Enterprise DNA Enterprise DNA
M MCP Servers Developer low

elang2/mcp-audit-gateway

by Various

Tamper-proof audit trail for AI Agent tool calls. Cryptographically signed, hash-chained records that prove what your agents did

MCP

elang2/mcp-audit-gateway

Added 21 Sept 2026

#ai-agent #ai-agents #ai-safety #attestation #audit-logs #in-toto #mcp #mcp-tools

Overview

A TypeScript gateway for MCP-based AI agents that logs every tool call into an append-only audit trail. Each record is cryptographically signed and hash-chained, making any post-hoc alteration detectable and providing verifiable proof of agent actions.

Best for

Best for
Teams operating MCP agents that need verifiable audit trails for compliance or security

Use cases

  • Prove what an agent did in a regulated environment
  • Detect tampering with tool-call history
  • Audit agent behavior for security investigations

How to use

Install

npx @mcp-audit-gateway/core wrap -- <your mcp server command>

Tested with

Claude Desktop, Claude Code, Cursor

Example client config

{\n  "mcpServers": {\n    "github": {\n      "command": "npx",\n      "args": ["mcp-audit", "wrap", "--", "npx", "@modelcontextprotocol/server-github"]\n    },\n    "filesystem": {\n      "command": "npx",\n      "args": ["mcp-audit", "wrap", "--", "npx", "@modelcontextprotocol/server-filesystem", "/tmp"]\n    }\n  }\n}

Notes

A TypeScript gateway for MCP-based AI agents that logs every tool call into an append-only audit trail. Each record is cryptographically signed and hash-chained, making any post-hoc alteration detectable and providing verifiable proof of agent actions.

0 stars on GitHub. Last updated 2026-09-16. Licensed MIT.

Use cases

  • Prove what an agent did in a regulated environment
  • Detect tampering with tool-call history
  • Audit agent behavior for security investigations

Pros

  • Cryptographic signatures and hash-chaining make logs tamper-evident
  • Provides verifiable history without relying on agent self-reporting
  • TypeScript implementation fits into existing MCP toolchains

Cons

  • Zero GitHub stars, so community adoption and review are unproven
  • No documented deployment steps or configuration examples provided
  • Adds a gateway layer that agents and tools must route through

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Cryptographic signatures and hash-chaining make logs tamper-evident
  • Provides verifiable history without relying on agent self-reporting
  • TypeScript implementation fits into existing MCP toolchains

Cons

  • Zero GitHub stars, so community adoption and review are unproven
  • No documented deployment steps or configuration examples provided
  • Adds a gateway layer that agents and tools must route through
Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks