MCP service governance method and device based on intelligent agent

By using a large-scale intelligent model to perform TLA+ modeling and context parsing of MCP services, and automatically generating structured labels, the problem of AI tool platforms in existing technologies being unable to verify complex security attributes is solved, thus achieving efficient and accurate governance of MCP services.

CN122020641APending Publication Date: 2026-05-12HANGZHOU EASTCOM SOFTWARE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU EASTCOM SOFTWARE TECH
Filing Date
2025-12-19
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

When integrating with external MCP services, existing AI tool platforms struggle to systematically verify complex security attributes, such as unauthorized access and sensitive data leakage. Furthermore, relying on manual labeling or simple keyword matching makes it difficult to identify high-level semantic tags, and insufficient initial data for model training leads to high costs for automated governance.

Method used

The MCP service governance method based on large model agents is adopted. Through action-sequence logic TLA+ modeling and contextual semantic parsing, the compliance of service behavior is automatically verified and structured classification labels are automatically generated. The LoRA parameter fine-tuning technology is combined to improve the model's understanding ability.

Benefits of technology

It achieves a seamless transition from formal compliance to refined governance, enhances the security and compliance of MCP services, provides high-fidelity, high-confidence semantic context, reduces the cost of manual iteration, and improves the accuracy and efficiency of automated governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122020641A_ABST
    Figure CN122020641A_ABST
Patent Text Reader

Abstract

The invention provides an agent-based MCP service governance method. In the method, firstly, model context protocol (MCP) service data is received; secondly, action sequential logic TLA + modeling is carried out on the first MCP service data through a large model agent, compliant first MCP service data are obtained according to a TLA + modeling result, the large model agent comprises a fine-tuned large model, and the fine-tuned large model is based on a mapping relation between a path corresponding to second MCP service data and a classification label; and carrying out fine tuning on the large model. And finally, performing context semantic analysis on the first MCP service data based on the large model agent, and extracting a classification label corresponding to the compliant first MCP service data so as to perform hierarchical and classified treatment on the compliant first MCP service data. According to the method, the problems that a traditional MCP service treatment method is easy to miss judgment of semantic violation and is difficult to cover the security attribute of the MCP service under complex state transition are solved, and the accuracy of label classification is improved through compliance verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence (AI) technology, and in particular to an MCP service governance method and apparatus based on intelligent agents. Background Technology

[0002] Currently, mainstream AI tool platforms (such as LangChain and LlamaIndex) and applications typically rely on manual review or rule-based static checks for security compliance management and scheduling when integrating external MCP services. For example, they use regular expressions to match sensitive fields, perform basic parameter validation based on OpenAPI Schema, or insert middleware or manual intervention at runtime to intercept high-risk operations. However, these methods have significant limitations. For instance, they cannot systematically verify complex security attributes such as "unauthorized access" or "sensitive data leakage"; service classification often relies on manual labeling or simple keyword matching, making it difficult to automatically identify higher-level semantic tags such as data themes and compliance criteria; and during model training, the initial data volume is usually insufficient, making it difficult for the model to learn complete knowledge, and manual model iteration is costly. Summary of the Invention

[0003] This application provides an agent-based MCP service governance method and apparatus, which solves the above-mentioned technical problems.

[0004] Firstly, an agent-based MCP service governance method is provided. In this method, firstly, firstly, firstly, firstly, firstly, firstly, firstly, firstly, firstly, firstly, firstly, firstly, secondly, through a large-scale intelligent agent, firstly, secondly, secondly, secondly, thirdly, secondly, thirdly, secondly, thirdly, thirdly, thirdly, thirdly, thirdly, thirdly, thirdly, thirdly, action-timing logic (TLA) is performed on the firstly, firstly, firstly, secondly, third ... fourthly, thirdly, third + Modeling, based on TLA + The modeling results yielded compliant first MCP service data, where the large model agent includes a fine-tuned large model. This fine-tuned large model was obtained by adjusting the large model based on the mapping relationship between the paths and classification labels corresponding to the second MCP service data. Then, based on the large model agent, contextual semantic parsing was performed on the compliant first MCP service data to extract the corresponding classification labels, enabling hierarchical classification and governance of the compliant first MCP service data.

[0005] In one possible implementation, the above-mentioned action-time logic (TLA+) modeling of the first MCP service data using a large model agent includes: abstracting the state of the first MCP service data using the large model agent to obtain the state machine and indeterminate forms corresponding to the first MCP service data; understanding the governance baseline of the natural language of the first MCP service data and generating valid initial values; writing Next clauses for the application programming interface (API) of the first MCP service data; and transforming the security policies and compliance requirements in the natural language of the first MCP service data into TLA⁺ logical expressions.

[0006] In one possible implementation, the above-mentioned large model intelligent agent performs action timing logic (TLA) on the first MCP service data. + After modeling, it also includes: according to TLA + The modeling results yielded non-compliant first MCP service data. A large model agent was then used to map the abstract state sequence corresponding to this non-compliant first MCP service data into natural language.

