{"id":51017557,"url":"https://github.com/nishant6118/Polaxis-SDK-MCP","last_synced_at":"2026-06-28T23:00:40.392Z","repository":{"id":360387937,"uuid":"1247295584","full_name":"nishant6118/Polaxis-SDK-MCP","owner":"nishant6118","description":"Python SDK and MCP server for Polaxis - AI agent governance platform. Evaluate every tool call against policies in real time: block dangerous actions, enforce budgets, route to human approvals. Under 5ms.","archived":false,"fork":false,"pushed_at":"2026-06-03T00:57:45.000Z","size":74,"stargazers_count":1,"open_issues_count":0,"forks_count":2,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-06-03T02:17:12.242Z","etag":null,"topics":["agent-governance","agent-security","agentic-ai","ai-agents","audit-log","compliance","crewai","fastapi","human-in-the-loop","langchain","llm-security","llmops","mcp","openai","prompt-injection","pydanticai","python","sdk","soc2","zero-trust"],"latest_commit_sha":null,"homepage":"https://polaxis.io","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nishant6118.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-23T06:04:11.000Z","updated_at":"2026-06-03T00:57:49.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/nishant6118/Polaxis-SDK-MCP","commit_stats":null,"previous_names":["nishant6118/polaxis-sdk-mcp"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/nishant6118/Polaxis-SDK-MCP","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nishant6118%2FPolaxis-SDK-MCP","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nishant6118%2FPolaxis-SDK-MCP/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nishant6118%2FPolaxis-SDK-MCP/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nishant6118%2FPolaxis-SDK-MCP/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nishant6118","download_url":"https://codeload.github.com/nishant6118/Polaxis-SDK-MCP/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nishant6118%2FPolaxis-SDK-MCP/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34906700,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-28T02:00:05.809Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agent-governance","agent-security","agentic-ai","ai-agents","audit-log","compliance","crewai","fastapi","human-in-the-loop","langchain","llm-security","llmops","mcp","openai","prompt-injection","pydanticai","python","sdk","soc2","zero-trust"],"created_at":"2026-06-21T13:00:20.768Z","updated_at":"2026-06-28T23:00:40.387Z","avatar_url":"https://github.com/nishant6118.png","language":"Python","funding_links":[],"categories":["[↑](#table-of-contents)Tools \u003ca name=\"tools\"\u003e\u003c/a\u003e","⚙️ Agent Operations"],"sub_categories":["Agent Tooling and MCP Security","🔒 Security \u0026 Governance"],"readme":"\u003cdiv align=\"center\"\u003e\n\n\u003cimg src=\"https://raw.githubusercontent.com/nishant6118/Polaxis/main/docs/logo/dark.svg\" alt=\"Polaxis\" width=\"180\"/\u003e\n\n\u003cbr/\u003e\u003cbr/\u003e\n\n\u003ch2\u003ePolaxis Python SDK \u0026 MCP Server\u003c/h2\u003e\n\n\u003cp\u003e\u003ci\u003eThe runtime control layer between your AI agents and the real world — intercept every tool call, enforce policies, require human approval, audit everything. Before anything executes.\u003c/i\u003e\u003c/p\u003e\n\n\u003cbr/\u003e\n\n[![PyPI](https://img.shields.io/pypi/v/polaxis?style=for-the-badge\u0026color=6366f1\u0026label=pip+install+polaxis)](https://pypi.org/project/polaxis)\n[![Python](https://img.shields.io/badge/python-3.10+-3776ab?style=for-the-badge\u0026logo=python\u0026logoColor=white)](https://pypi.org/project/polaxis)\n[![License](https://img.shields.io/badge/License-MIT-gray?style=for-the-badge)](LICENSE)\n[![Tests](https://img.shields.io/badge/tests-passing-22c55e?style=for-the-badge\u0026logo=pytest\u0026logoColor=white)](#)\n\n\u003cbr/\u003e\n\n[![Docs](https://img.shields.io/badge/docs.polaxis.io-blue?style=flat-square)](https://docs.polaxis.io)\n[![Dashboard](https://img.shields.io/badge/polaxis.io-live-6366f1?style=flat-square)](https://polaxis.io)\n[![Free Tier](https://img.shields.io/badge/free_tier-1_agent_·_10k_calls%2Fmo-22c55e?style=flat-square)](https://polaxis.io/register)\n[![Benchmark](https://img.shields.io/badge/benchmark-99.4%25_detection-22c55e?style=flat-square)](https://polaxis.io/benchmark)\n\n\u003c/div\u003e\n\n---\n\n## What is Polaxis?