The open-source security gateway for AI agents.
mcp-firewall sits between your MCP client and server, intercepting every tool call with enterprise-grade policy enforcement, real-time threat detection, and compliance-ready audit logging.
AI Agent ββ mcp-firewall ββ MCP Server
β
Policy Engine
Audit Trail
Threat Feed
AI agents can now execute tools β read files, run commands, query databases, make HTTP requests. Without guardrails, a single prompt injection can exfiltrate your credentials, execute arbitrary code, and chain tools for privilege escalation.
mcp-firewall is the WAF for AI agents.
The reviewed integration is available as the v0.2.0a1 GitHub prerelease. Download and verify its wheel as described in release instructions; this prerelease is not published to PyPI. See the changelog for changes and experimental recovery limits.
pip install mcp-firewall
# Wrap any MCP server with zero config
mcp-firewall wrap -- npx @modelcontextprotocol/server-filesystem /tmp
# Generate a starter policy
mcp-firewall initEvery tool call passes through 7 inbound security stages (plus optional human approval) and 2 outbound scanners:
Inbound (request screening):
- Kill Switch β Emergency deny-all
- Rate Limiter β Per-agent, per-tool, global
- Injection Detector β Pattern-based, sensitivity configurable (low/medium/high)
- Egress Control β Block SSRF, private IPs, cloud metadata
- Threat Feed β Known attack patterns (built-in community rules)
- Policy Engine β YAML policies + per-agent RBAC
- Chain Detector β Dangerous tool sequences
When a rule requires approval, an interactive prompt asks the user; non-interactive sessions fail closed (deny).
Outbound (response scanning):
- Secret Scanner β API keys, tokens, private keys
- PII Detector β Email, phone, SSN, IBAN, credit cards
Simple YAML for common rules:
agents:
claude-desktop:
allow: [read_file, search]
deny: [exec, shell, rm]
rate_limit: 100/min
rules:
- name: block-credentials
match: { arguments: { path: "**/.ssh/**" } }
action: denySee Policy Reference for the full rule schema.
mcp-firewall wrap --dashboard -- python my_server.py
# β Dashboard at http://localhost:9090Live event feed and statistics.
Enable audit.sign: true to sign every event with Ed25519 in addition to the hash chain. Export to SIEM (CEF/LEEF), Syslog, CSV, or JSON.
mcp-firewall audit # Verify chain integrity
mcp-firewall audit export --format cef --output siem.logAuto-generated evidence for regulatory audits:
mcp-firewall report dora # EU Digital Operational Resilience Act
mcp-firewall report finma # Swiss Financial Market Authority
mcp-firewall report soc2 # SOC 2 Type II evidenceCommunity-maintained detection rules (like Sigma for SIEM):
mcp-firewall feed list # Show active rulesRules detect known-bad patterns: webhook exfiltration, credential harvesting, cloud metadata SSRF, and more.
Pre-deployment security scanning (powered by mcpwn):
mcp-firewall scan -- python my_server.pyWorks with every MCP client β zero code changes:
{
"mcpServers": {
"filesystem": {
"command": "mcp-firewall",
"args": ["wrap", "--", "npx", "@modelcontextprotocol/server-filesystem", "/home"]
}
}
}Compatible with: Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, and any MCP client.
