Back to Browse

Agent Policy Enforcement MCP Server

Developer ToolsUse Caution2.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amount<100...

About

Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amount<100...

Remote endpoints: streamable-http: https://api.meok.ai/v1/a2a/policy-enforcement

Security Report

2.2
Use Caution2.2Critical Risk

This MCP server has moderate security concerns centered around unauthenticated access to core policy enforcement tools and reliance on an external metering system with fail-open behavior. While the server properly uses environment variables for API keys and includes HMAC attestation signing, the default allow behavior when authentication checks fail, combined with the lack of built-in rate limiting on unsigned requests, creates a gap between the stated security purpose (policy enforcement for EU AI Act compliance) and the actual enforcement. The code quality is reasonable, but the authentication model does not match the high-security use case. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed ยท 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

MCP Scorecard: 78/100

Agent Policy Enforcement MCP

MEOK AI Labs EU AI Act License PyPI

Per-agent-pair IAM for A2A

Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amount<1000'), gate every A2A call via evaluate_call. EU AI Act Art 14 + ISO 42001 Annex A.7 evidence with signed policy-decision attestations.


๐Ÿš€ Quick Start

# Install via pip
pip install agent_policy_enforcement_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install agent-policy-enforcement-mcp --client claude

โœจ Features

  • Per-agent-pair IAM
  • Policy enforcement
  • Permission inheritance
  • Audit logging
  • Dynamic updates

๐Ÿ“– Documentation

๐Ÿ›ก๏ธ Compliance

This MCP server is built with EU AI Act compliance built-in:

  • Free โ€” generous daily limit (100-1,000 depending on operation)

  • Pro ยฃ199/mo โ€” unlimited + signed HMAC attestations with public verify URLs โ€” subscribe

  • Enterprise ยฃ1,499/mo โ€” multi-tenant + custom predicate DSL + SIEM webhook push โ€” subscribe

  • โœ… Article 9 โ€” Risk Management System

  • โœ… Article 13 โ€” Transparency & Instructions for Use

  • โœ… Article 15 โ€” Bias Detection & Testing

  • โœ… Article 26 โ€” FRIA Support (where applicable)

  • โœ… Article 50 โ€” AI Content Watermarking (where applicable)

Need help getting compliant? Book a free 15-min diagnostic โ†’

๐Ÿข Enterprise

Need custom development, SLA guarantees, or white-label deployment?

  • Pro: ยฃ79/mo โ€” Full MCP suite + EU AI Act tracking
  • Enterprise: ยฃ499/mo โ€” Custom dev + SLA + Dedicated support

View Pricing โ†’ | Contact Sales โ†’

๐Ÿค Part of the MEOK Ecosystem

This server is part of the MEOK AI Labs ecosystem โ€” 26 PyPI packages ยท ~16,300 monthly installs.

DomainPurpose
councilof.aiEU AI Act compliance marketplace
safetyof.aiAI safety & monitoring
meok.aiSovereign AI platform
cobolbridge.aiLegacy modernization

๐Ÿ“œ License

MIT ยฉ CSOAI-ORG


  • Prompt Injection Firewall โ†’ uvx agent-prompt-injection-firewall-mcp ยท PyPI ยท GitHub
  • Data Residency โ†’ uvx agent-data-residency-mcp ยท PyPI ยท GitHub
  • Certified Handoff โ†’ uvx agent-handoff-certified-mcp ยท PyPI ยท GitHub
  • Audit Logger โ†’ uvx agent-audit-logger-mcp ยท PyPI ยท GitHub
  • Rate Limiter โ†’ uvx agent-rate-limiter-mcp ยท PyPI ยท GitHub

Full catalogue + Anthropic Registry verify links: meok.ai/anthropic-registry

Protocol coverage + Universal PAYG

This MCP is part of MEOK's 47-MCP fleet that bridges every active agent-interop protocol and 30+ regulatory frameworks. See the full coverage matrix at meok.ai/protocols.

Agent interop protocols supported (8 live):

  • โœ… MCP (Anthropic) โ€” native
  • โœ… A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
  • โœ… IBM ACP โ€” covered via A2A merge
  • โ— Stripe ACP (Agentic Commerce Protocol) โ€” Q3 bridge via agent-commerce-protocol-mcp
  • โ— AP2 (Google Agent Payments) โ€” partial via agent-commerce-payments-mcp
  • โ— x402 (Coinbase HTTP 402) โ€” partial via api.meok.ai gateway
  • โ†’ OASF / AGNTCY (Cisco Outshift + Linux Foundation) โ€” Q3 bridge
  • ๐Ÿ‘ ANP (Cisco Agent Network) โ€” watch-list

Pricing options:

OptionPriceBest for
Self-host (this MCP)ยฃ0 โ€” MITDevs
This MCP Starterยฃ29/moOne-MCP teams
This MCP Proยฃ79/moProduction + 24h SLA
Universal PAYGยฃ29/mo + ยฃ0.0002/callSpiky usage across many MCPs
Substrate bundle (this category)ยฃ99-ยฃ499/moA whole pack
MEOK Universeยฃ1,499/moAll 47 MCPs, 500K calls

Each tier above the free self-host adds HMAC-signed attestations verifiable at verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated buyers can deploy without vendor-lock-in objections.

๐Ÿ’ธ Try MEOK in 30 seconds โ€” instant buy ladder

TierPriceWhat you getStripe
Smoke testยฃ1Signed sample MCP-Hardening report + Article 50 PDFhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Quick Kitยฃ9EU AI Act Article 50 implementation guide (C2PA + EU-Icon)https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Founder Callยฃ2930-min 1-on-1 with the founderhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t

Refundable. UK Stripe โ€” VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "agent-policy-enforcement-mcp": {
      "command": "uvx",
      "args": ["agent-policy-enforcement-mcp"]
    }
  }
}

Or: pip install agent-policy-enforcement-mcp then run the agent-policy-enforcement-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use define_policy to โ€ฆ"
  • "Use evaluate_call to โ€ฆ"
  • "Use list_policies to โ€ฆ"

Reviews

No reviews yet

Be the first to review this server!

Agent Policy Enforcement MCP Server - Per-agent-pair IAM for A2A. Define policies ('orchestrator | MCP Marketplace