惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog
Y
Y Combinator Blog
N
Netflix TechBlog - Medium
M
MIT News - Artificial intelligence
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
Check Point Blog
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Proofpoint News Feed
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
GbyAI
GbyAI
博客园_首页
A
About on SuperTechFans
Blog — PlanetScale
Blog — PlanetScale
人人都是产品经理
人人都是产品经理
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
T
The Blog of Author Tim Ferriss
The Cloudflare Blog

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店
GitHub - marvior/regentix: Regentix is an MCP proxy that ...
wmolino · 2026-06-18 · via Hacker News: Show HN

Policy-driven MCP proxy for secure LLM tool execution using Rego-based governance with local AI-generated rules

Status License Architecture


⚠️ Warning
This project is in early development and is not production-ready. It may contain bugs, incomplete features, or breaking changes. Use at your own risk.


Video Demo

regentix_demo-2.mp4

📌 Overview

Regentix is a security and governance system that sits between LLM clients (like Claude Desktop) and MCP (Model Context Protocol) servers.

It acts as a policy enforcement gateway, ensuring that every tool execution request generated by an LLM is validated against Rego-based policies (Regorus engine) before being executed.

The system combines:

  • MCP proxy enforcement (Rust)
  • AI-driven policy generation (Python)
  • Rego policy engine (Regorus)
  • Web UI for rule creation (Angular)

🧠 Core Idea

LLM-generated intent should never directly become execution.
Every action must pass through a governance layer.


🚪 Key Features

  • 🔐 Rego-based policy enforcement via Regorus
  • 🤖 AI-generated policies using fine-tuned Qwen2.5-Coder-1.5B-Instruct
  • 🧠 Synthetic dataset generation via Google Gemini
  • 🚪 MCP proxy integration with Claude Desktop
  • 🧾 Fine-grained access control (e.g. Git repository restrictions)
  • 🌐 Web dashboard for policy generation (Angular UI)
  • ⚙️ Multi-language architecture (Rust + Python + Angular)
  • 🛡️ Deny-by-default execution model

🏗️ Architecture

                    ┌──────────────────────┐
                    │   Claude Desktop     │
                    │   (MCP Client)       │
                    └─────────┬────────────┘
                              │ MCP Tool Call
                              ▼
              ┌──────────────────────────────┐
              │   Regentix MCP Proxy (Rust)  │
              │   - STDIO MCP Server         │
              │   - Enforcement layer        │
              └─────────┬────────────────────┘
                        │
                        │ Policy evaluation
                        ▼
        ┌──────────────────────────────────────┐
        │   Regorus Policy Engine (Rego)       │
        │   - Allow / Deny decisions           │
        └─────────┬────────────────────────────┘
                  │
        ┌─────────┴─────────┐
        │                   │
        │ ALLOW             │ DENY
        ▼                   ▼
┌────────────────┐   ┌────────────────────┐
│ MCP Servers    │   │ Blocked Execution  │
│ (Git, FS, etc) │   │ Request rejected   │
└────────────────┘   └────────────────────┘


        ┌──────────────────────────────────────┐
        │ Python AI Backend                    │
        │ - Fine-tuned Qwen2.5-Coder           │
        │ - Generates Rego policies            │
        │ - Uses Gemini synthetic dataset      │
        └─────────┬────────────────────────────┘
                  │
                  │ policy generation API
                  ▼
        ┌──────────────────────────────────────┐
        │ Angular Web Dashboard                │
        │ - UI for policy creation             │
        │ - Sends requests to backend          │
        └──────────────────────────────────────┘

🔄 Request Flow

  1. Claude Desktop sends MCP tool request
  2. Rust MCP Proxy intercepts request
  3. Regorus evaluates Rego policies
  4. Decision:
    • Allow → forward to MCP server
    • Deny → block execution
  5. Python backend generates policies via AI
  6. Angular UI manages rule creation


🧠 AI Policy Generation

  • Base model: Qwen2.5-Coder-1.5B-Instruct
  • Dataset: synthetic data generated via Google Gemini
  • Output: Rego policies compatible with Regorus

Capabilities:

  • Natural language → policy generation
  • Policy refinement
  • Rule validation

🚫 Example Use Cases

  • Block GitHub repository access via MCP Git server
  • Restrict filesystem operations
  • Prevent destructive tool actions
  • Role-based execution control

🛠️ Tech Stack

Layer Technology
MCP Proxy Rust
Policy Engine Regorus
Backend Python
Frontend Angular
Model Qwen2.5-Coder
Dataset Gemini

🚀 Getting Started

Rust Compiling

Alternative compiling: ./deploy_build_rust.sh ./deploy_release_rust.sh

chmod +x deploy_build_rust.sh deploy_release_rust.sh


Python Backend

cd model_ai/ python -m venv venv source venv/bin/activate pip install -r requirements.txt

Fine tuning model

for the fune tuning I've used the M4 Air

cd model_ai/rego-finetuning ./start.sh

Start Python Backend

cd model_ai/ python start_server.py


Frontend

cd regentix_frontend npm install npm start

Open: http://localhost:4200/


🔌 Claude Desktop Config

{ { "mcpServers": { "regentix": { "command": "", "args": [] } }

🔌 Config.json

In this file add the mcp server for example: [

{
"server_name":"filesystem",
"command":"npx",
"args": ["-y", "@modelcontextprotocol/server-filesystem", ""],
"env":{}
},
{
"server_name": "commands",
"command": "npx",
"args": ["-y", "mcp-server-fetch-typescript"],
"env": {}
},
{
"server_name": "github",
"command": "npx",
"args": [
  "-y",
    "@modelcontextprotocol/server-github"],
"env": {}
}

]


🔐 Security Model

  • Deny-by-default execution
  • All MCP calls intercepted
  • Rego policy validation required
  • Explicit allow only

🧪 AI-Assisted Development

This project was built with extensive assistance from generative AI models. Used for:

  • code generation
  • architecture design
  • Rust learning

🧠 Philosophy

LLM intent ≠ execution
All actions must be governed


📌 Future Work

  • Improved Rego rule synthesis
  • HTTP transport support (not only STDIN MCP)
  • LLM-agnostic integration layer

🤝 Acknowledgements

OPA / Regorus / Qwen / Gemini / Claude MCP / Rust / Python / Angular