[0007] In one possible implementation, after the above-mentioned use of a large model agent to perform contextual semantic parsing on the first MCP service data and extract the classification labels corresponding to the compliant first MCP service data, it also includes: correcting the classification labels corresponding to the compliant first MCP service data. Through the large model agent, the mapping logic between the path corresponding to the compliant first MCP service data and the corrected classification labels is learned.

[0008] In one possible implementation, after the above-mentioned large model agent performs contextual semantic parsing on the first MCP service data and extracts the classification label corresponding to the compliant first MCP service data, it also includes: mapping the compliant first MCP service data into an MCP service description vector.

[0009] In one possible implementation, after mapping the compliant first MCP service data to an MCP service description vector, the process includes: using a tool invocation agent to determine multiple MCP services corresponding to the invocation request based on the invocation request and the MCP service description vector; and using an intent prediction agent to perform semantic alignment and intent parsing on the invocation request and the MCP service description vector to determine the MCP service most relevant to the invocation request.

[0010] In one possible implementation, after determining the MCP service most relevant to the call request, the method further includes: recommending other similar MCP services based on semantic alignment and intent parsing results and the most relevant MCP service through an intent prediction agent.

[0011] Secondly, a fine-tuning method for a large model is provided. This method first obtains the path and category label corresponding to the second MCP service data. Then, based on the mapping relationship between the path and category label of the second MCP service data, the large model understands the semantics of the API interface of the second MCP service data and generates compliant category labels corresponding to the second MCP service data.

[0012] In one possible implementation, the above-mentioned mapping relationship between paths and labels, which enables the large model to understand the semantics of the second MCP service data interface and generate compliant classification labels corresponding to the second MCP service data, is achieved by fine-tuning the large model using LoRA parameter fine-tuning technology based on the paths and classification labels corresponding to the second MCP service data.

[0013] Thirdly, an agent-based MCP service governance device is provided. This device includes a parsing module, a modeling module, and an extraction module. The parsing module receives first Model Context Protocol (MCP) service data. The modeling module performs Action Timing Logic (TLA) on the first MCP service data using a large model agent. + Modeling, based on TLA + The modeling results yield compliant first MCP service data. The large model agent includes a fine-tuned large model, which is obtained by adjusting the large model based on the mapping relationship between paths and classification labels corresponding to the second MCP service data. The extraction module performs contextual semantic parsing on the first MCP service data based on the large model agent to extract the classification labels corresponding to the compliant first MCP service data, enabling hierarchical classification and governance of the compliant first MCP service data.

[0014] The method provided in this application performs contextual semantic parsing on verified compliant MCP services using a large-scale model agent and automatically generates structured classification labels, achieving a seamless transition from formal compliance to refined governance. The formal verification process deeply analyzes the behavioral semantics of MCP services. When generating classification labels, the large-scale model agent can not only rely on the original path but also integrate abstract state variables and invariant semantics extracted during the verification process. Formal verification provides a high-fidelity, high-confidence semantic context for label generation, improving the accuracy of label recognition. Compliance verification provides a credible foundation for classification labels, while classification labels imbue compliant services with governance semantics. Together, they transform "static compliance" into "dynamic controllability," providing crucial support for building a trustworthy, efficient, and adaptive AI-native MCP service ecosystem. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of an MCP service governance system based on intelligent agents provided in an embodiment of this application;

[0016] Figure 2 This is a schematic diagram illustrating a specific example of the agent-based MCP service governance method provided in this application embodiment;

[0017] Figure 3 This is a schematic diagram of a method for governing MCP services based on intelligent agents, provided in an embodiment of this application.

[0018] Figure 4 This is a schematic diagram of the structure of an MCP service governance device based on intelligent agents provided in an embodiment of this application. Detailed Implementation

[0019] The solutions provided in the embodiments of this application will now be described with reference to the accompanying drawings. In the embodiments of this application, "multiple" refers to two or more objects, and "various types" refers to two or more types. Terms such as "first," "second," etc., are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.

[0020] To facilitate understanding of the solutions provided in the embodiments of this application, the technical terms that may be involved in the embodiments of this application will be introduced first.

[0021] Intelligent agent: An intelligent agent is a system or entity that can perceive its environment, make decisions, and take actions to achieve its goals.

[0022] Multi-agent systems are systems composed of multiple autonomous, interacting computational entities (i.e., "agents"). These agents interact in a shared environment through communication, cooperation, competition, or negotiation in order to accomplish a common task or pursue their individual goals.

[0023] Large Model: It is a general-purpose information processing and generation engine that learns from massive amounts of data and huge parameters through the Transformer architecture.

[0024] MCP (Model Context Protocol) service: refers to a callable external service built on the Model Context Protocol and designed for large language models.

[0025] Action Timing Logic (TLA) + A formal specification language used to describe, model, and verify the correctness of concurrent systems, distributed systems, and complex software / hardware systems.

