AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

Mcpwall

mcp-itaromi-mcpwall · by Itaromi

A local application firewall for coding agents. Little Snitch, but for AI agent tool calls.

No reviews yet
0 installs
29 views
0.0% view→install

Install

$ agentstack add mcp-itaromi-mcpwall

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-itaromi-mcpwall)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Mcpwall? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

mcpwall

"My client already asks me for permission, why would I need this?" Because your client's permissions are at the tool level and disappear under auto-accept. mcpwall filters at the level of argument contents, keeps an audit trail across sessions, and covers third-party servers you already approved, once and for all.

A local application firewall for coding agents. Little Snitch, but for AI agent tool calls.


The problem

You run your agent in auto-accept. A GitHub issue, a web page or an email contains a prompt injection. The agent reads a local secret, then tries to send it to a network tool. All your client sees is a sequence of already-authorised tool calls.

mcpwall sits between MCP clients and MCP servers, journals all JSON-RPC traffic, and blocks according to a local policy.

Coverage — what mcpwall sees, and what it does not

Being honest about coverage is a credibility argument.

| | Covered | | --- | --- | | MCP servers over stdio | yes | | MCP servers over streamable HTTP | planned (M3) | | Claude Code built-in tools (Read, Edit, Bash, WebFetch) | via PreToolUse hook (M3) | | Codex built-in tools | no — its security model goes through the sandbox | | Cursor | MCP traffic only |

An MCP proxy only sees MCP traffic. For Claude Code, the built-in tools are most of the attack surface: covering them is the hook's job, not the proxy's.

Status

Milestones M0, M1 and M2 are done: stdio relay, journal, policy daemon, init/restore, and the macOS application — menu bar, decision panel, journal window, graphical install.

There is no distributable build yet. The .dmg is neither signed nor notarised, so Gatekeeper forces a right click → Open. Sparkle is not wired up. See [SPEC.md](SPEC.md) §10 for what remains, and for the architecture and the decisions taken with their reasons.

Build and try it

# The application, with the core embedded
./scripts/build-app.sh
open build/mcpwall.app

The app starts the daemon, creates the symlink to the binary, and offers to install itself into your MCP clients on first launch — showing the diff of what will change, before writing anything.

From the command line alone, with no interface:

cargo build --release

# 1. the daemon, which writes a default policy on first launch
./target/release/mcpwall daemon &

# 2. see what init would do to your configurations — nothing is written without --apply
./target/release/mcpwall init

# 3. apply it, then restart your MCP clients
./target/release/mcpwall init --apply

# 4. watch the traffic go by
./target/release/mcpwall log --follow
./target/release/mcpwall log --stats

mcpwall restore puts every configuration back from the backups.

The policy lives in ~/.mcpwall/policy.yaml and hot-reloads. By default it lets everything through except access to secret paths and credentials spotted in arguments.

Without the application, an ask rule blocks instead of asking: there is nobody there to confirm. The message returned to the agent says so explicitly.

Principles

  • Local-first. No telemetry, no account, no outbound request other than the

update check.

  • Deterministic. No LLM analysis of calls. The policy is a readable file.
  • Available by default. If the daemon is unreachable, traffic goes through.

Breaking every one of the user's MCP servers because an app was closed is a defect, not a security posture.

  • Unobtrusive. Only high-confidence rules interrupt. Alert fatigue is what

kills this kind of tool.

Development

cargo test                                    # 167 tests
cargo clippy --workspace --all-targets -- -D warnings
cargo fmt --check
cargo test --release --test bench -- --nocapture   # latency, 5 ms p99 threshold

cd app && swift build                         # the application

The app's universal build requires Xcode; with the Command Line Tools alone, scripts/build-app.sh degrades to the native architecture and warns you. CI checks that the published binaries really are universal.

Licence

MIT.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.