\n\nPolaxis is the **runtime control layer** between your AI agents and the tools they call.\n\nYou put an API gateway in front of your backend. Polaxis is that gateway for your agents — every tool call intercepted before it executes, evaluated against your policies, and either allowed, blocked, or routed for human approval.\n\n```\n  Your AI agent\n        │\n        │  tool_call(\"delete_records\", {\"table\": \"users_prod\"})\n        ▼\n┌──────────────────────────────────────────────────────────────┐\n│                   Polaxis Control Layer                       │\n│                                                              │\n│  L1  Regex scan            — 80+ patterns: injection, PII   │\n│  L2  Risk scorer           — 15 signals, sub-millisecond    │\n│  L3  LLM semantic gate     — fires on ~11% of calls only    │\n│  L4  Behavioral baseline   — detects slow drift attacks     │\n│  L5  Session graph         — recon → exfil kill-chain       │\n│  L6  Threat intel          — per-agent threat level 0–4     │\n│  L7  Policy engine         — your rules, budgets, logic     │\n│                                                              │\n│  0.15ms p50 (regex layers) · $0.00026 per call              │\n└──────────────────┬─────────────────────┬────────────────────┘\n                   │                     │\n                ALLOW              BLOCK / ESCALATE\n                   │                     │\n           Your tools run         Human approves via\n         (database, API…)         Slack or dashboard\n```\n\n### Three outcomes for every call\n\n| Decision | Meaning | What to do |\n|----------|---------|------------|\n| `approved` | Within policy. Proceed. | Execute the tool |\n| `blocked` | Violates a rule or budget cap. | Abort — reason logged |\n| `escalated` | Human sign-off required. | Wait for approval via Slack or dashboard |\n\n---\n\n## Quickstart — 3 lines\n\n```bash\npip install polaxis\n```\n\n```python\nfrom polaxis import Polaxis\n\nguard = Polaxis(api_key=\"ag_prod_...\", agent_id=\"my-agent\")\n\n# Wrap any tool call — works with any framework\nresult = await guard.evaluate(\n    tool_name=\"delete_records\",\n    tool_input={\"table\": \"users_prod\"}\n)\n# result.decision → \"approved\" | \"blocked\" | \"escalated\"\n# result.reason   → \"rule: no-prod-delete · 0.15ms\"\n```\n\nThat's it. Works with LangChain, LangGraph, CrewAI, OpenAI Agents SDK, PydanticAI, AutoGen, or any custom agent — anything that calls a tool.\n\n---\n\n## MCP Proxy — zero code\n\nFor Claude Desktop, Cursor, or any MCP client: set three env vars and point your client at the proxy. No code changes.\n\n```bash\nexport POLAXIS_API_KEY=ag_prod_...\nexport POLAXIS_AGENT_ID=claude-desktop\nexport TARGET_MCP_SERVER_URL=http://localhost:8080\n\n# Start the proxy\npython -m polaxis.mcp_proxy\n```\n\nEvery MCP tool call now goes through Polaxis before it reaches your server.\n\n---\n\n## What it protects against\n\n| Threat | What it catches |\n|--------|-----------------|\n| **Prompt injection** | Direct, indirect (RAG/email), encoded (Base64, Unicode, NATO phonetic), multilingual |\n| **Credential leakage** | 25+ vendor key formats + high-entropy detection |\n| **PII exfiltration** | SSN, passport, credit card, phone, email — 10+ languages |\n| **Memory poisoning** | MINJA-style latent trigger attacks on vector stores |\n| **Authority claims** | Admin impersonation, sudo escalation, fake system overrides |\n| **Policy Puppetry** | XML/INI/JSON structured prompts claiming to disable security |\n| **Economic DoS** | Token amplification attacks — hard session cap enforced |\n\n---\n\n## Detection accuracy\n\n\u003e Measured on **459 real-world adversarial payloads** — hard tier includes Base64, ROT13, Unicode homoglyphs, zero-width chars, 10+ languages, MINJA memory poisoning, EchoLeak indirect injection.