protect-mcp-setup
Cedar policy enforcement and Ed25519 signed receipts gating every Claude Code tool call.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for protect-mcp-setup, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill that configures cryptographic governance for Claude Code tool calls. Every Bash/Edit/Write/WebFetch invocation is evaluated against an AWS Cedar policy before execution and produces an Ed25519-signed, hash-chained receipt verifiable offline. It runs bundled scripts to install runtime hooks and set up policy files — a security-critical skill that itself governs agent tool execution.
Key features and capabilities
- Cedar policy-gated tool execution
- Ed25519 signed, hash-chained receipts
- Offline-verifiable audit trail
Use cases
- Compliance-ready agent audit trails
- Policy-gating dangerous tool calls