[0026] This application provides an agent-based MCP service governance method. In this method, firstly, Model Context Protocol (MCP) service data is received. Secondly, a large model agent performs Action Timing Logic (TLA) on the first MCP service data. + Modeling, based on TLA +The modeling results yielded compliant first MCP service data. The large model agent included a fine-tuned large model, which was obtained by fine-tuning the large model based on the mapping relationship between paths and classification labels corresponding to the second MCP service data. Finally, the large model agent performed contextual semantic parsing on the first MCP service data to extract the classification labels corresponding to the compliant first MCP service data, enabling hierarchical classification and governance of the compliant first MCP service data.

[0027] This method transforms MCP service data into a TLA⁺ formal model using a large-scale model agent, automatically verifying whether service behaviors satisfy security and compliance invariants, thereby identifying and filtering non-compliant MCP services. Based on this, structured compliance tags are extracted, enabling fine-grained hierarchical classification and automated governance of MCP service data. Formal verification provides a high-fidelity, high-confidence semantic context for tag generation, improving the accuracy of tag recognition. Compliance verification provides a credible foundation for classification tags, which in turn imbue compliant services with governance semantics. Through collaborative verification using a large model and TLA⁺, a paradigm shift from passive compliance to proactive governance of MCP services is achieved, improving the security, compliance, and accuracy of AI tool platforms and applications when invoking MCP services in dynamically changing and complex scenarios. This addresses the problem that traditional MCP service governance methods, which rely solely on rule engines or regular expression matching to check the compliance of MCP calls, are prone to missing semantic violations and struggle to cover the security attributes of MCP services under complex state transitions.

[0028] Next, the multi-agent task orchestration method provided in the embodiments of this application will be introduced.

[0029] This application provides a method for fine-tuning a large model. In this method, firstly, the path and category tags corresponding to MCP service data are obtained. Secondly, based on the mapping relationship between the path and category tags corresponding to the MCP service data, the large model can understand the semantics of the API interface of the MCP service data and generate compliant category tags corresponding to the MCP service data.

[0030] Specifically, the path corresponding to an MCP service refers to a path string with a clear hierarchical organization, fixed format, and semantic segmentation. In the context of an MCP service, it specifically refers to a hierarchical identifier constructed according to a unified standard that reflects the service's functional domain and data classification.

[0031] Optionally, a dataset containing samples of MCP services can be prepared. Each sample may include the path of the service, its associated classification labels (such as security level, business labels, applicable regulations, etc.), and a description of these paths.

[0032] For example, sample examples of MCP services are shown in Table 1. In Table 1, "path" represents the path, "labels" represents the category labels, and "description" represents the description of the path.

[0033]

[0034] Table 1. Sample MCP Service

[0035] Optionally, LoRA parameter fine-tuning techniques can be used to fine-tune large models.

[0036] Specifically, LoRA technology is used to fine-tune a pre-trained large language model to adapt it to specific task requirements. The update of the weight matrix has a low-rank property (i.e., an effective update can be approximated by a low-dimensional matrix). LoRA updates the model parameters by adding a low-rank decomposition adapter to the original weights, thus achieving full parameter fine-tuning with only a small number of parameters trained.

[0037] The above "path-label" samples can be used to build a large model to gain a preliminary understanding of "path structure-label semantics".

[0038] For example, for a pre-trained weight matrix LoRA can update its constraints as follows:

[0039]

[0040] in, (Low-rank matrix B); (Low-rank matrix A); It is the rank, which can take small values ​​such as 4, 8, 16, etc.; Initialization: A is initialized with random Gaussian, and B is initialized as a zero matrix;

[0041] The forward propagation formula is:

[0042]

[0043] Where x is the input vector, that is, the input vector corresponding to the "path" sample.

[0044] In the standard Transformer's self-attention mechanism, the embedding of the input token sequence is represented as a matrix X. Then, the query, key, and value are calculated using three learnable weight matrices: Q = W_q · X, K = W_k · X, V = W_v · X.

[0045] LoRA does not directly update the weights W of the original large model, but instead adds a low-rank incremental update ΔW on top of it. The LoRA-enhanced Transformer layer is as follows: Q = W_q · X + (B_q A_q) · X, K = W_k · X + (B_k A_k) · X, V = W_v · X + (B_v A_v) · X.

[0046] Figure 1 A schematic diagram of an agent-based MCP service governance system architecture is shown. (Reference) Figure 1 The system can include a large model agent, a tool invocation agent, and an intent prediction agent. The large model agent can include a fine-tuned large model, which can be obtained by fine-tuning the large model based on the mapping relationship between the path and classification label corresponding to the second MCP service data. The large model agent can be used to receive Model Context Protocol (MCP) service data. It performs Action Timing Logic (TLA) on the MCP service data. + Modeling, based on TLA + The modeling results yield compliant MCP service data. Contextual semantic parsing is performed on this compliant MCP service data to extract corresponding classification labels, enabling hierarchical classification and governance of the compliant MCP service data. The large model agent can also be used to map compliant MCP service data to MCP service description vectors. The tool invocation agent can be used to match the MCP service corresponding to the user request based on the user request and the MCP service description vector. Alternatively, the tool invocation agent can be used to perform semantic alignment and intent parsing of the user request and MCP service description vector, predicting the MCP service corresponding to the user request based on the semantic alignment and intent parsing results. The intent prediction agent can be used to recommend other MCP services based on the user request, the corresponding MCP service, and the execution result of the corresponding MCP service.