\n\n| Threat Category | Detection Rate |\n|---|:---:|\n| Prompt Injection | **99.0%** |\n| Credential / Secret | **100.0%** |\n| PII Detection | **97.8%** |\n| Memory Poisoning | **96.7%** |\n| Authority Claims | **100.0%** |\n| LLM false positive rate | **4.0%** |\n| Regex false positive rate | **0.0%** |\n\n**99.4% average detection across all threat categories.**\n\n→ [Full benchmark methodology](https://polaxis.io/benchmark)\n\n---\n\n## Performance\n\n| Layer | p50 latency | Notes |\n|-------|-------------|-------|\n| Regex + risk scorer | **0.15ms** | Pure Python, no I/O |\n| Full 7-layer (no LLM) | **~0.5ms** | 89% of calls |\n| With LLM semantic gate | **80–200ms** | ~11% of calls |\n| Cost per call | **$0.00026** | LLM layer only when needed |\n\n---\n\n## Framework examples\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eLangChain\u003c/b\u003e\u003c/summary\u003e\n\n```python\nfrom langchain.tools import tool\nfrom polaxis import Polaxis\n\nguard = Polaxis(api_key=\"ag_prod_...\", agent_id=\"langchain-agent\")\n\n@tool\nasync def delete_records(table: str) -\u003e str:\n    \"\"\"Delete records from a table.\"\"\"\n    result = await guard.evaluate(\n        tool_name=\"delete_records\",\n        tool_input={\"table\": table}\n    )\n    if result.decision == \"blocked\":\n        return f\"Blocked: {result.reason}\"\n    # proceed with deletion\n    return f\"Deleted records from {table}\"\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eOpenAI Agents SDK\u003c/b\u003e\u003c/summary\u003e\n\n```python\nfrom agents import Agent, function_tool\nfrom polaxis import Polaxis\n\nguard = Polaxis(api_key=\"ag_prod_...\", agent_id=\"openai-agent\")\n\n@function_tool\nasync def send_email(to: str, body: str) -\u003e str:\n    result = await guard.evaluate(\n        tool_name=\"send_email\",\n        tool_input={\"to\": to, \"body\": body}\n    )\n    if result.decision != \"approved\":\n        return f\"Action {result.decision}: {result.reason}\"\n    # send email\n```\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eCrewAI\u003c/b\u003e\u003c/summary\u003e\n\n```python\nfrom crewai_tools import BaseTool\nfrom polaxis import Polaxis\n\nguard = Polaxis(api_key=\"ag_prod_...\", agent_id=\"crewai-agent\")\n\nclass SafeDatabaseTool(BaseTool):\n    async def _run(self, query: str) -\u003e str:\n        result = await guard.evaluate(\n            tool_name=\"run_query\",\n            tool_input={\"query\": query}\n        )\n        if result.decision == \"blocked\":\n            return f\"Blocked by Polaxis: {result.reason}\"\n        # execute query\n```\n\u003c/details\u003e\n\n---\n\n## Policy rules\n\nDefine policies in the dashboard or via JSON:\n\n```json\n[\n  {\n    \"rule\": \"no-prod-delete\",\n    \"tool\": \"delete_records\",\n    \"condition\": \"table LIKE '%prod%'\",\n    \"action\": \"block\"\n  },\n  {\n    \"rule\": \"large-charge-approval\",\n    \"tool\": \"charge_card\",\n    \"condition\": \"amount \u003e 500\",\n    \"action\": \"escalate\",\n    \"notify\": \"#finance-alerts\"\n  },\n  {\n    \"rule\": \"daily-budget\",\n    \"agent\": \"*\",\n    \"budget_usd\": 50,\n    \"period\": \"day\",\n    \"action\": \"block\"\n  }\n]\n```\n\n---\n\n## Links\n\n| | |\n|---|---|\n| **Dashboard** | [polaxis.io](https://polaxis.io) |\n| **Docs** | [docs.polaxis.io](https://docs.polaxis.io) |\n| **Interactive demo** | [polaxis.io/demo](https://polaxis.io/demo) |\n| **Benchmark** | [polaxis.io/benchmark](https://polaxis.io/benchmark) |\n| **Free tier** | 1 agent · 10,000 calls/month · no card required |\n| **PyPI** | `pip install polaxis` |\n\n---\n\n## License\n\nMIT — free to use, modify, and distribute.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnishant6118%2FPolaxis-SDK-MCP","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnishant6118%2FPolaxis-SDK-MCP","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnishant6118%2FPolaxis-SDK-MCP/lists"}