Inference guardrails

Pipelock vs LlamaFirewall

Network-layer enforcement next to inference-layer guardrails. One watches the wire, the other watches the model.

At a glance

Pipelock source LlamaFirewall
Job Agent firewall. Mediates HTTP, WebSocket, and MCP traffic routed through it, scans it for secret leaks, prompt injection, SSRF, and tool poisoning, and can emit signed action receipts for mediated decisions when a signing key is configured. Python guardrail library from Meta's PurpleLlama. Classifies inputs (PromptGuard), audits the agent's reasoning (AlignmentCheck), and scans generated code (CodeShield).
Enforcement point Network path, outside the agent process Inside the inference pipeline, as a library you import
Source Open source, Apache-2.0 core; Enterprise under ELv2 Open source, MIT
Pricing shape Free core; paid Pro and Enterprise tiers Free
Runs as Single Go binary, self-hosted; container and Helm pip install; needs a Python runtime and model weights for the classifier
Pick LlamaFirewall

You build a custom Python agent, control the model pipeline, and want to catch unsafe intent or unsafe generated code before the agent acts.

Pick Pipelock

You run agents whose pipeline you can't modify (Claude Code, Cursor, Copilot) or you need credential, MCP, and SSRF coverage on the traffic itself, with a signed record.

Run both

Custom Python agent: LlamaFirewall catches bad intent, Pipelock catches bad traffic. Different failure modes, complementary coverage.

Want the runtime boundary, not just another checklist?

The short version

Pipelock is a network-layer agent firewall. It scans HTTP requests, WebSocket frames, and MCP tool calls routed through it for credential leaks, prompt injection, SSRF, and tool poisoning, and can emit signed action receipts for mediated decisions when a signing key is configured. It works with any agent whose traffic you can route.

LlamaFirewall is an inference-layer Python library from Meta’s PurpleLlama project. It runs three scanners: PromptGuard classifies inputs with a fine-tuned model, AlignmentCheck audits the agent’s chain of thought with a second model, and CodeShield runs static analysis on generated code.

They operate at different layers. One watches the wire. The other watches the model.

Feature comparison

FeaturePipelockLlamaFirewall
LayerNetwork: HTTP, WebSocket, MCP proxyInference: Python library in the pipeline
LanguageGo, single binaryPython
DeploymentProxy, sidecar, or standaloneLibrary imported into your agent code
Credential scanning (DLP)65 patterns, encoding-awareNo
Prompt injection detectionDeterministic patterns with normalization on scanned responsesPromptGuard classifier, model-based
Chain-of-thought auditingNoAlignmentCheck
Generated-code analysisNoCodeShield
MCP tool scanningBoth directions, with drift detectionNo
SSRF protectionYesNo
Works with hosted agentsYes, proxy setting or MCP wrappingNeeds pipeline access; no hosted-agent integration documented
Process sandboxLandlock, seccomp, and network namespaces on Linux; sandbox-exec on macOSNo
Signed receiptsYes, Ed25519, verifiable offlineNo
Runtime dependenciesNone; 27 direct build dependenciesPython runtime, PyTorch, model weights
LicenseApache-2.0 core; Enterprise under ELv2MIT

Where LlamaFirewall is stronger

AlignmentCheck sees intent. It uses a second model to audit the primary model’s reasoning. If the model is planning to read a key file and send it somewhere, AlignmentCheck can catch that before anything happens. A network-layer tool only sees the result.

PromptGuard is model-based. A classifier can catch novel injection phrasings that a pattern set hasn’t seen.

CodeShield catches unsafe code. Generated code with known-bad patterns gets flagged before it runs. Pipelock doesn’t analyze generated code.

Where Pipelock is stronger

Closed-pipeline agents. Claude Code, Cursor, GitHub Copilot, and most commercial agents run on hosted models. You can’t insert a Python library into their inference chain. You can route their traffic through a proxy.

Credential leak prevention. Every outbound request is checked for secret patterns after decoding base64, hex, and URL encoding. LlamaFirewall has no DLP.

MCP security. Tool descriptions are fingerprinted and scanned for poisoning, mid-session changes are flagged, arguments and responses are inspected. LlamaFirewall doesn’t speak MCP.

SSRF protection. Private IP ranges, cloud metadata endpoints, and link-local addresses are blocked, with DNS rebinding protection.

Process containment. The pipelock sandbox command wraps a process with Landlock, seccomp, and network namespace isolation on Linux, and sandbox-exec profiles on macOS.

Evidence. With a signing key configured, Pipelock can emit signed receipts for mediated decisions and verify them offline.

Bypass surface

Both tools have limits, and they fail differently.

A classifier guardrail shares the model’s trust boundary. Input designed to fool the model is processed by similar techniques in the guardrail, so a sufficiently crafted injection can pass both. AlignmentCheck depends on the auditing model being sharper than the attack, and on the reasoning it audits actually revealing intent.

Pattern-based detection misses novel phrasings, and DLP regexes miss encrypted payloads. If an agent sends data through a channel Pipelock doesn’t proxy, Pipelock doesn’t see it.

Those failures are independent of each other, which is the argument for running both.

When to use each

Start with Pipelock if you run commercial or hosted agents, or your first risk is what leaves the machine. No Python required, no pipeline access needed.

Use LlamaFirewall if you build a custom Python agent, control the model pipeline, and want reasoning audits or model-based input classification.

Use both if you build a custom Python agent and want defense at both layers.

Further reading

Sources checked

Third-party descriptions on this page come from the public materials below, read on the dates shown. Features and pricing change; check the current documentation before you decide.

Third-party product names and marks belong to their owners. PipeLab is not affiliated with, sponsored by, or endorsed by the makers of any product compared on this page. Descriptions of other products come from their own public materials on the dates listed above and reflect PipeLab's reading of them. If something here is wrong or out of date, tell us and it will be corrected.

Frequently asked questions

What's the main difference between Pipelock and LlamaFirewall?
Pipelock operates at the network layer, scanning HTTP requests, WebSocket frames, and MCP tool calls routed through it and can emit signed receipts when a signing key is configured. LlamaFirewall operates at the inference layer, checking inputs, the model’s reasoning, and generated code before the agent acts. Pipelock catches credential leaks and injection in routed traffic. LlamaFirewall catches unsafe intent. They are complementary.
Should I use Pipelock or LlamaFirewall?
Ideally both. If you can only pick one: LlamaFirewall if you control the model pipeline and your risk is unsafe reasoning or generated code, Pipelock if you run third-party agents you can’t modify or your risk is what leaves the machine.
Does LlamaFirewall work with Claude Code or Cursor?
Not directly. LlamaFirewall is a Python library that hooks into a model pipeline you control. Hosted agents don’t expose that pipeline. Pipelock works with any agent because it operates at the network layer and needs only a proxy setting or MCP wrapping.

Want the runtime boundary, not just another checklist?

See all comparisons →