[0047] First, its large model agent can receive MCP service data.

[0048] Specifically, the MCP service data refers to the data corresponding to newly registered MCP services in the system. This data can be provided by the MCP service provider. The MCP service data is a structured or semi-structured data set of the service's functions, interfaces, behaviors, and metadata. This MCP service data includes, but is not limited to, service identifiers and basic information, API interface definitions (request parameters, return value structure, invocation methods, etc.), data semantics and compliance metadata (such as paths, sensitive data tags, compliance basis), runtime behavior descriptions, and other optional metadata.

[0049] Secondly, its large model agent can perform action timing logic (TLA) on MCP service data. + Modeling, based on TLA + The modeling results yield compliant MCP service data.

[0050] In one implementation, a large model agent can be used to abstract the state of MCP service data, obtaining the corresponding state machine and indeterminate form. The governance baseline of the natural language in the MCP service data is understood, and valid initial values ​​are generated. Next clauses are written for the API of the first MCP service data. The security policies and compliance requirements in the natural language of the MCP service data are transformed into TLA⁺ logical expressions, thereby completing the TLA. + Modeling.

[0051] Specifically, based on the interface definition, behavior description, and governance metadata of the MCP service, the large model agent can automatically identify its core state variables (such as user permission status, data access level, service call count, etc.) and build the corresponding state machine and invariant abstract model as the basis for subsequent TLA⁺ modeling.

[0052] The large model agent can parse the governance baselines expressed in natural language in the MCP service (e.g., "the service must not hold any user-sensitive data when it starts up" and "the default permission is read-only"), and translate them into the Init predicate in TLA⁺ to ensure that all initial states meet compliance constraints.

[0053] For each API interface of the MCP service, the large model agent can analyze its input / output semantics, side effects (such as data writing, permission changes) and calling conditions, and automatically generate the corresponding Next state transition clause.

[0054] Large model agents can automatically convert security policies (such as "prohibit unencrypted transmission of biometric data") and compliance requirements (such as "GDPR Article 9: Explicit consent required for special categories of data") described in natural language in MCP service documents into invariants in TLA⁺.

[0055] Optionally, the TLC model detector can be used to automatically verify whether the state machine corresponding to the MCP service violates safety invariants.

[0056] In this implementation, a large model agent is used to perform TLA⁺ modeling on the MCP service, eliminating the need for manually writing formal specifications, thus improving the efficiency of formal verification and enabling scalable application of compliance governance to massive numbers of MCP services. Before the MCP service goes live, a TLC model detector can automatically verify whether the state machine violates security invariants, exposing logical vulnerabilities or compliance conflicts in advance. Leveraging the fine-tuned large model's ability to understand natural language, ambiguous governance requirements are mapped into verifiable logical expressions, avoiding biases from human interpretation.

[0057] In one implementation, it can be based on TLA. + The modeling results yield non-compliant MCP service data. A large model agent is then used to map the abstract state sequences corresponding to this non-compliant MCP service data into natural language.

[0058] Specifically, based on the automatically generated TLA⁺ (containing Init, Next, and the safety invariant Inv) for each MCP service, the TLC model detector can be invoked to perform a state space search. If an execution path violates a preset invariant, TLC will return a counterexample (i.e., an abstract state sequence that leads to the violation). The state transition sequence in this counterexample can be structured into a machine-readable format. This structured counterexample is then input into a large model agent (as mentioned in the large model fine-tuning section above, the large model has learned from a large number of MCP service samples). Based on its understanding of the governance rules, data semantics, and state transitions in the MCP service data, this large model agent generates clear, accurate, and actionable natural language feedback. This natural language report can be directly provided to MCP service users.

[0059] In this implementation, the counterexamples (state sequences) returned by TLC are difficult for non-professionals to understand and require interpretation by formal method experts, which is time-consuming and costly. This solution deeply integrates the counterexample output of formal verification with the semantic interpretation capabilities of a large language model, which not only solves the problem of the difficulty in implementing formal methods, but also upgrades compliance governance from passive inspection to proactive interpretation and guidance, thereby improving the security, credibility, and development efficiency of MCP services.

[0060] Based on the above TLA + In terms of modeling methods, this application provides an LLM + TLA⁺ collaborative verification framework.

[0061] This framework can abstract the static description (such as OpenAPI / YAML / JSONSchema) and dynamic behavior (such as call sequence and data flow) of newly registered MCP services into state machines and invariants in the TLA⁺ specification. Then, it automatically verifies whether preset security or compliance attributes (such as "sensitive data must not be transmitted in plaintext" and "unauthorized access is prohibited") are violated through TLC. For example, an MCP service can be modeled as a TLA⁺ module:

[0062]

[0063] In this module, Init represents the initial state, defining the set of legal initial states of the MCP service after registration or loading, ensuring that its metadata and security attributes meet the governance baseline requirements; Next describes all possible state transitions of the MCP service during operation, including behaviors such as calling, executing, returning, and exceptions; Vars represents the set of all mutable states in the model, constituting Fairness: preventing deadlock or starvation problems such as "calls never complete".

