About · v3.5.0 · Aug 8, 2026

PipeLab is the company behind Pipelock.

Pipelock is an open-source agent firewall for MCP and agent traffic. It sits between AI agents and the internet and blocks secret leaks, unsafe tool traffic, and prompt-injection responses.

Also published: Agent Egress Bench results Proof Comparisons Technical guides

36,000+

Test cases

49

Releases

251

Bench cases

34

Injection patterns

Go

Single binary

Corpus snapshot verified against agent-egress-bench@a3d56890487a.

Origin

From a homelab problem to a public security tool

PipeLab started as a homelab project, not a startup. It grew because a real operational problem needed a real fix.

  1. 2024 · Homelab

    A plumbing business wanted to automate operations. The founder spun up a homelab and started building AI agents to take dispatch, scheduling, and back-office work off the calendar.

  2. The problem

    Those agents had shell access, API keys, and unrestricted network access. One bad call or poisoned tool response could send credentials out. The missing piece was an enforcement point between the agent and the internet.

  3. The fix

    Pipelock was built to fill the gap. A single Go binary (Apache-2.0 core; Enterprise features under ELv2). It scans mediated HTTP, WebSocket, and MCP messages for credential leaks, prompt injection, SSRF, and tool poisoning.

  4. Today

    Pipelock is listed in the CNCF Landscape under Security & Compliance, and publishes coverage mappings for OWASP MCP Top 10, OWASP Agentic Top 10, MITRE ATLAS, EU AI Act, NIST AI RMF, HIPAA, and SOC 2.

Ship

What PipeLab ships

Four public projects cover runtime enforcement, testing, detection rules, and verifiable evidence.

Pipelock

The open-source agent firewall. A single Go binary that sits between an AI agent and the internet, scanning mediated messages through a fixed-order pipeline with DLP before DNS.

LicenseApache-2.0 core
Tests36,000+
Releases49

Agent Egress Bench

A tool-neutral attack corpus for validating any agent egress proxy. Public methodology, public attack cases, public results.

Corpus snapshot verified against agent-egress-bench@a3d56890487a.

Cases251
Categories18
LicenseApache-2.0

Pipelock Rules

Community detection patterns shipped as signed YAML bundles. Hot-reloadable. Adds DLP, prompt-injection, and tool-poisoning coverage without a redeploy.

DLP patterns65
SigningEd25519
ReloadHot

Agent Evidence Level

An open draft standard for grading AI-agent audit evidence by what an independent party can verify and what omission they can detect.

StatusDraft v0.1
ScaleAEL-0 to AEL-4
GovernancePipeLab maintained

Philosophy

How PipeLab works

01 / Build it yourself

Build what you can inspect.

The scanner pipeline is public, testable, and traceable when something behaves differently than expected.

02 / Honest engineering

The security engine stays free. Coordination is paid.

Apache-2.0 core; Enterprise features under ELv2. The bench is public. The rules repo is signed and versioned. Pro features pay for multi-agent coordination, not for access to what should be free.

Public methodology Offline verification Reproducible tests