2.9 KiB
Product Design: The MCP Constraint Builder (Standalone)
This document outlines the product design and system architecture for a standalone security product: The MCP Constraint Builder. This tool acts as an auditing and policy-enforcement layer for AI agents, allowing users to visually configure execution policies and parameters for third-party MCP servers.
1. Core Concept
The MCP Constraint Builder is a security firewall and configuration manager for local AI agents. It intercepts JSON-RPC requests sent by AI clients (such as Claude, Cursor, or local coding assistants) to local MCP servers.
+------------+ JSON-RPC +------------------------+ JSON-RPC +------------------+
| AI Client | -----------------> | MCP Policy Proxy | -----------------> | Target MCP Server|
| (Claude/etc| | (Enforces rules.json) | | (Proprietary) |
+------------+ +-----------+------------+ +------------------+
|
| Reads policies
v
+------------------------+
| rules.json |
+------------------------+
2. Key Features
Visual Constraint Editor
A desktop application that allows users to import any standard MCP server configuration. The tool inspects the server's available tools (list_tools) and dynamically renders a visual configuration interface:
- Allow/Deny lists: Explicitly toggle which tools (e.g.
run_command,read_file) the agent is allowed to access. - Parameter boundaries: Set regex patterns or value ranges for arguments (e.g. "Only allow
read_fileif the path starts withC:/Users/Owner/workspace"). - Execution budget: Set rate limits (e.g. "maximum 10 tool calls per minute").
Proxy Firewall (JSON-RPC Middleware)
A lightweight background proxy runner. When the AI agent attempts to execute a tool, the proxy checks the arguments against rules.json:
- Pass: If within bounds, forwards the request directly to the target server.
- Block: If out of bounds, immediately returns an authorization error back to the AI client without executing the command.
- Escalate: If marked for manual verification, prompts the user on their host machine for real-time bypass approval.
3. Benefits
- Enterprise Compliance: Solves the data protection and code execution trust gap for running local agents.
- IP Protection: Allows creators of advanced AI agents to sell compiled/obfuscated MCP binaries while giving users full visibility and boundary control.
- Ecosystem Agnostic: Works with any standard MCP client and server protocol without requiring code changes to either.