Pipelock Guides

Pipelock Guides: IDE Setup and MCP Security

Agent security concepts explained.

94 guides

94 total. Filter by category or search by title and tag.

Evidence

Agent Evidence Levels

Agent Evidence Levels (AEL) is an open standard grading AI-agent audit evidence from AEL-0 to AEL-4 by what an independent party can verify offline.

intro aelevidencestandard

Concepts

Agent Firewall vs Guardrails vs Sandbox

Agent firewall, guardrails, and sandbox compared as four security functions: prevention, detection, containment, and evidence. What each does and misses.

deep agent-firewallconceptsevidence

IDE Setup

Claude Code Security

Claude Code security beyond built-in review. Add egress inspection, outbound DLP, MCP response scanning, and containment you can verify.

deep claude-codesecuritymcp

Concepts

Known Limitations

A standing register of what Pipelock does not catch: process-level bypass, non-HTTP exfiltration, covert channels, and semantic prompt injection.

ref limitationsevidenceconcepts

Operator

Progressive Enforcement

Progressive enforcement for AI agents: observe, baseline, shadow, then enforce. Roll out a blocking agent firewall with signed, reversible receipts.

deep progressive-enforcementlearn-and-lockagent-firewall

Concepts

What Pipelock Claims and Doesn't

Pipelock never claims non-bypass. It claims deterministic scanning of mediated traffic, containment as deployment guidance, and signed evidence.

deep evidenceagent-firewallconcepts

Evidence

AARP Claims Dictionary

AARP claims dictionary: verified claims, reserved vocabulary, does_not_assert limits, and overclaim-risk warnings for receipt appraisal.

ref receiptsassuranceevidence

Evidence

AARP Spec

AARP v0.1 spec: a signed assurance profile over Pipelock receipts. Claim-set by axis, JCS canonicalization, parallel signatures, X.509-SVID identity.

ref receiptsassuranceed25519

Evidence

AARP: Proves / Does Not

What a verified AARP receipt proves and does not prove. Binary-enforced versus deployment-claimed, and the trust assumptions a relying party must pin.

ref receiptsassurancethreat-model

Operator

Hermes Integration

Bridge Hermes Agent into Pipelock's scanner pipeline with a hook plugin. Install, verify, and roll back the integration with one command each.

intro integrationhermesmcp

Concepts

Redaction Placeholders

Decode AI redaction placeholders like <private_address>, <private_person>, and <pl:aws-access-key:1>: what each token means, what tool emits it, and why.

intro redactiondlpprivacy

Operator

Request Policy

Pipelock request policy allows or denies individual outbound API operations: GraphQL mutations, JSON batch sub-requests, and admin calls, not just hosts.

intro request-policyegressgraphql

Operator

Pro Reference Deployment

Pipelock Pro reference deployment: per-agent budgets, source-CIDR routing, cross-agent federation, signed receipts. The architecture, not the marketing.

deep prodeploymentfederation

Concepts

Agent Security Tool Profiles

Receipt-scoring profiles for agent security tools: signed, offline-verifiable evidence buyers can reproduce against the public corpus.

intro procurementreceiptsprofiles

Evidence

Agent Action Receipts

Agent action receipts: Ed25519-signed records of AI agent network and tool actions, chained by hash, verifiable offline by any third party.

intro receiptsevidenceaudit

Comparison

Agent Security Control Layers

Four-layer map of AI agent security: process sandboxing, identity governance, MCP gateway mediation, and egress inspection with signed receipts.

intro comparisonarchitectureegress

Evidence

Verifiable Egress Control

Verifiable Egress Control combines network-enforced AI agent egress with signed action receipts auditors and procurement teams can verify offline.

intro vecevidencereceipts

Operator

Verify a Receipt

Verify Pipelock Ed25519 action receipts with Go, TypeScript, Rust, or Python verifier CLIs against the public conformance corpus.

intro receiptsed25519audit-packet

Operator

Pipelock v2.5 Upgrade

Pipelock v2.5 upgrade guide: verifier rollout, containment lifecycle, strict federation, MCP integrity, and installer checks.

