About · v3.5.0 · Aug 8, 2026
PipeLab is the company behind Pipelock.
Pipelock is an open-source agent firewall for MCP and agent traffic. It sits between AI agents and the internet and blocks secret leaks, unsafe tool traffic, and prompt-injection responses.
36,000+
Test cases
49
Releases
251
Bench cases
34
Injection patterns
Go
Single binary
Corpus snapshot verified against agent-egress-bench@a3d56890487a.
Origin
From a homelab problem to a public security tool
PipeLab started as a homelab project, not a startup. It grew because a real operational problem needed a real fix.
2024 · Homelab
A plumbing business wanted to automate operations. The founder spun up a homelab and started building AI agents to take dispatch, scheduling, and back-office work off the calendar.
The problem
Those agents had shell access, API keys, and unrestricted network access. One bad call or poisoned tool response could send credentials out. The missing piece was an enforcement point between the agent and the internet.
The fix
Pipelock was built to fill the gap. A single Go binary (Apache-2.0 core; Enterprise features under ELv2). It scans mediated HTTP, WebSocket, and MCP messages for credential leaks, prompt injection, SSRF, and tool poisoning.
Today
Pipelock is listed in the CNCF Landscape under Security & Compliance, and publishes coverage mappings for OWASP MCP Top 10, OWASP Agentic Top 10, MITRE ATLAS, EU AI Act, NIST AI RMF, HIPAA, and SOC 2.
Ship
What PipeLab ships
Four public projects cover runtime enforcement, testing, detection rules, and verifiable evidence.
Pipelock
The open-source agent firewall. A single Go binary that sits between an AI agent and the internet, scanning mediated messages through a fixed-order pipeline with DLP before DNS.
Agent Egress Bench
A tool-neutral attack corpus for validating any agent egress proxy. Public methodology, public attack cases, public results.
Corpus snapshot verified against agent-egress-bench@a3d56890487a.
Pipelock Rules
Community detection patterns shipped as signed YAML bundles. Hot-reloadable. Adds DLP, prompt-injection, and tool-poisoning coverage without a redeploy.
Agent Evidence Level
An open draft standard for grading AI-agent audit evidence by what an independent party can verify and what omission they can detect.
Philosophy
How PipeLab works
01 / Build it yourself
Build what you can inspect.
The scanner pipeline is public, testable, and traceable when something behaves differently than expected.
02 / Honest engineering
The security engine stays free. Coordination is paid.
Apache-2.0 core; Enterprise features under ELv2. The bench is public. The rules repo is signed and versioned. Pro features pay for multi-agent coordination, not for access to what should be free.
Continue