ZT MCP Project

security MCP Server

Reference implementation of ZT-MCP: a zero-trust security architecture for MCP-connected AI agents. Includes TIV, APE, DCOF, PAL enforcement components with formal CapBAC access control model.

Verified
securitysecurity
4 views0 stars0 forksMIT

Why This Matters

Discovered via github-topic:model-context-protocol and last synced 3mo ago.

Verified
Source
github-topic:model-context-protocol
Stars
0
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
17
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (17)

ACP

% of allow/deny decisions matching ground truth policy

PAL

Every interaction logged; anomaly detection on access patterns

PEL

Latency from invocation request to ZT-MCP decision (ms)

Mode

Behavior

Micro-Segmentation

Deployment Modes

strict

All invocations require capability token + full APE approval. No exceptions.

Component

Description

audit-only

Logs all interactions without blocking. Violations flagged for review.

TIV

Cryptographic certificate verification at every invocation

System

ACP (%)

APE

Capability tokens scoped to minimum required action

Metric

Definition

HITL-AP

ZT-MCP

ABR

% of adversarial interactions blocked before execution

TAC

% of MCP interactions captured in PAL audit log

DCOF

All tool outputs treated as adversarial; classified before agent use

FPR

% of legitimate invocations incorrectly denied