ref releaseupgradev2.5

Operator

Audit Packet Threat Model

Threat model for the Pipelock Audit Packet. Receipt provenance, self-consistent verdicts, signer-key pinning, what verified evidence does not prove.

ref audit-packetthreat-modelreceipts

Operator

Browser Shield

Browser Shield strips extension probes, hidden prompt traps, and tracking beacons from agent-fetched HTML, JavaScript, and SVG. Signed receipts.

intro browser-shieldresponse-rewritingreceipts

IDE Setup

Continue.dev MCP Security

Continue.dev MCP security guide. Wrap each MCP server in Continue's config through pipelock mcp proxy for DLP, injection, and tool-poisoning scanning.

intro continue.devmcpsetup

Concepts

Pipelock Performance

Latency, cold-start, and memory overhead numbers for Pipelock across HTTP, SSE, MCP stdio, WebSocket, and tool-call chains. Reproducible.

deep performancebenchmarklatency

IDE Setup

Zed MCP Security

Zed MCP security guide. Install Pipelock to scan every context_server tool call in Zed stable, Zed Preview, and Flatpak Zed.

intro zedmcpsetup

Operator

License Setup

Pipelock license setup guide. Install your Pro or Founding Pro token, verify it loaded, and start using premium features.

intro licenseinstallpro

MCP Security

MCP Runtime Security

MCP runtime security covers live-traffic defenses pre-deploy scanners miss: tool poisoning in responses, rug-pull drift, chain attacks, fail-closed.

deep mcpruntimesecurity

MCP Security

MCP Vulnerability Scanner

MCP vulnerability scanner comparison covering pre-deploy and runtime tools for Model Context Protocol server security, OSS and commercial.

deep mcpsecurityscanner

Compliance

AI Agent Regulatory Controls

How Pipelock evidence maps to AI agent regulatory programs: EU AI Act, DORA, NIS2, Colorado AI Act, NIST AI RMF, ISO 42001, SOC 2, OWASP.

ref evidenceregulatoryeu-ai-act

Evidence

Verify Agent Actions

Live demo for AI coding agents: Pipelock blocks a malicious MCP response and emits an Ed25519-signed action receipt verified offline.

intro evidencereceiptsmcp

Operator

Agent Egress Control

Pipelock Agent Egress Control GitHub Action setup guide. Kernel-enforced containment, signed Audit Packets, pinning options, offline receipt verification.

intro github-actionciaudit-packet

Compliance

Compliance Evidence Substrate

Pipelock as evidence substrate: EU AI Act Article 12 and NIST AI RMF mapped to signed action receipts, scanner verdicts, and audit packets.

ref evidenceeu-ai-actnist-ai-rmf

MCP Security

Skill Supply Chain Security

Skill supply chain security for SKILL.md poisoning: where Pipelock scans, what v2.5 catches, and what egress controls stop.

deep skillssupply-chainmcp

Concepts

Cloudflare AI Gateway

Cloudflare AI Gateway runs LLM API traffic through Cloudflare's edge with caching, rate limiting, Guardrails, and DLP. What it does and does not.

deep cloudflareai-gatewayllm-gateway

Operator

Block Reason Headers

Pipelock v2.4 X-Pipelock-Block-Reason header reference: vocabulary, severity, retry hints, transports, and agent integration patterns.

ref block-reasonhttp-headersmcp

Operator

Health Watchdog

Pipelock v2.4 health watchdog reference: the /health endpoint, subsystem map, hybrid passive plus active probe, and Kubernetes liveness pattern.

ref healthlivenesskubernetes

Operator

Learn-and-Lock

Learn-and-lock turns observed AI agent traffic into signed Pipelock contracts, then tests them in shadow mode before enforcement.

deep learn-and-lockcontractsagent-firewall

Operator

Pipelock v2.4 Upgrade

Pipelock v2.4 upgrade guide: learn-and-lock rollout, block reason headers, inbound envelope verification, Gemini redaction, and health checks.

