Pipelock Guides
Pipelock Guides: IDE Setup and MCP Security
Agent security concepts explained.
Featured
Hand-picked starting points
IDE Setup
Claude Code Hooks
Install Pipelock hooks for Claude Code in one command. Scans Bash, WebFetch, Write, Edit, and MCP tool calls for credential leaks and injection.
Operator
Learn-and-Lock
Learn-and-lock turns observed AI agent traffic into signed Pipelock contracts, then tests them in shadow mode before enforcement.
MCP Security
MCP Security
MCP security guide to risks, best practices, OWASP controls, tool poisoning, secret leaks, SSRF, runtime defenses, and audit.
All guides
94 total. Filter by category or search by title and tag.
Evidence
Agent Evidence Levels
Agent Evidence Levels (AEL) is an open standard grading AI-agent audit evidence from AEL-0 to AEL-4 by what an independent party can verify offline.
Concepts
Agent Firewall vs Guardrails vs Sandbox
Agent firewall, guardrails, and sandbox compared as four security functions: prevention, detection, containment, and evidence. What each does and misses.
IDE Setup
Claude Code Security
Claude Code security beyond built-in review. Add egress inspection, outbound DLP, MCP response scanning, and containment you can verify.
Concepts
Known Limitations
A standing register of what Pipelock does not catch: process-level bypass, non-HTTP exfiltration, covert channels, and semantic prompt injection.
Operator
Progressive Enforcement
Progressive enforcement for AI agents: observe, baseline, shadow, then enforce. Roll out a blocking agent firewall with signed, reversible receipts.
Concepts
What Pipelock Claims and Doesn't
Pipelock never claims non-bypass. It claims deterministic scanning of mediated traffic, containment as deployment guidance, and signed evidence.
Evidence
AARP Claims Dictionary
AARP claims dictionary: verified claims, reserved vocabulary, does_not_assert limits, and overclaim-risk warnings for receipt appraisal.
Evidence
AARP Spec
AARP v0.1 spec: a signed assurance profile over Pipelock receipts. Claim-set by axis, JCS canonicalization, parallel signatures, X.509-SVID identity.
Evidence
AARP: Proves / Does Not
What a verified AARP receipt proves and does not prove. Binary-enforced versus deployment-claimed, and the trust assumptions a relying party must pin.
Operator
Hermes Integration
Bridge Hermes Agent into Pipelock's scanner pipeline with a hook plugin. Install, verify, and roll back the integration with one command each.
Concepts
Redaction Placeholders
Decode AI redaction placeholders like <private_address>, <private_person>, and <pl:aws-access-key:1>: what each token means, what tool emits it, and why.
Operator
Request Policy
Pipelock request policy allows or denies individual outbound API operations: GraphQL mutations, JSON batch sub-requests, and admin calls, not just hosts.
Operator
Pro Reference Deployment
Pipelock Pro reference deployment: per-agent budgets, source-CIDR routing, cross-agent federation, signed receipts. The architecture, not the marketing.
Concepts
Agent Security Tool Profiles
Receipt-scoring profiles for agent security tools: signed, offline-verifiable evidence buyers can reproduce against the public corpus.
Evidence
Agent Action Receipts
Agent action receipts: Ed25519-signed records of AI agent network and tool actions, chained by hash, verifiable offline by any third party.
Comparison
Agent Security Control Layers
Four-layer map of AI agent security: process sandboxing, identity governance, MCP gateway mediation, and egress inspection with signed receipts.
Evidence
Verifiable Egress Control
Verifiable Egress Control combines network-enforced AI agent egress with signed action receipts auditors and procurement teams can verify offline.
Operator
Verify a Receipt
Verify Pipelock Ed25519 action receipts with Go, TypeScript, Rust, or Python verifier CLIs against the public conformance corpus.
Operator
Pipelock v2.5 Upgrade
Pipelock v2.5 upgrade guide: verifier rollout, containment lifecycle, strict federation, MCP integrity, and installer checks.
Operator
Audit Packet Threat Model
Threat model for the Pipelock Audit Packet. Receipt provenance, self-consistent verdicts, signer-key pinning, what verified evidence does not prove.
Operator
Browser Shield
Browser Shield strips extension probes, hidden prompt traps, and tracking beacons from agent-fetched HTML, JavaScript, and SVG. Signed receipts.