[0064] When a TLC report violates an invariant, the output is an abstract sequence of states (e.g., s0→s1→s2). The large model agent can map these states back to business semantics. For example, "In step 2, user Alice (unauthenticated) called GET / user / 123, and the service returned plaintext data containing email and phone number, violating the NoPlaintextPII invariant." Based on this, the large model agent can further propose practical remediation solutions, such as "Adding a rule to the Next step: If the currently accessed endpoint belongs to a set of endpoints involving personally identifiable information, and the user has not yet been authenticated, return a 403 error, prohibiting access, to prevent sensitive data leakage."

[0065] Next, the large model agent can perform contextual semantic parsing on compliant MCP service data, extract the corresponding classification labels for compliant MCP service data, and carry out hierarchical classification and governance of compliant MCP service data.

[0066] Specifically, after MCP service data passes formal compliance verification, the system can invoke a large model agent to perform context-aware semantic parsing of its structured description (including API paths, interface semantics, input / output schemas, and governance metadata). Based on the domain knowledge understanding capabilities of a pre-trained language model and combined with a LoRA adapter, the large model agent can automatically extract structured, regulatory-compliant classification tags (such as data sensitivity level, business theme, and applicable legal provisions) corresponding to the MCP service data. These tags, as governance metadata, are used to implement hierarchical and categorized management of compliant MCP services.

[0067] For example, to achieve automated governance of compliance tools in the MCP service, this proposal introduces a large language model with fine-tuned instructions. The formally validated tool definitions are subjected to structured semantic parsing, and key governance attributes are automatically extracted as tags.

[0068] Let the primitive definition of tool t be... Its content includes interface descriptions, input / output schemas, permission declarations, and data field metadata. The system constructs standardized prompts to guide the large model in information extraction. As a structured tag for tool t:

[0069]

[0070] Indicates text concatenation;

[0071] The pre-defined instruction template contains the following: "Please extract structured tags from the following MCP service and toolset definitions, including but not limited to: ① Business category; ② Data theme; ③ Sensitivity level (values ​​L1 / L2 / L3); ④ Applicable compliance (e.g., GDPR, CCPA, etc.). The output format must be strict JSON and must not contain any additional content."

[0072] The model output is a structured label object, for example:

[0073] {

[0074] "category": "user_profile",

[0075] "data_theme": "PII",

[0076] "sensitivity": "L3",

[0077] "compliance": ["GDPR_Art9", "CCPA_Sec1798"]

[0078] }

[0079] In this implementation, a large-scale model agent performs contextual semantic parsing on verified compliant MCP services and automatically generates structured classification labels. This system achieves a seamless transition from formal compliance to refined governance. The formal verification process deeply analyzes the behavioral semantics of MCP services. When generating classification labels, the large-scale model agent can not only rely on the original path but also integrate abstract state variables and invariant semantics extracted during the verification process. Formal verification provides a high-fidelity, high-confidence semantic context for label generation, improving the accuracy of label recognition. Compliance verification provides a credible foundation for classification labels, while classification labels endow compliant services with governance semantics. Together, they transform "static compliance" into "dynamic controllability," providing crucial support for building a credible, efficient, and adaptive AI-native MCP service ecosystem.

[0080] In one implementation, the large model agent performs contextual semantic parsing on the MCP service data, extracts the classification labels corresponding to the compliant MCP service data, and can also correct the classification labels corresponding to the compliant MCP service data. Through the large model agent, the mapping logic between the path corresponding to the compliant MCP service data and the corrected classification labels is learned.

[0081] For example, if a user corrects the labels output by the large model (e.g., the original label for tool path / user-related data / device information / lock screen password was "Security Level 3", and the user changes it to "Security Level 4" and adds "Compliance basis GB / T35273-2020 Clause 5.2"), the large model agent can be triggered to perform the following two steps: Temporary learning prompt word construction: Automatically extract the core information of the MCP service (tool ID, path, function description) and the modified label, construct "sample prompt words" according to a preset template, embed them into the real-time inference process of the large model, and enable the large model agent to temporarily learn the label mapping logic.

[0082] In one implementation, the large model agent performs contextual semantic parsing on the MCP service data, extracts the classification labels corresponding to the compliant MCP service data, and can then map the compliant MCP service data into MCP service description vectors.

[0083] Alternatively, a domain-fine-tuned text embedding model (such as bge-large-zh-v1.5) can be used to map the tool description text t in the MCP service to dense vectors:

[0084]

[0085] In the formula, t represents the tool description text in the MCP service. This represents a text embedding model.

[0086] Vectors corresponding to all MCP service tools can be stored in a vector index library (such as FAISS) to support efficient approximate nearest neighbor (ANN) retrieval.

[0087] In one implementation, after mapping compliant MCP service data to MCP service description vectors, an agent can be invoked via a tool to match multiple MCP services corresponding to the model input based on the model input and the MCP service description vectors. Alternatively, an intent-predicting agent can perform semantic alignment and intent parsing between the model input and the MCP service description vectors to determine the MCP service most relevant to the model input.