βββββββββββββββ ββββββββββββββββββββββββββββββββ βββββββββββββββ
β MCP Client ββββββΊβ mcp-firewall ββββββΊβ MCP Server β
βββββββββββββββ β β βββββββββββββββ
β Inbound ββΊ Policy ββΊ Outboundβ
β β β β β
β βΌ βΌ βΌ β
β [Audit] [Alerts] [Metrics] β
β β β
β βΌ β
β [Dashboard] [Reports] β
βββββββββββββββββββββββββββββββ--β
| Feature | mcp-firewall | Agent-Wall | LlamaFirewall | MintMCP |
|---|---|---|---|---|
| MCP-native proxy | β | β | β | β (SaaS) |
| Open source | β | β | β | β |
| Agent RBAC | β | β | β | β |
| Signed audit trail | β | β | β | β |
| Compliance reports | β | β | β | SOC2 only |
| Threat feed | β | β | β | β |
| Alerting | β | β | β | β |
| Dashboard | β | Basic | β | β |
| Cost tracking | β | β | β | β |
| Built-in scanner | β | β | β | β |
- Developers: Protect your machine when trying new MCP servers
- Security Teams: Enforce tool usage policies across the organization
- Compliance Officers: Generate audit evidence for DORA, FINMA, SOC 2
- CISOs: Visibility and control over AI agent behavior
- Red Teamers: Test AI agent security posture
mcp-firewall works as a Python library, not just an MCP proxy. Use it with OpenClaw, LangChain, CrewAI, or any custom agent:
from mcp_firewall.sdk import Gateway
with Gateway(config_path="mcp-firewall.yaml") as gw:
decision = gw.check("read_file", {"path": "/tmp/example.txt"}, agent="my-agent")
if decision.blocked:
print(f"Blocked: {decision.reason}")
else:
# Illustrative output: the SDK itself never executes the tool.
output = "AWS_KEY=AKIAIOSFODNN7EXAMPLE"
result = gw.scan_response(output, context=decision.context)
print(result.content) # "AWS_KEY=[REDACTED by mcp-firewall]"See examples/openclaw_integration.py for a full example.
SDK approval requests now fail closed by default, and configured audit logging is respected. See the SDK migration guide for changed defaults, async methods, structured responses, and resource cleanup.
Use mcp-firewall wrap --dashboard-approvals -- <server> for authenticated,
single-call approval in the local dashboard. Set MCP_FIREWALL_DASHBOARD_TOKEN
and connect the controller first. Missing approval, timeout or controller loss
denies the call; global restrictions still apply. See setup and limits.
A native AgentReins adapter adds the same approval controls and correlated protocol evidence to a pinned AgentReins development build.
Export versioned lifecycle events to a local desktop companion or another HTTP receiver. Events correlate admission and response decisions using session and call IDs, with bounded background delivery and sanitized metadata. Audit entries and the dashboard use the same event model. Export never grants permission or proves that a tool executed.
See the integration contract, JSON schema, and example receiver.
mcpwn β Security scanner for MCP servers. While mcp-firewall protects at runtime, mcpwn finds vulnerabilities before deployment.
| Tool | When | What |
|---|---|---|
| mcpwn | Pre-deployment | Find vulnerabilities in MCP servers |
| mcp-firewall | Runtime | Block attacks, enforce policies, audit logging |
Scan first, then protect:
# Step 1: Scan for vulnerabilities
mcp-firewall scan -- python my_server.py
# Step 2: Protect at runtime
mcp-firewall wrap -- python my_server.pyOpt in to before/after file snapshots with wrap --dashboard-approvals --snapshot-workspace /absolute/project. The native adapter can display diffs and
restore a selected file while rejecting stale edits. Snapshots are bounded and
last for the proxy process lifetime; pause external writers before restore.
See workspace rollback for setup and limits.
- Getting Started
- Policy Reference
- Compliance Guide
- Threat Feed
- Architecture
- Workspace snapshots and rollback
See CONTRIBUTING.md for guidelines.
Security issues: see SECURITY.md.
AGPL-3.0 β see LICENSE.
Commercial licensing available for organizations that cannot use AGPL. Contact rr@canus.ch.
Built by Robert Ressl β Associate Director Offensive Security at Kyndryl. CISSP, OSEP, OSCP, CRTO. After 100+ penetration tests and red team engagements across banking, insurance, and critical infrastructure, I saw the gap: AI agents are the new attack surface, and MCP is the protocol everyone uses but nobody secures.
mcp-firewall is the firewall that MCP needs.