IDE Setup
Continue.dev MCP Security
Continue.dev MCP security guide. Wrap each MCP server in Continue's config through pipelock mcp proxy for DLP, injection, and tool-poisoning scanning.
Concepts
Pipelock Performance
Latency, cold-start, and memory overhead numbers for Pipelock across HTTP, SSE, MCP stdio, WebSocket, and tool-call chains. Reproducible.
IDE Setup
Zed MCP Security
Zed MCP security guide. Install Pipelock to scan every context_server tool call in Zed stable, Zed Preview, and Flatpak Zed.
Operator
License Setup
Pipelock license setup guide. Install your Pro or Founding Pro token, verify it loaded, and start using premium features.
MCP Security
MCP Runtime Security
MCP runtime security covers live-traffic defenses pre-deploy scanners miss: tool poisoning in responses, rug-pull drift, chain attacks, fail-closed.
MCP Security
MCP Vulnerability Scanner
MCP vulnerability scanner comparison covering pre-deploy and runtime tools for Model Context Protocol server security, OSS and commercial.
Compliance
AI Agent Regulatory Controls
How Pipelock evidence maps to AI agent regulatory programs: EU AI Act, DORA, NIS2, Colorado AI Act, NIST AI RMF, ISO 42001, SOC 2, OWASP.
Evidence
Verify Agent Actions
Live demo for AI coding agents: Pipelock blocks a malicious MCP response and emits an Ed25519-signed action receipt verified offline.
Operator
Agent Egress Control
Pipelock Agent Egress Control GitHub Action setup guide. Kernel-enforced containment, signed Audit Packets, pinning options, offline receipt verification.
Compliance
Compliance Evidence Substrate
Pipelock as evidence substrate: EU AI Act Article 12 and NIST AI RMF mapped to signed action receipts, scanner verdicts, and audit packets.
MCP Security
Skill Supply Chain Security
Skill supply chain security for SKILL.md poisoning: where Pipelock scans, what v2.5 catches, and what egress controls stop.
Concepts
Cloudflare AI Gateway
Cloudflare AI Gateway runs LLM API traffic through Cloudflare's edge with caching, rate limiting, Guardrails, and DLP. What it does and does not.
Operator
Block Reason Headers
Pipelock v2.4 X-Pipelock-Block-Reason header reference: vocabulary, severity, retry hints, transports, and agent integration patterns.
Operator
Health Watchdog
Pipelock v2.4 health watchdog reference: the /health endpoint, subsystem map, hybrid passive plus active probe, and Kubernetes liveness pattern.
Operator
Learn-and-Lock
Learn-and-lock turns observed AI agent traffic into signed Pipelock contracts, then tests them in shadow mode before enforcement.
Operator
Pipelock v2.4 Upgrade
Pipelock v2.4 upgrade guide: learn-and-lock rollout, block reason headers, inbound envelope verification, Gemini redaction, and health checks.
Concepts
AI Agent Security Categories
A buyer's map of the six AI agent security categories. What each one controls, what each one misses, and how they stack.
IDE Setup
Claude Code Secret Exfiltration
How Claude Code can leak credentials through tool calls, MCP servers, and shell, plus the runtime defenses that catch each path before traffic leaves.
Concepts
Preventing SSRF in AI Agents
SSRF against AI agents: cloud metadata, private CIDRs, DNS rebinding, encoded IPs, parser-differential gaps, and defenses that work.
Operator
Self-Hosted Sure + Pipelock
Self-hosted Sure guide for enabling Pipelock in Helm, gating external AI assistant egress, and validating the chart guard.
Compliance
Agent Evidence Integration
Pipelock action receipts integrate with SIEM, audit, and LLM detection pipelines. Tamper-evident JSONL, hash-chained, Ed25519-signed.
Operator
AI Agent Data Redaction
Pipelock redacts AI agent secrets in flight using class-preserving placeholders across Anthropic, OpenAI, Gemini, and custom JSON providers.
Operator
Pipelock v2.3 Upgrade
Pipelock v2.3 upgrade guide: drop-in upgrade from v2.2.x, plus how to enable class-preserving redaction and generic SSE streaming scanning.
Operator
SSE Streaming Response Scanning
Pipelock v2.3.0 streams every SSE response with per-event DLP and prompt injection scanning. OpenAI, Anthropic, Kilo Gateway, any LLM SSE.