[0088] Optionally, cosine similarity can be used to match the model input and the MCP service description vector. The model input can be natural language text input by the user into the model.

[0089] The formula for cosine similarity is as follows:

[0090]

[0091] In the formula, This refers to the tool description text in the MCP service. This represents the natural language text input to the model. This represents the dense vector corresponding to the tool description text in the MCP service. This represents a dense vector corresponding to the natural language text input to the model.

[0092] For the user input u to the model, first calculate its embedding vector. Search for Top-k similarity tools in the tool vector library:

[0093]

[0094] Simultaneously, the BM25 algorithm is used for matching and filtering:

[0095] For the user-input query q and the label / description text dt of tool t, its BM25 score is:

[0096]

[0097]

[0098] In the formula, The word w in document d t (i.e., word frequency in the label or description of tool t); Document d represents document d t Length (in words); represents the average length of all tool documents; k1 represents the saturation rate of word frequency control, preferably 1.5; b represents the strength of document length normalization control, preferably 0.75; N represents the total number of tools; n(w) represents the number of tools containing word w.

[0099] The similarity score for hybrid recall is:

[0100]

[0101] In the formula, This represents the weighting coefficient for semantic recall.

[0102] The toolset for hybrid recall is as follows:

[0103]

[0104] Where the threshold =0.65. If If the maximum value is less than 0.65, it is considered an invalid instruction and execution is refused.

[0105] The intention is to anticipate that the intelligent agent is also responsible for receiving the user's original input u and the set of N candidate MCP service tools recalled by the system. It then performs deep semantic alignment and intent parsing to predict the optimal MCP service tool. The prediction formula is as follows:

[0106]

[0107] In the formula, "You are a tool scheduler for an MCP service. User request: 'u' Candidate tool: " Please select the single best matching tool and generate the JSON call parameters. θ* represents the selected optimal MCP service tool; θ* represents the call parameters (JSON object) conforming to the t* interface specification.

[0108] In one implementation, an intent-predicting agent can also recommend other similar MCP services based on semantic alignment and intent parsing results, and the most relevant MCP service.

[0109] For example, the intent-predicting agent can perform semantic alignment and intent parsing on the call request and the MCP service description vector, and combine this with the finally determined MCP service to predict other similar MCP services for the user to use in subsequent stages. Specifically, the intent-predicting agent can predict the MCP service tool that the user is most likely to use next based on a preset context. This context could be: user request: "{u}"; system-invoked tool: "{t" i}”; Execution result summary: “{summary}”; List of all available MCP service tools (including descriptions): Please select the top 4 MCP service tools most likely to be called by users in the next round, arranged in descending order of probability; Output format (strict JSON): {"next_tools": ["tool A", "tool B", "tool C", "tool D"]}.

[0110] Optionally, if the user does not adopt the MCP service tool recommended by the agent based on the intention prediction, or if the task fails, the system can send back a feedback signal to fine-tune the internal strategies of the two agents, such as reducing the similarity between the target MCP service tool and the recommended MCP service tool. All interaction states (user requests, MCP service tool call sequences, result summaries) can be uniformly stored in the dialogue state tracking module to ensure consistency across multiple rounds.

[0111] Figure 2 This diagram illustrates a specific example of the MCP service governance method based on a large model agent provided in this application. The large model agent may include a compliance governance agent and a semantic labeling agent.

[0112] like Figure 2 As shown, the first step is MCP service registration. The newly registered MCP service and its tool description information (including path, API definition, natural language description, parameter schema, etc.) are input into the compliance governance agent.

[0113] Secondly, the compliance governance intelligent agent can use a fine-tuned large model to analyze MCP service data and perform action timing logic (TLA). + Modeling, based on TLA + The modeling results are used to determine the validity of MCP service data.

[0114] Next, the semantic labeling agent can use a fine-tuned large model to parse MCP service data, extract keywords based on MCP service information, archive and classify MCPs, and assign structured labels (such as city, analogy, function).

[0115] Then, the MCP service information can be confirmed manually;

[0116] If the MCP service information is accurate, proceed to the next step. If there is a problem with the MCP service information, it can be corrected, and the corrected MCP service information can be stored as new sample data in the fine-tuning dataset. After accumulating a certain number of data, the fine-tuning of the large model is triggered during idle time.

[0117] Next, the embedding model can be used to vectorize the MCP service and tool descriptions contained in the accurate MCP service information and store them in a vector library.

[0118] The above steps involve compliance verification and classification management of MCP service information. The next step is the system's management of MCP services when users invoke them.

[0119] Continue to refer to Figure 2 First, users can enter a request through the system's input interface.

[0120] Secondly, the tool calling agent transforms the calling request into a vector. It then uses the cosine similarity of the vector plus a tag keyword recall mechanism to recall the top K MCP service tools from the MCP service tool set, and filters out irrelevant calling instructions (instructions corresponding to MCP service tools that are not recalled are considered invalid instructions), and selects the valid instructions with high similarity (instructions corresponding to the top K MCP service tools).

