MCP Server

Sunaiva Gate — Agent Rule Enforcement

io.sunaivacore/gate
MCP & Agent Infrastructure Security Public & reachable MCP 2026-07-28

What this MCP does

Validates proposed agent actions against configurable enforcement rules, supports rule modes and bypass logging, and exposes audit decisions.

add_custom_rule
Create a custom detection rule in the backend. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['name', 'description', 'detection_pattern', 'severity'], 'properties': {'name': {'type': 'string', 'description': 'Rule name'}, 'tier': {'type': 'string', 'description': 'Optional tier restriction'}, 'severity': {'enum': ['block', 'warn'], 'type': 'string', 'description': 'Severity on match'}, 'description': {'type': 'string', 'description': 'Rule description (required — the backend 400s on a missing/empty description)'}, 'detection_pattern': {'type': 'string', 'description': "Compiled regex detection pattern (required — the backend 400s on a missing/empty detection_pattern). There is no 'pattern' field: 'detection_pattern' is the only field name the evaluator reads; the backend explicitly rejects 'pattern'."}}}
apply_preset
Apply a preset bundle, activating all its included rules. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['preset_id'], 'properties': {'preset_id': {'type': 'string', 'description': 'ID of the preset to apply'}}}
audit_verify
[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Forward-linked hash-chain / ed25519 audit-log verification is not yet built in this backend.
Input schema
{'type': 'object', 'properties': {}}
delete_custom_rule
Delete a custom rule. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Rule ID to delete'}}}
get_audit_log
View recent gate decisions — blocks, warnings, passes, and bypasses.
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'number', 'description': 'Max entries to return (default 50)'}, 'rule_id': {'type': 'string', 'description': 'Accepted for forward-compatibility but NOT applied server-side — the backend only honors limit/cursor. Filter the returned entries client-side.'}}}
get_rule_modes
List all enforcement-mode overrides configured for the authenticated customer. Requires an account (Dev+).
Input schema
{'type': 'object', 'properties': {}}
get_rules
List active validation rules — the customer's TRUE enforced set (constitutional + recommended-default metadata on dev tier, all 69 premium rules on pro+). `category`/`preset` filter args are accepted but not applied server-side.
Input schema
{'type': 'object', 'properties': {'preset': {'type': 'string', 'description': 'Filter by preset name'}, 'category': {'type': 'string', 'description': 'Filter by category'}}}
list_custom_rules
List all custom rules for the authenticated customer. Requires API key (Pro+).
Input schema
{'type': 'object', 'properties': {}}
list_presets
List available rule preset bundles. Requires API key (Dev+).
Input schema
{'type': 'object', 'properties': {}}
log_bypass
Record an intentional rule bypass with justification. Cannot bypass constitutional rules.
Input schema
{'type': 'object', 'required': ['rule_id', 'reason'], 'properties': {'reason': {'type': 'string', 'description': 'Justification for the bypass'}, 'rule_id': {'type': 'string', 'description': 'ID of the rule to bypass'}}}
reset_rule_mode
Remove a mode override for a rule, reverting it to its default enforcement mode. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['rule_id'], 'properties': {'rule_id': {'type': 'string', 'description': 'Rule ID whose override to remove'}}}
set_rule_mode
Set enforcement mode (shadow/advisory/enforce) for a specific rule. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['rule_id', 'mode'], 'properties': {'mode': {'enum': ['shadow', 'advisory', 'enforce'], 'type': 'string', 'description': 'Enforcement mode'}, 'rule_id': {'type': 'string', 'description': 'Rule ID to configure'}, 'agent_id': {'type': 'string', 'description': 'Optional: scope override to a specific agent ID'}}}
ship_confidence_check
[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Ship Confidence Gate (Rule 42) dual-tier authorization is not yet built in this backend.
Input schema
{'type': 'object', 'required': ['artifact_id'], 'properties': {'label': {'type': 'string', 'description': 'Human-readable label of the publish action (optional)'}, 'artifact_id': {'type': 'string', 'description': "The artifact being shipped (e.g. '@sunaiva/gate@1.1.0')"}, 'command_preview': {'type': 'string', 'description': 'First 300 chars of the command that triggered the check (optional)'}}}
update_custom_rule
Update an existing custom rule. Requires API key (Pro+).
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Rule ID to update'}, 'name': {'type': 'string'}, 'tier': {'type': 'string'}, 'severity': {'enum': ['block', 'warn'], 'type': 'string'}, 'description': {'type': 'string'}, 'detection_pattern': {'type': 'string', 'description': "There is no 'pattern' field — 'detection_pattern' is the only field name the evaluator reads; the backend explicitly rejects 'pattern'."}}}
update_rules
[Planned — not yet implemented on the remote endpoint, returns NOT_IMPLEMENTED] Enable/disable is not backed by any route in this API; use set_rule_mode (shadow/advisory/enforce) instead, or the local `npx @sunaiva/gate` package.
Input schema
{'type': 'object', 'properties': {'enable': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rule IDs to enable'}, 'disable': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rule IDs to disable'}}}
validate_action
Check if a proposed action passes all active validation rules. Returns allowed/blocked with rule violations.
Input schema
{'type': 'object', 'required': ['action'], 'properties': {'action': {'type': 'string', 'description': 'The action to validate'}, 'context': {'type': 'string', 'description': 'Optional additional context, appended to `action` before rule matching — it can change which rules match and therefore the verdict.'}}}
Added
apply_preset
Sept. 17, 2026, 12:53 p.m.
Added
list_presets
Sept. 17, 2026, 12:53 p.m.
Added
list_custom_rules
Sept. 17, 2026, 12:53 p.m.
Added
delete_custom_rule
Sept. 17, 2026, 12:53 p.m.
Added
update_custom_rule
Sept. 17, 2026, 12:53 p.m.
Added
add_custom_rule
Sept. 17, 2026, 12:53 p.m.
Added
reset_rule_mode
Sept. 17, 2026, 12:53 p.m.
Added
get_rule_modes
Sept. 17, 2026, 12:53 p.m.
Added
set_rule_mode
Sept. 17, 2026, 12:53 p.m.
Added
audit_verify
Sept. 17, 2026, 12:53 p.m.
Added
ship_confidence_check
Sept. 17, 2026, 12:53 p.m.
Added
get_audit_log
Sept. 17, 2026, 12:53 p.m.
Added
update_rules
Sept. 17, 2026, 12:53 p.m.
Added
get_rules
Sept. 17, 2026, 12:53 p.m.
Added
log_bypass
Sept. 17, 2026, 12:53 p.m.
Added
validate_action
Sept. 17, 2026, 12:53 p.m.