and are not in its audit log. Denials come back to the client as tool errors with AgentGuard's reasons. Keep the audit log on disk, not stdout, when using the stdio transport.