data-ai MCP Server
AI agent security and governance platform for the full lifecycle. Scan before you ship. Govern and block at runtime. No Azure required.
Discovered via agent-topic:crewai and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
What Drako shows you
Rules
P50
Specific Rules
Requirement
FW-008 → FW-009 (auto-imported plugins, no cost guard)
General rules
strict agents: researcher: source: agents/researcher.py tools: web_search: type: read code_runner: type: execute # ⚠ flagged CRITICAL by scan policies: odd: researcher: permitted_tools: [web_search, file_reader] forbidden_tools: [code_runner] dlp: mode: enforce circuit_breaker: failure_threshold: 5 hitl: triggers: tool_types: [write, execute, payment] spend_above_usd: 100.00 ``` **Autopilot** reads your scan, generates the config, starts in audit mode. When ready: `drako upgrade --balanced` enables enforcement. Industry templates: `drako init --template fintech` · `healthcare` · `eu-ai-act` · `startup` · `enterprise` 📄 [Full config reference →](docs/config.md) · [Policy templates →](docs/policy-templates.md) --- ## Runtime Enforcement One line to protect agents in production: ```python from drako import govern crew = govern(crew) # every tool call passes through enforcement ``` Every tool call goes through a 13-stage pipeline before executing. If a tool is forbidden, carries PII, exceeds spend caps, matches a known threat, or needs human approval — blocked before it runs. ### Key capabilities - 🔒 **DLP** — Presidio-based PII/PCI scanning. Critical PII blocked before reaching downstream APIs. - 👤 **Human-in-the-Loop** — Agent pauses on high-risk actions, escalates to human. Configurable triggers. EU AI Act Art. 14. - ⚡ **Circuit Breaker** — Per-agent AND per-tool. One failing tool doesn't kill the whole agent. - 📋 **Audit Trail** — SHA-256 hash chain with Ed25519 signatures. Tamper-evident, exportable, regulator-ready. - 🌐 **Collective Intelligence** — Anonymous IOC sharing across deployments. One detection protects everyone. Sub-5s propagation. 📄 [Full runtime docs →](docs/runtime-capabilities.md) — covers all 20 capabilities including Trust Score, Intent Fingerprinting, ODD Enforcement, Magnitude Limits, FinOps, Secure A2A, Topology Monitoring, Chaos Engineering, Observability, Alerting, and OTEL/SIEM Export. --- ## Out-of-process proxy Zero code changes. The agent can't bypass what doesn't run in its process. ```bash drako proxy start export OPENAI_BASE_URL=http://localhost:8990/openai/v1 ``` 📄 [Proxy docs →](docs/proxy-mode.md) · [Docker + Helm →](deploy/) --- ## Autopilot Mode Zero-config governance. One command, smart defaults from your scan. ```bash drako init # autopilot (default) — audit-first drako init --balanced # enforcement active with escape hatches drako init --strict # maximum governance for enterprise drako init --manual # full YAML with all sections drako init --template fintech # start from industry template ``` Autopilot analyzes your project and generates a `.drako.yaml` pre-configured with: - **ODD**: Each agent locked to its discovered tools - **DLP**: Audit mode (logging PII, not blocking yet) - **Circuit Breaker**: Threshold 5 failures / 60s window - **HITL**: Active for write/execute tools (auto-allow on timeout) - **FinOps**: Cost tracking enabled Everything starts in audit mode. When you're ready for enforcement: ```bash drako upgrade --balanced # DLP enforce, ODD enforce, HITL reject on timeout drako upgrade --strict # + intent verification, cryptographic audit, magnitude enforce ``` --- ## CI/CD ### GitHub Action The [Drako GitHub Action](.github/actions/drako-scan/) posts inline PR comments on the exact lines where issues are found, uploads SARIF to Code Scanning, and gates merges on governance score. ```yaml # .github/workflows/drako.yml name: Drako Governance on: [push, pull_request] jobs: scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-python@v5 with: { python-version: "3.12" } - run: pip install drako - run: drako scan . --format sarif > results.sarif - run: drako scan . --fail-on critical --threshold 70 - uses: github/codeql-action/upload-sarif@v3 with: { sarif_file: results.sarif } if: always() ``` ### Pre-commit hook ```yaml # .pre-commit-config.yaml - repo: https://github.com/DrakoLabs/Drako hooks: - id: drako-scan ``` --- ## Supported Frameworks
LangChain.js, Vercel AI SDK, Mastra, AutoGen.js (`pip install drako[typescript]`)
Cryptographic audit trail with policy snapshot references
Focus
Implementing Microsoft Defender for Cloud to enable cloud security posture management, workload protection across VMs, containers, databases, and storage, configure security recommendations, and set up adaptive security controls with automated remediation.
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
Detecting misconfigured Azure Storage accounts including publicly accessible blob containers, missing encryption settings, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.
为独立开发者准备的精选技术栈和工具仓库来了!这里有你最需要的工具,帮你提升开发效率、节约成本,最重要的是——这些工具都是市场上热门的,经过验证的。🚀A curated collection of tech stacks and tools tailored for independent developers is here! these are proven, popular tools widely used in the industry. 🚀
Labs to explore AI Models, MCP servers, and Agents with the AI Gateway powered by Azure API Management and Microsoft Foundry 🚀
Learn Cloud Applied Generative AI Engineering (GenEng) using OpenAI, Gemini, Streamlit, Containers, Serverless, Postgres, LangChain, Pinecone, and Next.js
This repo helps you to build a team of AI agents with Autogen
Learn how to use the azure-cosmos-ts-v2 Claude skill. Complete guide with installation instructions and examples.
Learn how to use the azure-storage-queue-ts-v2 Claude skill. Complete guide with installation instructions and examples.
Learn how to use the azure-functions-v3 Claude skill. Complete guide with installation instructions and examples.