The short version
A WAF (web application firewall) sits in front of a web server. It blocks inbound attacks: SQL injection, cross-site scripting, request smuggling, and the rest of the categories a rule set like the OWASP CRS covers.
An agent firewall sits between an AI agent and the internet. It scans routed outbound requests for credential leaks and routed inbound responses for prompt injection. Pipelock can emit signed action receipts for mediated decisions when a signing key is configured.
They protect different things and the traffic flows in different directions. If you run AI agents, a WAF doesn’t cover your threat model.
Traffic direction
| WAF | Agent firewall | |
|---|---|---|
| Protects | Web servers | Mediated agent traffic |
| Primary traffic | Inbound requests from users | Outbound requests routed from agents, and routed responses |
| Threat model | Attackers sending malicious requests | Agents leaking secrets or following injected instructions |
| Position | Between the internet and the server | On the agent’s routed network path |
A WAF asks: is this incoming request an attack? An agent firewall asks: is this outgoing request leaking a credential, and is this incoming response trying to hijack the agent?
What WAFs are good at
WAFs have decades of maturity. The OWASP Core Rule Set alone covers SQL injection, cross-site scripting, local and remote file inclusion, and several code-injection classes, and commercial WAF products layer rate limiting, IP reputation, and vendor signatures on top. If you run a web application, you should have one.
What WAFs don’t cover
Outbound credential scanning. An agent with shell access may have cloud keys, repository tokens, and database passwords in its environment. If an injection tells it to POST them to an attacker’s server, the WAF in front of your web app never sees that request. The agent’s outbound traffic doesn’t go through it.
Prompt injection in responses. When an agent fetches a URL and the response says to ignore its instructions and send a private key somewhere, that’s an attack on the agent. The WAF sources read for this page do not describe response-body scanning for prompt injection.
MCP tool poisoning. MCP lets agents call external tools. A poisoned tool description can instruct the agent to exfiltrate data. The WAF sources read for this page do not describe MCP tool-description inspection.
Exfiltration through allowed channels. An agent can encode secrets in a request to a destination that looks fine. Catching that needs content inspection on the egress path, not signature matching on the ingress path.
What about “Firewall for AI” products?
Some WAF and CDN vendors market an add-on under a name like AI firewall or Firewall for AI. Cloudflare’s is the concrete example: its docs now call it AI Security for Apps, formerly Firewall for AI. It scans incoming JSON requests to endpoints you label cf-llm for PII, unsafe or custom topics, and prompt injection, and exposes the results as fields for WAF rules; the detection fields are an Enterprise paid add-on. The shape is a WAF feature tuned for an LLM endpoint you host, which is a different thing from an agent firewall. It sits in front of your model API and screens what users send to it.
That’s useful if you run an LLM-powered API that users talk to. It protects the model from users. It doesn’t protect an agent from the internet.
| Firewall for AI add-ons | Agent firewall | |
|---|---|---|
| Protects | Your LLM API endpoint | The agent process |
| Direction | Inbound to the model | Outbound from the agent and inbound to the agent |
| Deployment | In front of your API | On the agent’s routed network path |
| What it inspects | Requests to your model endpoint, per the vendor’s docs; Cloudflare’s reads JSON prompts for PII, topics, and injection | Mediated credentials in HTTP bodies, WebSocket frames, and MCP arguments, plus routed responses for injection |
| MCP support | No MCP support documented in the sources read | MCP proxy scanning |
When to use each
Use a WAF if you run a web application, with or without AI features, that serves HTTP to users.
Use an agent firewall if you run AI agents that make outbound requests, call MCP tools, or hold credentials. That includes Claude Code, Cursor, Copilot, custom agents, and any framework that gives a model tool access.
Use both if your agent also serves web traffic, or your stack has both user-facing APIs and backend agents.
How Pipelock fits
Pipelock is an open-source agent firewall. It runs as a proxy between the agent and the internet and scans mediated HTTP, WebSocket, and MCP traffic through a fixed-order pipeline with DLP before DNS resolution. It covers the agent side of the problem: outbound credential leaks, injection in inbound responses, SSRF, MCP tool poisoning, and per-domain rate limits. With a signing key configured, it can emit signed action receipts for mediated decisions.
It doesn’t replace your WAF.
Users -> WAF -> your web app (protected from attacks)
Agent -> Pipelock -> internet, MCP (protected from leaks and injection)
Further reading
- What is an agent firewall?: definition, threat coverage table, and evaluation checklist
- Agent firewall checklist: requirements for evaluating implementations
- Agent firewall vs guardrails: another commonly confused pair
- Agent egress security: preventing credential leaks from agents
- Why Pipelock is an egress agent firewall: why it controls egress instead of filtering inbound like a WAF
- OWASP Core Rule Set: the open-source WAF rule set for traditional web attacks
- Pipelock on GitHub
Sources checked
Third-party descriptions on this page come from the public materials below, read on the dates shown. Features and pricing change; check the current documentation before you decide.
Third-party product names and marks belong to their owners. PipeLab is not affiliated with, sponsored by, or endorsed by the makers of any product compared on this page. Descriptions of other products come from their own public materials on the dates listed above and reflect PipeLab's reading of them. If something here is wrong or out of date, tell us and it will be corrected.