ref releaseupgradev2.4

Concepts

AI Agent Security Categories

A buyer's map of the six AI agent security categories. What each one controls, what each one misses, and how they stack.

deep agent-securityai-agent-securitymarket-map

IDE Setup

Claude Code Secret Exfiltration

How Claude Code can leak credentials through tool calls, MCP servers, and shell, plus the runtime defenses that catch each path before traffic leaves.

deep claude-codeexfiltrationdlp

Concepts

Preventing SSRF in AI Agents

SSRF against AI agents: cloud metadata, private CIDRs, DNS rebinding, encoded IPs, parser-differential gaps, and defenses that work.

deep ssrfegresscloud-metadata

Operator

Self-Hosted Sure + Pipelock

Self-hosted Sure guide for enabling Pipelock in Helm, gating external AI assistant egress, and validating the chart guard.

deep surehelmkubernetes

Compliance

Agent Evidence Integration

Pipelock action receipts integrate with SIEM, audit, and LLM detection pipelines. Tamper-evident JSONL, hash-chained, Ed25519-signed.

deep evidencesiemreceipts

Operator

AI Agent Data Redaction

Pipelock redacts AI agent secrets in flight using class-preserving placeholders across Anthropic, OpenAI, Gemini, and custom JSON providers.

deep dlpredactionsecrets

Operator

Pipelock v2.3 Upgrade

Pipelock v2.3 upgrade guide: drop-in upgrade from v2.2.x, plus how to enable class-preserving redaction and generic SSE streaming scanning.

ref releaseupgradev2.3

Operator

SSE Streaming Response Scanning

Pipelock v2.3.0 streams every SSE response with per-event DLP and prompt injection scanning. OpenAI, Anthropic, Kilo Gateway, any LLM SSE.

deep ssestreamingscanner

Concepts

LLM Security

LLM security covers prompt injection, data leaks, tool poisoning, and agent runtime attacks. Practitioner guide to threats and where defenses fit.

deep llmthreatsdefense

Concepts

AI Agent Data Loss Prevention

AI agent DLP guide: where agents leak credentials and PII, what catches it at the network layer, and the open-source self-hosted approach.

deep dlppatternsdata-loss

Prompt Injection

Chatbot Security

Chatbot security guide: credential leaks, prompt injection, jailbreaks, oversharing, and the network-layer controls that catch what the model misses.

intro chatbotexplainer

MCP Security

What Is MCP?

Plain-language guide to Model Context Protocol (MCP): what it is, who built it, how it works, and how it differs from function calling and RAG.

intro mcpexplainer

Operator

Mediation Envelope

Pipelock mediation envelope guide: RFC 9421 signing, inbound verification, SPIFFE actors, and the well-known directory for cross-org federation.

deep signingrfc9421ed25519

Operator

Pipelock K8s Companion Proxy

Pipelock Kubernetes companion proxy guide: generate an enforced proxy Deployment, Service, NetworkPolicies, and bound identity from a workload manifest.

deep kubernetesproxytopology

Operator

Pipelock Posture Verify

Pipelock posture verify guide: validate signed posture capsules, enforce policy thresholds, and use exit codes separating integrity from policy failures.

ref postureciverify

Operator

Pipelock Session Recovery

Pipelock session recovery guide: use inspect, explain, release, terminate, and recover to handle airlocked sessions without guessing at proxy state.

ref sessionsrecoveryops

Operator

Pipelock v2.2 Upgrade

Pipelock v2.2 upgrade guide: strict YAML validation, rollout checks, and the operator steps to verify config before you cut traffic over.

ref releaseupgradev2.2

Concepts

AI Runtime Security

AI runtime security covers model, agent, and infrastructure threats at execution time: prompt injection, tool misuse, egress exfiltration, and defenses.

deep runtimethreatslayers

Concepts

Generative AI Firewall

Generative AI firewall guide to prompt filtering, output scanning, agent egress control, vendors, and where open-source tools fit.