[0121] Then, the intent-predicting agent, through deep analysis of the recalled top K MCP service information, determines the MCP service and tool to be invoked from the top K MCP service tools and generates corresponding invocation instructions. Furthermore, it can recommend other similar MCP services based on the invocation request, the deep analysis results of the MCP service information, and the invocation instructions.

[0122] Finally, the tool calls the intelligent agent to confirm the call command, and generates the command content and call parameters. The call command is then used to invoke the corresponding MCP service and tool for user use.

[0123] Figure 3 This diagram illustrates a flowchart of an MCP service governance method based on a large model intelligent agent, as provided in an embodiment of this application. Figure 3 As shown, the method includes the following steps.

[0124] Step S301: Receive the first Model Context Protocol (MCP) service data.

[0125] Step S302: Through the large model agent, perform action timing logic (TLA) on the first MCP service data. + Modeling, based on TLA + The modeling results yielded compliant first MCP service data. The large model agent was obtained by fine-tuning the large model based on the mapping relationship between the path and classification label corresponding to the second MCP service data.

[0126] Step S303: Based on the large model intelligent agent, perform contextual semantic parsing on the compliant first MCP service data, extract the classification labels corresponding to the compliant first MCP service data, and perform hierarchical classification and governance on the compliant first MCP service data.

[0127] In one implementation, the above-mentioned large model intelligent agent performs action timing logic (TLA) on the first MCP service data. + Modeling includes: abstracting the state of the first MCP service data using a large model agent to obtain the corresponding state machine and indeterminate form; understanding the governance baseline of the natural language in the first MCP service data and generating valid initial values; writing Next clauses for the application programming interface (API) of the first MCP service data; and transforming the security policies and compliance requirements in the natural language of the first MCP service data into TLA⁺ logical expressions.

[0128] In one implementation, a large model agent performs action timing logic (TLA) on the first MCP service data. + After modeling, it also includes: according to TLA + The modeling results yielded non-compliant first MCP service data. A large model agent was then used to map the abstract state sequence corresponding to this non-compliant first MCP service data into natural language.

[0129] In one implementation, after performing contextual semantic parsing on the first MCP service data based on a large model agent to extract the classification labels corresponding to the compliant first MCP service data, the method further includes: correcting the classification labels corresponding to the compliant first MCP service data. The large model agent learns the mapping logic between the paths corresponding to the compliant first MCP service data and the corrected classification labels.

[0130] In one implementation, after performing contextual semantic parsing on the first MCP service data based on the large model agent and extracting the classification labels corresponding to the compliant first MCP service data, the method further includes: mapping the compliant first MCP service data to an MCP service description vector.

[0131] In one implementation, after mapping the compliant first MCP service data to an MCP service description vector, the process includes: using a tool invocation agent to determine multiple MCP services corresponding to the invocation request based on the invocation request and the MCP service description vector; and using an intent prediction agent to perform semantic alignment and intent parsing on the invocation request and the MCP service description vector to determine the MCP service most relevant to the invocation request.

[0132] In one implementation, after determining the MCP service most relevant to the call request, the method further includes: recommending other similar MCP services based on semantic alignment and intent parsing results and the most relevant MCP service through an intent prediction agent.

[0133] Based on the above description, this application also provides a schematic diagram of the structure of an MCP service governance device 400 based on a large model intelligent agent. For example... Figure 4 As shown, the device 400 includes:

[0134] The parsing module 410 is used to receive the first Model Context Protocol (MCP) service data.

[0135] Modeling module 420 is used to perform action timing logic (TLA) on the first MCP service data through a large model agent. + Modeling, based on TLA + The modeling results yielded compliant first MCP service data, in which the large model agent included a fine-tuned large model. The fine-tuned large model was obtained by fine-tuning the large model based on the mapping relationship between the path and classification label corresponding to the second MCP service data.

[0136] The extraction module 430 is used to perform contextual semantic parsing on the first MCP service data based on the large model intelligent agent, and extract the classification labels corresponding to the compliant first MCP service data, so as to carry out hierarchical classification and governance of the compliant first MCP service data.

[0137] For example, the implementation of the parsing module 410 will be described below. Similarly, the modeling module 420 and the extraction module 430 can refer to the implementation of the parsing module 410.

[0138] As an example of a software functional unit, the parsing module 410 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Further, the aforementioned computing instance may be one or more. For example, the parsing module 410 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.

[0139] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.

[0140] As an example of a hardware functional unit, the parsing module 410 may include at least one computing device, such as a server. Alternatively, the parsing module 410 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0141] The multiple computing devices included in the parsing module 410 can be distributed in the same region or in different regions. Similarly, the multiple computing devices included in the parsing module 410 can be distributed in the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the parsing module 410 can be distributed in the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0142] It should be noted that, in other embodiments, the parsing module 410 can be used to execute any step in the XXX method, the B module can be used to execute any step in the XXX method, and the C module can be used to execute any step in the XXX method. The steps implemented by the parsing module 410, the B module, and the C module can be specified as needed. By implementing different steps in the XXX method through the parsing module 410, the B module, and the C module, all functions of the YY device can be realized.

