AgentOS MCP Server

June 8, 2026 ยท View on GitHub

Important

Public Preview โ€” This npm package is a public preview release. APIs may change before GA.

Build safe AI agents with natural language and 0% policy violations

npm version MCP Registry License: MIT

Part of Agent OS - Kernel-level governance for AI agents

๐Ÿš€ Quick Install

npx agentos-mcp-server

npm: agentos-mcp-server
MCP Registry: io.github.microsoft/agentos

Overview

AgentOS MCP Server brings the complete Agent OS safety framework to any MCP-compatible AI assistant including Claude Desktop, GitHub Copilot, Cursor, and more. Create, deploy, and manage policy-compliant autonomous agents through natural conversation.

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚           Claude Desktop / Copilot / Cursor                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚            "Create an agent that..."                    โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                          โ”‚ MCP Protocol
            โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
            โ”‚   ๐Ÿ›ก๏ธ AgentOS MCP Server   โ”‚
            โ”‚                           โ”‚
            โ”‚  โ€ข 10 Tools              โ”‚
            โ”‚  โ€ข Policy Engine         โ”‚
            โ”‚  โ€ข Approval Workflows    โ”‚
            โ”‚  โ€ข Audit Logging         โ”‚
            โ”‚  โ€ข Template Library      โ”‚
            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                          โ”‚
      โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
      โ”‚                   โ”‚                   โ”‚
โ”Œโ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”      โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”     โ”Œโ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Agents   โ”‚      โ”‚  Policies   โ”‚     โ”‚  Audit    โ”‚
โ”‚  (Local)  โ”‚      โ”‚  (Enforced) โ”‚     โ”‚  (Logged) โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜      โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜     โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โœจ Features

๐Ÿค– Natural Language Agent Creation

User: Create an agent that processes customer feedback from support emails daily

Claude: โœ… Agent Created Successfully!

Agent: customer-feedback-processor
โœ… Data Source: Email inbox via IMAP
โœ… Processing: Sentiment analysis + categorization
โœ… Output: Daily summary to Slack
โœ… Schedule: Every day at 9 AM

Safety Policies Applied:
๐Ÿ›ก๏ธ PII Protection: Customer emails/names anonymized
๐Ÿ›ก๏ธ Rate Limiting: Max 1000 emails per run
๐Ÿ›ก๏ธ Human Review: Negative sentiment cases flagged

๐Ÿ›ก๏ธ Policy Enforcement with 0% Violations

  • 6 built-in policies (PII, rate-limiting, cost-control, data-deletion, secrets, human-review)
  • Real-time policy evaluation
  • Automatic blocking of violations
  • Clear explanations and alternatives

โœ… Human-in-the-Loop Approval Workflows

  • Risk-based approval requirements
  • Multi-party approval for critical actions
  • Email/Slack notifications
  • Expiration handling

๐Ÿ“Š Complete Audit Trail

  • Every action logged immutably
  • Policy evaluations recorded
  • Compliance report generation
  • Export for auditors

๐Ÿ“‹ Template Library

  • 10+ agent templates (data processor, email assistant, backup, scraper, etc.)
  • 6+ policy templates (GDPR, SOC 2, HIPAA, PCI DSS, etc.)
  • Industry-specific compliance frameworks

๐Ÿ›๏ธ Compliance Ready

  • SOC 2 - Security & availability controls
  • GDPR - EU data protection
  • HIPAA - Healthcare data privacy
  • PCI DSS - Payment card security
  • CCPA - California privacy
  • NIST - Cybersecurity framework
  • ISO 27001 - Information security
  • FedRAMP - Federal authorization

๐Ÿš€ Quick Start

Step 1: Configure Claude Desktop

Add to your claude_desktop_config.json:

Windows: %APPDATA%\Claude\claude_desktop_config.json macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Linux: ~/.config/Claude/claude_desktop_config.json

{
  "mcpServers": {
    "agentos": {
      "command": "npx",
      "args": ["-y", "agentos-mcp-server"],
      "env": {
        "AGENTOS_POLICY_MODE": "strict"
      }
    }
  }
}

Step 2: Restart Claude Desktop

Close and reopen Claude Desktop to load the MCP server.

Step 3: Start Building Agents!

Just ask Claude naturally:

"Create an agent that backs up my Documents folder to Google Drive every night"

Claude will:

  1. Create the agent with appropriate configuration
  2. Suggest safety policies based on the task
  3. Let you test before deployment
  4. Deploy with monitoring enabled

๐Ÿ’ฌ Example Conversations

Creating a Data Processing Agent

User: I need an agent that processes customer feedback from support emails daily

Claude: โœ… Agent Created Successfully!

Agent: customer-feedback-processor
ID: a1b2c3d4-e5f6-7890-abcd-ef1234567890
Status: draft
Language: python

Task:
Process customer feedback from support emails daily

Workflow Steps:
1. connect_email: email.connect
2. process_data: execute
3. output_results: output

Safety Policies Applied:
๐Ÿ›ก๏ธ PII Protection: Customer emails/names anonymized
๐Ÿ›ก๏ธ Rate Limiting: Max 1000 emails per run
๐Ÿ›ก๏ธ Human Review: Negative sentiment cases flagged

Next Steps:
1. Use `test_agent` to run a dry-run test
2. Use `attach_policy` to add more safety policies
3. Use `deploy_agent` when ready to run

Testing Before Deployment

User: Test this agent with a scenario of processing 100 emails

Claude: โœ… Test PASSED

Agent: customer-feedback-processor
Scenario: Process 100 customer emails
Mode: Dry Run (no changes)

Configuration Check: โœ… Valid
Workflow Check: โœ… Valid (3 steps)

Policy Evaluation: โœ… No violations detected

Warnings:
โš ๏ธ  PII access logged

Resource Estimates:
- Duration: ~30 seconds
- Cost: \$0.05

Next Step: Use `deploy_agent` to deploy this agent.

Checking Compliance

User: Check if this agent is SOC 2 compliant

Claude: # Compliance Report: SOC2

Agent: customer-feedback-processor
Framework: SOC2
Date: 2026-01-30

## Summary
โœ… COMPLIANT
Score: 100% (4/4 controls passed)

## Control Assessment

โœ… CC6.1: Logical Access Controls
   Restrict logical access to information assets
   Evidence: Policy enforcement enabled, Access logging active

โœ… CC6.6: Security Event Monitoring
   Detect and respond to security events
   Evidence: Audit logging enabled, Event timestamps recorded

โœ… CC7.2: Incident Response
   Respond to security incidents
   Evidence: Human review enabled, Escalation procedures in place

โœ… CC8.1: Change Management
   Manage changes to system components
   Evidence: Deployment approval required, Version control enabled

Creating Custom Policies

User: Create a policy that blocks access to customer credit card data

Claude: โœ… Custom Policy Created

Policy: Block Access To Customer
ID: custom-a1b2c3d4
Category: security

Description:
Block access to customer credit card data

Rules Generated (1):

๐ŸŸ  custom_block_rule [high]
   Block actions based on: block access to customer credit card data
   Action: deny

Usage:
1. Attach to agent: `attach_policy` with policyId "custom-a1b2c3d4"
2. Test enforcement: `test_agent` with policy scenarios
3. View active policies: `get_agent_status`

๐Ÿ”ง Available Tools

ToolDescription
create_agentCreate agent from natural language description
attach_policyAttach safety policies to agents
test_agentDry-run test before deployment
deploy_agentDeploy agent locally or to cloud
get_agent_statusGet agent status and metrics
list_templatesBrowse agent and policy templates
request_approvalCreate approval request for sensitive actions
audit_logQuery audit trail
create_policyCreate custom policy from description
check_complianceCheck against compliance frameworks

Tool Details

create_agent

Create a new AI agent from a natural language description with automatic policy recommendations.

Parameters:

ParameterTypeRequiredDescription
descriptionstringโœ…Natural language description of agent task
policiesstring[]Policy templates to apply
approvalRequiredbooleanRequire human approval before execution
languagestringpython, typescript, javascript, go
schedulestringCron schedule for recurring execution

attach_policy

Attach safety policies to an agent with conflict detection.

