From Law to Action: Neuro-Symbolic Runtime Enforcement for MCP Agents
Abstract
We describe a corpus-grounded neuro-symbolic implementation for constraining Model Context Protocol (MCP) agents before protected tool execution. The method starts from three different sources: multi-jurisdictional legal documents, CVE-linked vulnerability and repair records, and SkillCenter Markdown procedures. Source-preserving adapters produce Legal IR, Security IR, and Intent IR; these share content identity and provenance but retain distinct meanings and authority. Family-specific compilers expose first-order, frame, temporal-deontic, cognitive-event, and solver-oriented views. An authorization service selects applicable constraints, constructs per-action proof obligations, and returns a context-bound decision. A separate enforcement adapter validates the live invocation and consumes a permitted use before delegation. DuckDB and a typed Quack owner maintain operational state; IPFS identifies and distributes immutable evidence; libp2p carries peer traffic; and UCAN limits delegated capabilities. We document these implemented roles, the source-to-IR transformations, the separation of learned proposals from checked decisions, and the tests needed to establish guarded-path safety. Corpus release statistics and inspected regression assertions are reported separately from end-to-end evaluation, which remains to be completed. code and artifacts are available on github.