Concepts
LLM Security
LLM security covers prompt injection, data leaks, tool poisoning, and agent runtime attacks. Practitioner guide to threats and where defenses fit.
Concepts
AI Agent Data Loss Prevention
AI agent DLP guide: where agents leak credentials and PII, what catches it at the network layer, and the open-source self-hosted approach.
Prompt Injection
Chatbot Security
Chatbot security guide: credential leaks, prompt injection, jailbreaks, oversharing, and the network-layer controls that catch what the model misses.
MCP Security
What Is MCP?
Plain-language guide to Model Context Protocol (MCP): what it is, who built it, how it works, and how it differs from function calling and RAG.
Operator
Mediation Envelope
Pipelock mediation envelope guide: RFC 9421 signing, inbound verification, SPIFFE actors, and the well-known directory for cross-org federation.
Operator
Pipelock K8s Companion Proxy
Pipelock Kubernetes companion proxy guide: generate an enforced proxy Deployment, Service, NetworkPolicies, and bound identity from a workload manifest.
Operator
Pipelock Posture Verify
Pipelock posture verify guide: validate signed posture capsules, enforce policy thresholds, and use exit codes separating integrity from policy failures.
Operator
Pipelock Session Recovery
Pipelock session recovery guide: use inspect, explain, release, terminate, and recover to handle airlocked sessions without guessing at proxy state.
Operator
Pipelock v2.2 Upgrade
Pipelock v2.2 upgrade guide: strict YAML validation, rollout checks, and the operator steps to verify config before you cut traffic over.
Concepts
AI Runtime Security
AI runtime security covers model, agent, and infrastructure threats at execution time: prompt injection, tool misuse, egress exfiltration, and defenses.
Concepts
Generative AI Firewall
Generative AI firewall guide to prompt filtering, output scanning, agent egress control, vendors, and where open-source tools fit.
Concepts
Cloudflare Sandboxes + Pipelock
Cloudflare Sandboxes provides agent isolation and domain filtering. Pipelock adds content scanning for credentials, injection, and tool poisoning.
Compliance
Mythos-Ready Playbook
CSA/SANS/OWASP Mythos-Ready playbook mapped to runtime controls: egress filtering, agent containment, and machine-speed response.
MCP Security
MCP Authorization
MCP authorization controls which agents access which tools. Covers OAuth 2.1, scopes, tool-level RBAC, confused deputy, and audit patterns.
Compliance
OWASP MCP Top 10
OWASP MCP Top 10 (MCP01:2025-MCP10:2025): each risk category explained with the scanner, gateway, inspection, and audit controls that stop it.
MCP Security
Shadow MCP
Shadow MCP is the unauthorized MCP connectivity hiding in your codebase. How to find rogue MCP servers, score the risk, and enforce policy at runtime.
Concepts
Agent Security Best Practices
AI agent security best practices start with least privilege, network isolation, and runtime inspection. Use this checklist to lock down your agents.
Concepts
Agent Security Tools
AI agent security tools range from static scanners to runtime firewalls. Compare what each layer catches and pick the right stack for your agents.
Compliance
AI Agent Compliance
AI agent compliance needs audit logs, runtime policy controls, and signed evidence. Map agent behavior to SOC 2, EU AI Act, and OWASP frameworks.
Concepts
AI Egress Proxy
An AI egress proxy routes all agent traffic through one control point. Inspect HTTP and MCP requests, block data leaks, and enforce network policy.
MCP Security
MCP Gateway: Open Source Security Comparison
MCP gateway guide comparing open source and commercial options, routing, auth, content inspection, proxy differences, and security controls.
MCP Security
MCP Security Tools
MCP security tools help you scan servers, inspect traffic, block tool poisoning, and control access. Compare the main options and their trade-offs.
Concepts
Open Source AI Firewall
Open source AI firewall comparison for self-hosted agent security: Pipelock, LlamaFirewall, MCP gateways, guardrails, and runtime controls.
Concepts
Secure Agent Deployment
Secure AI agent deployment starts before launch. Isolate credentials, restrict network access, inspect tool traffic, and log every decision.
Operator
Action Receipt Spec
Pipelock signed receipt formats: Ed25519 ActionReceipt v1 for proxy decisions, plus EvidenceReceipt v2 for v2.4 contract lifecycle and shadow evidence.