ref firewallvendorscomparison

Concepts

Cloudflare Sandboxes + Pipelock

Cloudflare Sandboxes provides agent isolation and domain filtering. Pipelock adds content scanning for credentials, injection, and tool poisoning.

deep cloudflaresandboxeslayered

Compliance

Mythos-Ready Playbook

CSA/SANS/OWASP Mythos-Ready playbook mapped to runtime controls: egress filtering, agent containment, and machine-speed response.

deep playbookcsasans

MCP Security

MCP Authorization

MCP authorization controls which agents access which tools. Covers OAuth 2.1, scopes, tool-level RBAC, confused deputy, and audit patterns.

deep mcpoauthrbac

Compliance

OWASP MCP Top 10

OWASP MCP Top 10 (MCP01:2025-MCP10:2025): each risk category explained with the scanner, gateway, inspection, and audit controls that stop it.

ref owaspmcpOWASP-MCP

MCP Security

Shadow MCP

Shadow MCP is the unauthorized MCP connectivity hiding in your codebase. How to find rogue MCP servers, score the risk, and enforce policy at runtime.

deep mcpshadow-itdetection

Concepts

Agent Security Best Practices

AI agent security best practices start with least privilege, network isolation, and runtime inspection. Use this checklist to lock down your agents.

intro best-practiceschecklist

Concepts

Agent Security Tools

AI agent security tools range from static scanners to runtime firewalls. Compare what each layer catches and pick the right stack for your agents.

ref toolscomparison

Compliance

AI Agent Compliance

AI agent compliance needs audit logs, runtime policy controls, and signed evidence. Map agent behavior to SOC 2, EU AI Act, and OWASP frameworks.

deep compliancesoc2nist

Concepts

AI Egress Proxy

An AI egress proxy routes all agent traffic through one control point. Inspect HTTP and MCP requests, block data leaks, and enforce network policy.

intro proxyegressexplainer

MCP Security

MCP Gateway: Open Source Security Comparison

MCP gateway guide comparing open source and commercial options, routing, auth, content inspection, proxy differences, and security controls.

ref mcpgateway

MCP Security

MCP Security Tools

MCP security tools help you scan servers, inspect traffic, block tool poisoning, and control access. Compare the main options and their trade-offs.

ref mcptoolscomparison

Concepts

Open Source AI Firewall

Open source AI firewall comparison for self-hosted agent security: Pipelock, LlamaFirewall, MCP gateways, guardrails, and runtime controls.

intro firewallopen-source

Concepts

Secure Agent Deployment

Secure AI agent deployment starts before launch. Isolate credentials, restrict network access, inspect tool traffic, and log every decision.

deep deploymentthreat-modelingkill-switch

Operator

Action Receipt Spec

Pipelock signed receipt formats: Ed25519 ActionReceipt v1 for proxy decisions, plus EvidenceReceipt v2 for v2.4 contract lifecycle and shadow evidence.

ref receiptsed25519spec

Concepts

AI Agent Security

AI agent security explained in three layers: agent-side hooks, inference guardrails, and egress inspection. What each layer catches and what it misses.

intro agent-securitylayersexplainer

Prompt Injection

LLM Prompt Injection

LLM prompt injection explained. How attackers hijack AI agents through malicious text in tool responses, web pages, and MCP servers. Defenses included.

intro injectionllmexplainer

MCP Security

MCP Proxy

An MCP proxy sits between agents and servers, inspecting tool descriptions, arguments, and responses for injection, credentials, and rug-pulls.

ref mcpproxyscanner

MCP Security

MCP Tool Poisoning Defense

MCP tool poisoning hides malicious instructions in tool metadata. Catch rug-pulls and block unsafe tool changes at runtime with proxy-layer defense.

deep mcptool-poisoningruntime

MCP Security

MCP Vulnerabilities

MCP vulnerabilities mapped: tool poisoning, rug-pulls, credential theft, SSRF, prompt injection, session hijacking. Runtime defenses for each risk.

deep mcpssrfcredentials

Prompt Injection

Prompt Injection Detection

Prompt injection detection techniques for AI agents. Pattern matching, ML classifiers, normalization pipelines, and how to combine detection layers.