[0143] Based on the same concept as the foregoing embodiments, this application also provides a computing device, which includes at least a processor and a memory. The memory stores a program, and when the processor reads the program, it can implement the algorithmic functions embodied by the above-described methods or devices.

[0144] Based on the methods in the above embodiments, this application provides a computer-readable storage medium including computer program instructions. When executed by a cluster of computing devices including at least one computing device, the computer program instructions cause the cluster of computing devices to perform the methods in the above embodiments. Exemplarily, the computer-readable storage medium can be any available medium capable of being stored in the cluster of computing devices or a data storage device such as a data center containing one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives).

[0145] Based on the methods in the above embodiments, this application provides a computer program product containing instructions. The computer program product may be software or program products containing instructions, capable of running on a computing device or stored on any available medium. When the instructions are executed by a cluster of computing devices containing at least one computing device, at least one computing device in the cluster of computing devices performs the methods in the above embodiments.

[0146] It is understood that the processor in the embodiments of this application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.

[0147] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an ASIC.

[0148] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0149] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application.

[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.

Claims

1. A method for MCP service governance based on intelligent agents, characterized in that, include: Receive first model context protocol (MCP) service data; Using a large model intelligent agent, the action timing logic (TLA) is performed on the first MCP service data. + Modeling, based on the TLA + The modeling results yield compliant first MCP service data; the large model agent includes a fine-tuned large model, which is obtained by fine-tuning the large model based on the mapping relationship between the path and classification label corresponding to the second MCP service data; Based on the large model agent, the compliant first MCP service data is analyzed for contextual semantics, and the corresponding classification labels are extracted to perform hierarchical classification and governance of the compliant first MCP service data.

2. The method according to claim 1, characterized in that, The process involves using a large model intelligent agent to perform action timing logic (TLA) on the first MCP service data. + Modeling, including: Through the large model agent, the state of the first MCP service data is abstracted to obtain the state machine and indeterminate form corresponding to the first MCP service data; Understand the natural language governance baseline of the first MCP service data and generate valid initial values; Write a Next clause in the Application Programming Interface (API) of the first MCP service data; The security policies and compliance requirements in the natural language of the first MCP service data are converted into TLA⁺ logical expressions.

3. The method according to claim 1, characterized in that, The process involves using a large model intelligent agent to perform action timing logic (TLA) on the first MCP service data. + After modeling, it also includes: According to the TLA + The modeling results yielded non-compliant first MCP service data; The abstract state sequence corresponding to the non-compliant first MCP service data is mapped into natural language using a large model intelligent agent.

4. The method according to claim 1, characterized in that, After performing contextual semantic parsing on the first MCP service data based on the large model agent and extracting the classification labels corresponding to the compliant first MCP service data, the process further includes: Correct the category label corresponding to the compliant first MCP service data; The large model agent learns the mapping logic between the path corresponding to the compliant first MCP service data and the corrected classification label.

5. The method according to claim 1, characterized in that, After performing contextual semantic parsing on the first MCP service data based on the large model agent and extracting the classification labels corresponding to the compliant first MCP service data, the process further includes: The compliant first MCP service data is mapped to an MCP service description vector.

6. The method according to claim 5, characterized in that, The step of mapping the compliant first MCP service data to an MCP service description vector includes: By invoking the intelligent agent through the tool, multiple MCP services corresponding to the invocation request are determined based on the invocation request and the MCP service description vector; By using an intent-predicting agent, the call request and the MCP service description vector are semantically aligned and the intent is parsed to determine the MCP service most relevant to the call request.

7. The method according to claim 6, characterized in that, After determining the MCP service most relevant to the call request, the process further includes: Based on the semantic alignment and intent parsing results, and the most relevant MCP service, the agent predicts intent and recommends other similar MCP services.

8. A method for fine-tuning a large model, characterized in that, include: Obtain the path and category tags corresponding to the second MCP service data; Based on the mapping relationship between the path and the classification label corresponding to the second MCP service data, the large model can understand the semantics of the API interface of the second MCP service data and generate compliant classification labels corresponding to the second MCP service data.

9. The method according to claim 8, characterized in that, The process of enabling the large model to understand the semantics of the second MCP service data interface and generate compliant classification tags corresponding to the second MCP service data, based on the mapping relationship between the path and the tag, is accomplished by fine-tuning the large model using LoRA parameter fine-tuning technology, based on the path and classification tags corresponding to the second MCP service data.

10. A mechanism for governing MCP services based on intelligent agents, characterized in that, include: The parsing module is used to receive the first Model Context Protocol (MCP) service data; The modeling module is used to perform action timing logic (TLA) on the first MCP service data through a large model agent. + Modeling, based on the TLA + The modeling results yield compliant first MCP service data; the large model agent includes a fine-tuned large model, which is obtained by fine-tuning the large model based on the mapping relationship between the path and classification label corresponding to the second MCP service data; The extraction module is used to perform contextual semantic parsing on the first MCP service data based on the large model agent, and extract the classification labels corresponding to the compliant first MCP service data, so as to perform hierarchical classification and governance on the compliant first MCP service data.