Concepts
AI Agent Security
AI agent security explained in three layers: agent-side hooks, inference guardrails, and egress inspection. What each layer catches and what it misses.
Prompt Injection
LLM Prompt Injection
LLM prompt injection explained. How attackers hijack AI agents through malicious text in tool responses, web pages, and MCP servers. Defenses included.
MCP Security
MCP Proxy
An MCP proxy sits between agents and servers, inspecting tool descriptions, arguments, and responses for injection, credentials, and rug-pulls.
MCP Security
MCP Tool Poisoning Defense
MCP tool poisoning hides malicious instructions in tool metadata. Catch rug-pulls and block unsafe tool changes at runtime with proxy-layer defense.
MCP Security
MCP Vulnerabilities
MCP vulnerabilities mapped: tool poisoning, rug-pulls, credential theft, SSRF, prompt injection, session hijacking. Runtime defenses for each risk.
Prompt Injection
Prompt Injection Detection
Prompt injection detection techniques for AI agents. Pattern matching, ML classifiers, normalization pipelines, and how to combine detection layers.
MCP Security
MCP Server Security
MCP server security starts with auth, tool controls, and runtime inspection. Seven common attacks and the defenses that stop each one.
Compliance
AI Compliance Evidence
AI compliance evidence from Pipelock. Maps runtime controls to five frameworks and generates signed bundles. SARIF integrates with GitHub Code Scanning.
Operator
Canary Tokens
Canary tokens for AI agent security. Plant synthetic secrets in Pipelock that trigger alerts when an agent attempts to exfiltrate them.
Operator
Flight Recorder
AI agent audit log with hash-chained, tamper-evident entries. Pipelock's flight recorder writes DLP-redacted JSONL with Ed25519 signed checkpoints.
IDE Setup
JetBrains MCP Security
JetBrains MCP security guide. Install Pipelock to scan MCP connections in IntelliJ IDEA, PyCharm, WebStorm, GoLand, and Junie agents.
Compliance
OWASP AIVSS Coverage
Pipelock maps controls to all 10 OWASP AIVSS agentic AI risk categories, supporting assessments that reduce vulnerability scores by up to 33%.
Operator
Pipelock Detection Rules
Pipelock detection rules from the community. 28 signed rules covering DLP patterns, MCP tool poisoning, and prompt injection scanning.
Compliance
SlowMist Coverage
Pipelock covers 10 of 19 SlowMist MCP security test cases fully, 8 partially, with 1 out of scope. Full item-by-item breakdown.
IDE Setup
VS Code MCP Security
VS Code MCP security guide. Install Pipelock to scan MCP server traffic for credential leaks, prompt injection, and tool poisoning before execution.
IDE Setup
Claude Code Hooks
Install Pipelock hooks for Claude Code in one command. Scans Bash, WebFetch, Write, Edit, and MCP tool calls for credential leaks and injection.
Compliance
OWASP Agentic AI Threats: Coverage
Pipelock covers 12 of 15 OWASP Agentic AI threats including memory poisoning, tool misuse, privilege compromise, and rogue agents. Full coverage mapping.
Compliance
OWASP Agentic Top 10: Coverage
Pipelock coverage for all 10 risks in the OWASP Top 10 for Agentic Applications 2026 (ASI01-ASI10), with per-threat assessment.
Compliance
OWASP LLM Top 10: Coverage
Pipelock covers 7 of 10 OWASP LLM Top 10 threats at the network layer: prompt injection, sensitive info disclosure, excessive agency, and supply chain.
Compliance
EU AI Act Compliance
EU AI Act compliance for AI agents: Article 26 deployer duties, the 26(6) six-month log retention rule, and the runtime controls that satisfy them.
IDE Setup
Cursor AI Security
Cursor AI security guide. Install Pipelock hooks to block credential exfiltration, reverse shells, and dangerous commands before they execute.
Concepts
Agent Egress Security
Agent egress security controls outbound AI agent traffic to stop credential leaks via HTTP, DNS, and MCP. Attack vectors and runtime defenses.
MCP Security
MCP Security
MCP security guide to risks, best practices, OWASP controls, tool poisoning, secret leaks, SSRF, runtime defenses, and audit.
Prompt Injection
Prompt Injection Prevention
Prompt injection prevention beyond the model layer. Network scanning catches injection in HTTP and MCP traffic before it reaches the AI agent.
No guides match this filter.
Ready to protect your own setup?