deep injectiondetectionml

MCP Security

MCP Server Security

MCP server security starts with auth, tool controls, and runtime inspection. Seven common attacks and the defenses that stop each one.

deep mcptutorialconfig

Compliance

AI Compliance Evidence

AI compliance evidence from Pipelock. Maps runtime controls to five frameworks and generates signed bundles. SARIF integrates with GitHub Code Scanning.

ref evidenceframeworks

Operator

Canary Tokens

Canary tokens for AI agent security. Plant synthetic secrets in Pipelock that trigger alerts when an agent attempts to exfiltrate them.

intro canarydetectioncredentials

Operator

Flight Recorder

AI agent audit log with hash-chained, tamper-evident entries. Pipelock's flight recorder writes DLP-redacted JSONL with Ed25519 signed checkpoints.

ref audithash-chained25519

IDE Setup

JetBrains MCP Security

JetBrains MCP security guide. Install Pipelock to scan MCP connections in IntelliJ IDEA, PyCharm, WebStorm, GoLand, and Junie agents.

intro jetbrainsjuniesetup

Compliance

OWASP AIVSS Coverage

Pipelock maps controls to all 10 OWASP AIVSS agentic AI risk categories, supporting assessments that reduce vulnerability scores by up to 33%.

ref owaspaivssOWASP-AIVSS

Operator

Pipelock Detection Rules

Pipelock detection rules from the community. 28 signed rules covering DLP patterns, MCP tool poisoning, and prompt injection scanning.

intro ruleshot-reloaddetection

Compliance

SlowMist Coverage

Pipelock covers 10 of 19 SlowMist MCP security test cases fully, 8 partially, with 1 out of scope. Full item-by-item breakdown.

ref slowmistmcpcoverage

IDE Setup

VS Code MCP Security

VS Code MCP security guide. Install Pipelock to scan MCP server traffic for credential leaks, prompt injection, and tool poisoning before execution.

intro vscodemcpsetup

IDE Setup

Claude Code Hooks

Install Pipelock hooks for Claude Code in one command. Scans Bash, WebFetch, Write, Edit, and MCP tool calls for credential leaks and injection.

intro claude-codehookssetup

Compliance

OWASP Agentic AI Threats: Coverage

Pipelock covers 12 of 15 OWASP Agentic AI threats including memory poisoning, tool misuse, privilege compromise, and rogue agents. Full coverage mapping.

ref owaspagenticthreats

Compliance

OWASP Agentic Top 10: Coverage

Pipelock coverage for all 10 risks in the OWASP Top 10 for Agentic Applications 2026 (ASI01-ASI10), with per-threat assessment.

ref owaspagenticOWASP-AGENTIC

Compliance

OWASP LLM Top 10: Coverage

Pipelock covers 7 of 10 OWASP LLM Top 10 threats at the network layer: prompt injection, sensitive info disclosure, excessive agency, and supply chain.

ref owaspllmOWASP-LLM

Compliance

EU AI Act Compliance

EU AI Act compliance for AI agents: Article 26 deployer duties, the 26(6) six-month log retention rule, and the runtime controls that satisfy them.

deep eu-ai-actcompliance

IDE Setup

Cursor AI Security

Cursor AI security guide. Install Pipelock hooks to block credential exfiltration, reverse shells, and dangerous commands before they execute.

intro cursorsetupdlp

Concepts

Agent Egress Security

Agent egress security controls outbound AI agent traffic to stop credential leaks via HTTP, DNS, and MCP. Attack vectors and runtime defenses.

deep egresscredentialsexfiltration

MCP Security

MCP Security

MCP security guide to risks, best practices, OWASP controls, tool poisoning, secret leaks, SSRF, runtime defenses, and audit.

deep mcpowaspoverview

Prompt Injection

Prompt Injection Prevention

Prompt injection prevention beyond the model layer. Network scanning catches injection in HTTP and MCP traffic before it reaches the AI agent.

deep injectionnormalizationproxy

Ready to protect your own setup?