Install
$ agentstack add mcp-kabirnarang39-wardline ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
The control-plane proxy that auto-blocks compromised AI agents — in one static Go binary.
[](https://github.com/kabirnarang39/wardline/actions/workflows/ci.yml) [](https://github.com/kabirnarang39/wardline/releases) [](go.mod) [](https://pkg.go.dev/github.com/kabirnarang39/wardline) [](https://kabirnarang39.github.io/wardline/docs/) [](https://deepwiki.com/kabirnarang39/wardline) [](LICENSE) [](CONTRIBUTING.md) [](https://github.com/kabirnarang39/wardline/stargazers)
Wardline is an open-source proxy that sits between your AI agents and everything they call (MCP servers, tools, gRPC upstreams) and enforces identity, policy, budget, and audit — with statistical anomaly detection that blocks a compromised agent in real time, no rule written for the attack and no human in the loop. One static Go binary; no database, IdP, or sidecar to start.
make demo # spins up a mock MCP server + Wardline and runs the scenario above
The same run in the built-in read-only dashboard — the block, the anomaly that triggered it, and the policy behind it:
How it works
Any caller — an AI agent, a CLI/IDE, or an app — reaches its MCP/gRPC upstreams only through Wardline, which applies identity, policy, budget, and anomaly detection in-process and writes every decision to the audit trail.
Full design: Architecture.
Key Features
- Real-time anomaly auto-block
Four self-baselining heuristics (rate spike, novel tool, deny-rate spike, and a combined ml_score z-score via Welford's algorithm — no training data, no external model) that don't just alert: auto_block rejects a flagged identity's calls for a bounded TTL. Enforcement, not a log line.
- Three policy backends, one binary
Static YAML, embedded OPA/Rego, and embedded AWS Cedar — switched by a single policy_backend config key, with no external process and no network hop.
- Identity & access
Short-lived RS256 JWT issuance with refresh tokens and JWKS rotation, OIDC / mTLS-SPIFFE bootstrap, Kubernetes-style RBAC, SCIM 2.0 provisioning, and end-to-end tenant isolation.
- Budget & rate control
Two-tier per-identity and per-tenant rate limits — both must clear for a call to proceed.
- Compliance & audit
Structured JSON audit trail, wardline export-evidence (checksummed, RSA-signable bundle for an auditor), configurable retention, and wardline infer-policy to generate a starter allow-list from observed traffic.
- Federation & observability
Cross-instance correlation over signed, pseudonymized anomaly summaries; OpenTelemetry tracing; a live web dashboard; and HA multi-replica deployment with shared state over Postgres.
Getting Started
# From source (always works)
go build -o wardline ./cmd/wardline
# Or pull the published multi-arch image (built for each tagged release)
docker pull ghcr.io/kabirnarang39/wardline:latest
./wardline validate-policy --file policy.yaml.example
./wardline validate-config --config wardline.yaml.example
./wardline serve --config wardline.yaml.example
Point upstream at a real MCP server (a proxied call 502s until you do — for a quick test, python3 -m http.server 9000). Every request carries an X-Wardline-Identity header; policy matches on that value plus the MCP tool name:
curl -X POST http://localhost:8080 \
-H "X-Wardline-Identity: agent-abc123" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"tools/call","params":{"name":"read_file"}}'
Prebuilt binaries (linux/darwin/windows · amd64/arm64) and multi-arch images ship on every v* tag via Releases and GHCR.
Documentation
Full docs, per-feature design notes, and honest known-limitations live on the docs site:
- Getting Started — install, quickstart, configuration
- Concepts — architecture, policy backends, identity, audit
- Features — every capability in depth
- Deployment — Docker, Helm, HA, observability
- [Framework integrations](docs/integrations/) — LangChain, LlamaIndex, OpenAI Agents SDK, CrewAI, raw MCP
Full capability list
Everything below is shipped and testable under [internal/features/](internal/features/). The v0.1 baseline (proxy + policy + audit) is always on; everything else is gated by a config flag.
| Capability | Docs | |---|---| | Policy backends — YAML · OPA/Rego · AWS Cedar | Policy backends | | Anomaly detection + auto-block | Anomaly detection | | Budget enforcement (per-identity + per-tenant) | Budget | | Credential issuance (JWT + refresh + JWKS) | Credentials | | SSO (OIDC) / mTLS-SPIFFE bootstrap | SSO · mTLS | | RBAC + SCIM + tenancy | RBAC · SCIM | | Federation (cross-instance correlation) | Federation | | Compliance evidence export + retention | Compliance | | Auto-generated sandbox policy | infer-policy | | Policy packs (12 embedded + -packs-dir) | Policy packs | | gRPC transport passthrough | gRPC | | Postgres storage + HA deployment | HA | | Web dashboard | Dashboard | | OpenTelemetry tracing | Observability | | Taint tracking (untrusted-read gating) | Taint tracking | | Approval workflow (needsapproval + approve-and-retry) | Approval workflow | | Per-job budget ceiling (hard cap per tenant/identity/session job) | Per-job budget ceiling |
Performance
Reproducible with go test -bench, not marketing numbers. BenchmarkDecider_Decide (default YAML backend, Apple Silicon): ~33 ns / 0 allocations at 10 rules, ~2.4 µs at 1000 rules. The ml_score false-positive claim is regression-guarded by TestDetector_MLScore_FalsePositiveRateOnSteadyTraffic (asserts 0% false positives on steady traffic, budget
License
[Apache 2.0](LICENSE).
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kabirnarang39
- Source: kabirnarang39/wardline
- License: Apache-2.0
- Homepage: https://kabirnarang39.github.io/wardline/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.