The short version
Pipelock is a network-layer agent firewall. It scans HTTP requests, WebSocket frames, and MCP tool calls routed through it for credential leaks, prompt injection, SSRF, and tool poisoning, and can emit signed action receipts for mediated decisions when a signing key is configured. It works with any agent whose traffic you can route.
LlamaFirewall is an inference-layer Python library from Meta’s PurpleLlama project. It runs three scanners: PromptGuard classifies inputs with a fine-tuned model, AlignmentCheck audits the agent’s chain of thought with a second model, and CodeShield runs static analysis on generated code.
They operate at different layers. One watches the wire. The other watches the model.
Feature comparison
| Feature | Pipelock | LlamaFirewall |
|---|---|---|
| Layer | Network: HTTP, WebSocket, MCP proxy | Inference: Python library in the pipeline |
| Language | Go, single binary | Python |
| Deployment | Proxy, sidecar, or standalone | Library imported into your agent code |
| Credential scanning (DLP) | 65 patterns, encoding-aware | No |
| Prompt injection detection | Deterministic patterns with normalization on scanned responses | PromptGuard classifier, model-based |
| Chain-of-thought auditing | No | AlignmentCheck |
| Generated-code analysis | No | CodeShield |
| MCP tool scanning | Both directions, with drift detection | No |
| SSRF protection | Yes | No |
| Works with hosted agents | Yes, proxy setting or MCP wrapping | Needs pipeline access; no hosted-agent integration documented |
| Process sandbox | Landlock, seccomp, and network namespaces on Linux; sandbox-exec on macOS | No |
| Signed receipts | Yes, Ed25519, verifiable offline | No |
| Runtime dependencies | None; 27 direct build dependencies | Python runtime, PyTorch, model weights |
| License | Apache-2.0 core; Enterprise under ELv2 | MIT |
Where LlamaFirewall is stronger
AlignmentCheck sees intent. It uses a second model to audit the primary model’s reasoning. If the model is planning to read a key file and send it somewhere, AlignmentCheck can catch that before anything happens. A network-layer tool only sees the result.
PromptGuard is model-based. A classifier can catch novel injection phrasings that a pattern set hasn’t seen.
CodeShield catches unsafe code. Generated code with known-bad patterns gets flagged before it runs. Pipelock doesn’t analyze generated code.
Where Pipelock is stronger
Closed-pipeline agents. Claude Code, Cursor, GitHub Copilot, and most commercial agents run on hosted models. You can’t insert a Python library into their inference chain. You can route their traffic through a proxy.
Credential leak prevention. Every outbound request is checked for secret patterns after decoding base64, hex, and URL encoding. LlamaFirewall has no DLP.
MCP security. Tool descriptions are fingerprinted and scanned for poisoning, mid-session changes are flagged, arguments and responses are inspected. LlamaFirewall doesn’t speak MCP.
SSRF protection. Private IP ranges, cloud metadata endpoints, and link-local addresses are blocked, with DNS rebinding protection.
Process containment. The pipelock sandbox command wraps a process with Landlock, seccomp, and network namespace isolation on Linux, and sandbox-exec profiles on macOS.
Evidence. With a signing key configured, Pipelock can emit signed receipts for mediated decisions and verify them offline.
Bypass surface
Both tools have limits, and they fail differently.
A classifier guardrail shares the model’s trust boundary. Input designed to fool the model is processed by similar techniques in the guardrail, so a sufficiently crafted injection can pass both. AlignmentCheck depends on the auditing model being sharper than the attack, and on the reasoning it audits actually revealing intent.
Pattern-based detection misses novel phrasings, and DLP regexes miss encrypted payloads. If an agent sends data through a channel Pipelock doesn’t proxy, Pipelock doesn’t see it.
Those failures are independent of each other, which is the argument for running both.
When to use each
Start with Pipelock if you run commercial or hosted agents, or your first risk is what leaves the machine. No Python required, no pipeline access needed.
Use LlamaFirewall if you build a custom Python agent, control the model pipeline, and want reasoning audits or model-based input classification.
Use both if you build a custom Python agent and want defense at both layers.
Further reading
- Pipelock vs Microsoft AGT: an in-process governance SDK with its own audit chain
- What is an agent firewall?: definition and threat model
- Agent firewall vs guardrails: the category-level version of this comparison
- Pipelock vs Lakera Guard: a commercial classifier at the same boundary
- MCP security: tool poisoning and rug-pulls
- Pipelock on GitHub
Sources checked
Third-party descriptions on this page come from the public materials below, read on the dates shown. Features and pricing change; check the current documentation before you decide.
Third-party product names and marks belong to their owners. PipeLab is not affiliated with, sponsored by, or endorsed by the makers of any product compared on this page. Descriptions of other products come from their own public materials on the dates listed above and reflect PipeLab's reading of them. If something here is wrong or out of date, tell us and it will be corrected.