Parameters:

ParameterTypeRequiredDescription
agentIdstringโœ…Agent ID to attach policy to
policyIdstringโœ…Policy template ID
customRulesobject[]Additional custom rules

test_agent

Run a dry-run test with simulated scenarios.

Parameters:

ParameterTypeRequiredDescription
agentIdstringโœ…Agent ID to test
scenariostringโœ…Test scenario description
mockDataobjectMock data for testing
dryRunbooleanRun without side effects (default: true)

deploy_agent

Deploy an agent to local or cloud environment.

Parameters:

ParameterTypeRequiredDescription
agentIdstringโœ…Agent ID to deploy
environmentstringlocal or cloud
autoStartbooleanStart immediately after deployment

check_compliance

Check an agent against regulatory frameworks.

Parameters:

ParameterTypeRequiredDescription
agentIdstringโœ…Agent ID to check
frameworkstringโœ…SOC2, GDPR, HIPAA, PCI_DSS, CCPA, NIST, ISO27001, FEDRAMP
generateReportbooleanGenerate detailed report

๐Ÿ“‹ Policy Templates

Built-in Security Policies

Policy IDNameDescription
pii-protectionPII ProtectionProtects personally identifiable information (GDPR)
rate-limitingRate LimitingPrevents resource abuse through rate limits
cost-controlCost ControlPrevents runaway costs from automation
data-deletionData Deletion SafetyPrevents accidental data loss
secrets-protectionSecrets ProtectionPrevents exposure of credentials
human-reviewHuman Review RequiredRequires approval for sensitive actions

Compliance Templates

Template IDFrameworkDescription
gdpr-complianceGDPREU General Data Protection Regulation
soc2-securitySOC 2SOC 2 Type II security controls
hipaa-healthcareHIPAAHealthcare data privacy (PHI protection)
pci-dss-paymentsPCI DSSPayment card data security
read-only-accessSecurityRestricts database to read-only
production-safetyOperationsExtra safeguards for production

๐Ÿค– Agent Templates

Data Processing

TemplateDescriptionDefault Policies
data-processorProcesses and transforms data filesrate-limiting, cost-control
web-scraperScrapes websites for data collectionrate-limiting, cost-control
report-generatorGenerates periodic reportspii-protection, rate-limiting

Communication

TemplateDescriptionDefault Policies
email-assistantMonitors and processes emailspii-protection, human-review
slack-botAutomated Slack notificationshuman-review, rate-limiting

Infrastructure

TemplateDescriptionDefault Policies
backup-agentBacks up files to cloud storagecost-control
api-monitorMonitors API health and performancerate-limiting
file-organizerOrganizes files based on rulesdata-deletion

Analytics

TemplateDescriptionDefault Policies
database-analystQueries databases and generates reportsdata-deletion, pii-protection
content-moderatorModerates user-generated contenthuman-review, pii-protection

โš™๏ธ Configuration

Environment Variables

VariableDescriptionDefault
AGENTOS_API_KEYAPI key for cloud features(none)
AGENTOS_POLICY_MODEstrict or permissivestrict
AGENTOS_DATA_DIRLocal data directory.agentos
AGENTOS_LOG_LEVELdebug, info, warn, errorinfo

Policy Modes

ModeBehavior
strictAny policy violation blocks the action
permissiveOnly critical violations block (warnings logged)

Data Storage

All data is stored locally in the AGENTOS_DATA_DIR:

.agentos/
โ”œโ”€โ”€ agents/           # Agent configurations
โ”‚   โ””โ”€โ”€ {id}.json
โ”œโ”€โ”€ approvals/        # Approval requests
โ”‚   โ””โ”€โ”€ {id}.json
โ””โ”€โ”€ audit/            # Audit logs (JSONL format)
    โ””โ”€โ”€ {date}.jsonl

