StackMap
Subscribe
Explore / pipelock
luckyPipewrench

pipelock

Agent egress firewall in Go: an inline proxy scanning HTTP, MCP, A2A and WebSocket traffic for secret exfiltration, SSRF and prompt injection, with signed action receipts you verify offline.

912 104 Go Apache-2.0updated yesterday
View on GitHubDispute this mapping →
Curator's take

Put pipelock in front of any agent that holds credentials and can reach the network: it scans requests before they leave (65 DLP patterns, run before DNS so secrets can't leak through lookups), scans responses for injection, wraps MCP servers with `pipelock mcp proxy`, and writes hash-chained, signed receipts you can verify offline. It is unusually candid about its limits — read them. It only sees traffic routed through it, so pair it with enforced egress (network policy, a sandbox, or its own Landlock/netns containment) or an agent can simply go around it; without TLS interception, CONNECT traffic is checked only at hostname/URL level. Open-core: the Apache-2.0 core is the proxy; the fleet dashboard and Conductor are ELv2 and license-gated. Not a model guardrail — for prompt/output rails use nemo-guardrails.

Mapped by ShipWithAI editors · links verified

Continue your stack

What teams reach for next — and why each earns a place beside pipelock. Ranked by curator confidence.

pairs wellpairs wellpairs wellpairs wellpairs wellpairs wellephemora-cellfenceAdrianagent-sandboxmcp-context-forgeclaude-secretspipelock
pairs wellalternativebuilt withpick a node for the why · open it from the panel
Weekly digest
README.md1 min read

Pipelock

Open-source AI agent firewall for Verifiable Egress Control.

CI Security Gauntlet exam Go 1.26+ Release

OpenSSF Scorecard OpenSSF Best Practices codecov pipelock self-scanned

Core Apache 2.0 Enterprise ELv2 CNCF Landscape: Security & Compliance Discord

Pipelock blocking a live secret-exfiltration attempt from an AI agent

Pipelock sits between AI agents and the network. It inspects mediated HTTP, WebSocket, MCP, and A2A traffic, plus CONNECT tunnel contents when TLS interception is enabled, for secret exfiltration, prompt injection, SSRF, tool poisoning, and risky tool-call chains. Plain CONNECT without interception is scanned at the hostname and URL level. Configured MCP upstreams are an exception to private-address SSRF blocking: local/private servers are allowed, but cloud metadata endpoints r