Open-source agent firewall for MCP and AI agent egress
Pipelock mediates MCP, HTTP, and WebSocket traffic at the agent boundary and emits signed action receipts any third party can verify offline when receipt signing is configured.
Wraps stdio MCP servers too, the local subprocess servers most agents actually use, with the same scanner pipeline as network upstreams. New to the category? Start with what an agent firewall does and where its boundary stops.
v3.3.0 ships · operator dashboard · evidence viewer · stricter receipts
Public demo receipt stars carry signed chain records. Select one for details.
27 public demo receipts
792+
GitHub Stars
31,000+
Test Cases
>90%
Core Coverage
Go
Single Binary
214
Public Bench Cases
7
Compliance Mappings
Product metrics verified against pipelock@38bd9056b812 · corpus snapshot verified against agent-egress-bench@fb75dbf6e381.
CNCF Landscape
Pipelock is listed under Provisioning · Security & Compliance.
Narrative
Detect. Enforce. Prove.
One binary, three jobs. Each line below is a real surface in the Pipelock source tree.
Detect
11-layer scanner pipeline. 65 DLP patterns. A2A scanning. Encoded payload handling across HTTP, WebSocket, and MCP.
Enforce
OR-composed kill switch. Adaptive escalation. Process sandbox on Linux and macOS. MCP tool policy with redirect. Fail-closed on mediated paths.
Prove
Evidence for mediated machine operations. Hash-chained flight recorder. Ed25519-signed assessment reports. 30+ attack simulations.
Capabilities
What Pipelock covers
A compressed view. The full inventory lives on the product page.
Data Loss Prevention
65 credential patterns with checksum validation. Base64, hex, URL, and Unicode encoding-aware.
Prompt Injection
33 detection patterns. 6-pass normalization covering zero-width chars, homoglyphs, and leetspeak.
MCP Security
Stdio subprocess wrapping, tool poisoning detection, rug-pull tracking, policy engine with redirect, session binding, and chain detection.
Process Sandbox
Landlock + seccomp + network namespaces on Linux. sandbox-exec on macOS. Per-agent profiles with strict mode.
Adaptive Enforcement
Per-session threat scoring. Three escalation levels. Auto-recovery after clean traffic. No permanent lockouts.
Compliance Evidence
OWASP MCP Top 10, OWASP Agentic Top 10, MITRE ATLAS, EU AI Act, NIST AI RMF, HIPAA, SOC 2 mappings. Ed25519-signed reports.
Plus more surfaces
Evidence
Monitor. Block. Prove.
Three real artifacts the binary produces today. Click any panel to see how it works in production.

01 Monitor
Operator console
A read-only console over signed evidence: enforcement decisions, evidence integrity, exemptions, budgets, and fleet posture. Plus 85 Prometheus metrics.
See the console →
02 Block
6-source kill switch
Trigger from CLI, dashboard, API, or Telegram. One source flips the agent into deny-all in under a second.
Kill-switch flow →
03 Prove
Ed25519-signed reports
7 compliance frameworks. Demo reports verify offline against the Pipelock demo key; customer reports verify against the deployment's pinned key.
View Assess →Get Started
Two minutes to protection
Works with Claude Code, Cursor, VS Code, JetBrains, local stdio MCP servers, or any agent that speaks HTTP or WebSocket.
In production
Run by people who ship agents
Operators running Pipelock in front of real coding agents with real secrets.
verify it yourself: pipelab.org/playground/
Public methodology · Public attack cases · Public Pipelock results
