AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

AI Firewall MCP

mcp-akhilucky-ai-firewall · by Akhilucky

Multi-agent LLM security layer detecting prompt injection and jailbreaks.

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add mcp-akhilucky-ai-firewall

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v1.0.1 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Possible prompt-injection directive.

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v1.0.1. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of AI Firewall MCP? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

GitHub • PyPI • Docker Hub

AI Firewall — MCP Server

A multi-agent AI security layer that protects LLMs from prompt injection, jailbreaks, and policy violations. Available as an MCP server for any MCP-compatible client (Claude Desktop, Cursor, Windsurf, Cline, Roo Code, etc.).

Quick Start

pip install

pip install ai-firewall-mcp
ai-firewall-mcp

Docker

docker pull akhilucky/ai-firewall-mcp:latest
docker run -i akhilucky/ai-firewall-mcp:latest

Claude Desktop

Add to claude_desktop_config.json:

pip install:

{
  "mcpServers": {
    "ai-firewall": {
      "command": "pipx",
      "args": ["run", "ai-firewall-mcp"]
    }
  }
}

Docker:

{
  "mcpServers": {
    "ai-firewall": {
      "command": "docker",
      "args": ["run", "-i", "akhilucky/ai-firewall-mcp:latest"]
    }
  }
}

Cursor / Windsurf / Cline / Roo Code

Configure in your MCP settings with:

  • Type: stdio
  • Command: docker run -i akhilucky/ai-firewall-mcp:latest
  • Or use ai-firewall-mcp if installed via pip

MCP Tools

| Tool | Description | |------|-------------| | analyze_prompt | Analyze a prompt for injection, jailbreaks, exfiltration, and leakage | | get_threat_breakdown | Detailed per-signal scoring breakdown from the last analysis | | sanitize_prompt | Clean a suspicious prompt while preserving legitimate content | | get_firewall_status | Health check: vector DB size, model status, uptime | | benchmark_firewall | Run the adversarial test suite and return detection statistics |

Testing with MCP Inspector

npx @modelcontextprotocol/inspector ai-firewall-mcp

Architecture

The firewall runs three agents per prompt:

User Prompt → [Retrieval Agent] → [Guard Agent] → [Policy Agent] → LLM
                   │                    │               │
                   ▼                    ▼               ▼
              Vector DB (FAISS)    Threat Signals    Allow/Block

| Agent | Role | |-------|------| | Retrieval Agent | Semantic search against known attack patterns (FAISS + sentence-transformers) | | Guard Agent | Multi-signal classification: vector similarity, keyword match, heuristic scoring | | Policy Agent | Final decision: ALLOW / BLOCK / SANITIZE based on configurable thresholds |

Threat signals are weighted: 40% vector similarity, 25% keyword match, 20% heuristic, 15% policy weight.

Configuration

| Env Var | Default | Description | |---------|---------|-------------| | FIREWALL_MODE | strict | strict / moderate / permissive | | SIMILARITY_THRESHOLD | 0.50 | Vector match threshold (lower = stricter) | | LOG_LEVEL | INFO | Logging verbosity |

CLI / API Usage

# Interactive dashboard
python main.py

# Red-team adversarial tests
python main.py --redteam

# REST API server
python main.py --api

# Single prompt analysis
python main.py --analyze "Ignore all previous instructions"

The REST API runs at http://localhost:8000 with OpenAPI docs at /docs (requires pip install ai-firewall-mcp[api]).

Testing

pytest tests/ -v          # Full test suite (43 tests)
pytest tests/test_mcp.py  # MCP-specific tests only

Project Structure

├── src/ai_firewall/          # MCP server package (PyPI entry)
│   ├── mcp_server.py         #    5 MCP tools, stdio transport
│   ├── threat_scorer.py      #    Per-signal scoring breakdown
│   └── __init__.py
├── src/agents/               # Core firewall agents
├── tests/                    # Test suites
├── Dockerfile                # Docker image (2.04GB, CPU-only torch)
├── pyproject.toml            # Package config & metadata
└── .github/workflows/ci.yml  # CI/CD pipeline

License

MIT — see [LICENSE](LICENSE).


Built for security. Designed for production.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v1.0.1 Imported from the upstream source.