[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:pipelock":3},"\u003Ch1>\n  \u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FluckyPipewrench\u002Fpipelock\u002FHEAD\u002Fassets\u002Fpipelock-lockup.svg\" alt=\"Pipelock\" width=\"465\" \u002F>\n\u003C\u002Fh1>\u003Cp align=\"center\">\n  \u003Cstrong>Open-source AI agent firewall for \u003Ca href=\"https:\u002F\u002Fpipelab.org\u002Flearn\u002Fverifiable-egress-control\u002F\" rel=\"nofollow ugc noopener\">Verifiable Egress Control\u003C\u002Fa>.\u003C\u002Fstrong>\n\u003C\u002Fp>\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fci.yaml\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"CI\" src=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fci.yaml\u002Fbadge.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fsecurity.yaml\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Security\" src=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fsecurity.yaml\u002Fbadge.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fcontinuous-gauntlet.yaml\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Gauntlet exam\" src=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Factions\u002Fworkflows\u002Fcontinuous-gauntlet.yaml\u002Fbadge.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Fblob\u002FHEAD\u002Fgo.mod\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Go 1.26+\" src=\"https:\u002F\u002Fimg.shields.io\u002Fgithub\u002Fgo-mod\u002Fgo-version\u002FluckyPipewrench\u002Fpipelock?logo=go&amp;label=Go\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Freleases\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Release\" src=\"https:\u002F\u002Fimg.shields.io\u002Fgithub\u002Fv\u002Frelease\u002FluckyPipewrench\u002Fpipelock\" \u002F>\u003C\u002Fa>\n\u003C\u002Fp>\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fscorecard.dev\u002Fviewer\u002F?uri=github.com\u002FluckyPipewrench\u002Fpipelock\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"OpenSSF Scorecard\" src=\"https:\u002F\u002Fapi.scorecard.dev\u002Fprojects\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Fbadge\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fwww.bestpractices.dev\u002Fprojects\u002F11948\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"OpenSSF Best Practices\" src=\"https:\u002F\u002Fwww.bestpractices.dev\u002Fprojects\u002F11948\u002Fbadge\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fcodecov.io\u002Fgh\u002FluckyPipewrench\u002Fpipelock\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"codecov\" src=\"https:\u002F\u002Fcodecov.io\u002Fgh\u002FluckyPipewrench\u002Fpipelock\u002Fgraph\u002Fbadge.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Fblob\u002Fmain\u002F.github\u002Fworkflows\u002Fci.yaml#L21-L35\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"pipelock self-scanned\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fpipelock-self--scanned-00FFC8?style=flat&amp;labelColor=1A1A2E&amp;logo=data:image\u002Fsvg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAxNCAxNCI+PHBhdGggZmlsbD0iIzAwRkZDOCIgZmlsbC1ydWxlPSJldmVub2RkIiBjbGlwLXJ1bGU9ImV2ZW5vZGQiIGQ9Ik03IDAuNWMtMS45MyAwLTMuNSAxLjY2LTMuNSAzLjd2MS4zSDNjLS44MyAwLTEuNSAuNjctMS41IDEuNXY2YzAgLjgzLjY3IDEuNSAxLjUgMS41aDhjLjgzIDAgMS41LS42NyAxLjUtMS41VjdjMC0uODMtLjY3LTEuNS0xLjUtMS41aC0uNVY0LjJjMC0yLjA0LTEuNTctMy43LTMuNS0zLjdabS0yIDVWNC4yYzAtMS40OSAxLjEyLTIuNyAyLjUtMi43czIuNSAxLjIxIDIuNSAyLjd2MS4zSDVaTTIuNSA1aDJ2MS4yaC0yVjVabTcgMGgydjEuMmgtMlY1Wk03IDguMmMtLjY5IDAtMS4yNS41Ni0xLjI1IDEuMjUgMCAuNDQuMjMuODMuNTcgMS4wNXYxLjVoMS4zNnYtMS41Yy4zNC0uMjIuNTctLjYxLjU3LTEuMDUgMC0uNjktLjU2LTEuMjUtMS4yNS0xLjI1WiIvPjwvc3ZnPgo=\" \u002F>\u003C\u002Fa>\n\u003C\u002Fp>\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Fblob\u002FHEAD\u002FLICENSE\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Core Apache 2.0\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FCore-Apache_2.0-blue.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FluckyPipewrench\u002Fpipelock\u002Fblob\u002FHEAD\u002Fenterprise\u002FLICENSE\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Enterprise ELv2\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FEnterprise-ELv2-orange.svg\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Flandscape.cncf.io\u002F?item=provisioning--security-compliance--pipelock\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"CNCF Landscape: Security &amp; Compliance\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FCNCF%20Landscape-Security%20%26%20Compliance-1a73e8?logo=cncf&amp;logoColor=white\" \u002F>\u003C\u002Fa>\n  \u003Ca href=\"https:\u002F\u002Fdiscord.gg\u002FbadNfhGKTc\" rel=\"nofollow ugc noopener\">\u003Cimg alt=\"Discord\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002FDiscord-Join%20the%20community-5865F2?logo=discord&amp;logoColor=white\" \u002F>\u003C\u002Fa>\n\u003C\u002Fp>\u003Cdiv align=\"center\">\n  \u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002FluckyPipewrench\u002Fpipelock\u002FHEAD\u002Fassets\u002Fdemo.gif\" alt=\"Pipelock blocking a live secret-exfiltration attempt from an AI agent\" width=\"900\" \u002F>\n\u003C\u002Fdiv>\u003Cp>Pipelock sits between AI agents and the network. It inspects mediated HTTP, WebSocket, MCP, and A2A traffic, plus CONNECT tunnel contents when TLS interception is enabled, for secret exfiltration, prompt injection, SSRF, tool poisoning, and risky tool-call chains. Plain CONNECT without interception is scanned at the hostname and URL level. Configured MCP upstreams are an exception to private-address SSRF blocking: local\u002Fprivate servers are allowed, but cloud metadata endpoints r\u003C\u002Fp>\n",1790587592775]