Back to Browse

Agent Policy Enforcement MCP Server

Developer ToolsUse Caution2.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amount<100...

About

Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amount<100...

Remote endpoints: streamable-http: https://api.meok.ai/v1/a2a/policy-enforcement

Security Report

2.2
Use Caution2.2Critical Risk

This MCP server has moderate security concerns centered around unauthenticated access to core policy enforcement tools and reliance on an external metering system with fail-open behavior. While the server properly uses environment variables for API keys and includes HMAC attestation signing, the default allow behavior when authentication checks fail, combined with the lack of built-in rate limiting on unsigned requests, creates a gap between the stated security purpose (policy enforcement for EU AI Act compliance) and the actual enforcement. The code quality is reasonable, but the authentication model does not match the high-security use case. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Reviews

No reviews yet

Be the first to review this server!