๐Ÿ—๏ธ Architecture

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                     Claude Desktop                           โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚                    Claude AI Model                      โ”‚ โ”‚
โ”‚  โ”‚     Natural language understanding & orchestration      โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚                         โ”‚ MCP Protocol                       โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚                    MCP Client                           โ”‚ โ”‚
โ”‚  โ”‚          Tool discovery & request handling              โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                          โ”‚ stdio
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚               @agentos/mcp-server (Node.js)                 โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚                    MCP Server                           โ”‚ โ”‚
โ”‚  โ”‚            Tool/Resource/Prompt handlers                โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚
โ”‚  โ”‚  Agent   โ”‚ โ”‚  Policy  โ”‚ โ”‚ Approval โ”‚ โ”‚    Audit      โ”‚  โ”‚
โ”‚  โ”‚ Manager  โ”‚ โ”‚  Engine  โ”‚ โ”‚ Workflow โ”‚ โ”‚   Logger      โ”‚  โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚
โ”‚  โ”‚              Template Library (50+ templates)           โ”‚ โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                          โ”‚ HTTPS (optional)
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚              AgentOS Cloud Platform (Future)                โ”‚
โ”‚     โ€ข Persistent storage  โ€ข Multi-tenant  โ€ข Enterprise      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ”’ Security

FeatureDescription
Policy EnforcementAll actions validated against policies before execution
Data RedactionSensitive data automatically redacted from logs
Secret ProtectionSecrets never stored in plain text
Audit TrailComplete immutable log for compliance
Human ApprovalRequired for high-risk operations
Local-FirstAll data stored locally by default

๐Ÿ’ป Development

Local Development

# Clone the repository
git clone https://github.com/microsoft/agent-governance-toolkit
cd agent-governance-python/agent-os/extensions/mcp-server

# Install dependencies
npm install

# Build
npm run build

# Run in stdio mode (for Claude Desktop)
npm start -- --stdio

# Run in HTTP mode (for development)
npm start -- --http --port 3000

Project Structure

agent-governance-python/agent-os/extensions/mcp-server/
โ”œโ”€โ”€ src/
โ”‚   โ”œโ”€โ”€ index.ts              # Main entry point
โ”‚   โ”œโ”€โ”€ cli.ts                # CLI with --stdio/--http modes
โ”‚   โ”œโ”€โ”€ server.ts             # MCP server implementation
โ”‚   โ”œโ”€โ”€ tools/                # 10 MCP tools
โ”‚   โ”‚   โ”œโ”€โ”€ create-agent.ts
โ”‚   โ”‚   โ”œโ”€โ”€ attach-policy.ts
โ”‚   โ”‚   โ”œโ”€โ”€ test-agent.ts
โ”‚   โ”‚   โ”œโ”€โ”€ deploy-agent.ts
โ”‚   โ”‚   โ”œโ”€โ”€ get-agent-status.ts
โ”‚   โ”‚   โ”œโ”€โ”€ list-templates.ts
โ”‚   โ”‚   โ”œโ”€โ”€ request-approval.ts
โ”‚   โ”‚   โ”œโ”€โ”€ audit-log.ts
โ”‚   โ”‚   โ”œโ”€โ”€ create-policy.ts
โ”‚   โ”‚   โ””โ”€โ”€ check-compliance.ts
โ”‚   โ”œโ”€โ”€ services/             # Core business logic
โ”‚   โ”‚   โ”œโ”€โ”€ agent-manager.ts
โ”‚   โ”‚   โ”œโ”€โ”€ policy-engine.ts
โ”‚   โ”‚   โ”œโ”€โ”€ approval-workflow.ts
โ”‚   โ”‚   โ”œโ”€โ”€ audit-logger.ts
โ”‚   โ”‚   โ””โ”€โ”€ template-library.ts
โ”‚   โ”œโ”€โ”€ prompts/              # MCP prompts
โ”‚   โ””โ”€โ”€ types/                # TypeScript definitions
โ”œโ”€โ”€ package.json
โ”œโ”€โ”€ tsconfig.json
โ””โ”€โ”€ README.md

Running Tests

npm test
npm run test:coverage

๐Ÿ“Š Performance

MetricTarget
MCP server startup<2 seconds
Tool response time<500ms (p95)
Memory footprint<100MB
Policy evaluation<50ms

๐Ÿ“œ License

MIT License - see LICENSE.


Build safe AI agents with AgentOS

GitHub ยท Documentation ยท Report Issue

Made with ๐Ÿ›ก๏ธ by the Agent OS team