Cette page est affichée en anglais. Une traduction française est en cours.
CLI ToolsMay 11, 2026·2 min de lecture

Pipelock — MCP Firewall for Agent Egress

Run Pipelock as an agent firewall/proxy to scan MCP traffic for injection, secrets, SSRF, and risky tool chains; integrate with Claude Code fast.

Introduction

Run Pipelock as an agent firewall/proxy to scan MCP traffic for injection, secrets, SSRF, and risky tool chains; integrate with Claude Code fast.

  • Best for: teams running tool-using agents (MCP/HTTP) who need egress control and auditable security checks
  • Works with: Claude Code hooks, MCP proxy patterns, and forward-proxy style agent egress control (per docs)
  • Setup time: 10 minutes

Quantitative Notes

  • GitHub stars + forks (verified): see Source & Thanks
  • Docs mention scanners for secrets + injection patterns (repo/docs)
  • Setup time ~10 minutes (install + Claude Code setup + restart)

Practical Notes

A pragmatic rollout: install the binary, enable Claude Code integration, and restart. Then run 10–20 normal tasks and record what gets flagged. Create allow/deny rules based on real incidents: metadata SSRF attempts, secret patterns in prompts, and risky tool chains (e.g., web fetch → write file → exec).

Safety note: Don’t rely on a single control. Combine firewall/proxy checks with least-privilege tools, sandboxing, and human approval for high-risk actions.

FAQ

Q: Is this a replacement for sandboxing? A: No. It complements sandboxing by enforcing egress policy and scanning tool traffic.

Q: Will it break my workflows? A: Start in observe mode (or with a permissive preset) and tighten rules once you see false positives.

Q: Where should I enforce policy? A: At the boundary: before tools execute or requests leave the machine/network.


🙏

Source et remerciements

GitHub: https://github.com/luckyPipewrench/pipelock Owner avatar: https://avatars.githubusercontent.com/u/142104046?v=4 License (SPDX): Apache-2.0 GitHub stars (verified via api.github.com/repos/luckyPipewrench/pipelock): 577 GitHub forks (verified via api.github.com/repos/luckyPipewrench/pipelock): 61

Fil de discussion

Connectez-vous pour rejoindre la discussion.
Aucun commentaire pour l'instant. Soyez le premier à partager votre avis.

Actifs similaires