AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

Wardline

mcp-kabirnarang39-wardline · by kabirnarang39

Open source control-plane proxy for AI agents: identity, policy, budget, audit for MCP and beyond

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add mcp-kabirnarang39-wardline

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-kabirnarang39-wardline)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
yesterday

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Wardline? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

The control-plane proxy that auto-blocks compromised AI agents — in one static Go binary.

[](https://github.com/kabirnarang39/wardline/actions/workflows/ci.yml) [](https://github.com/kabirnarang39/wardline/releases) [](go.mod) [](https://pkg.go.dev/github.com/kabirnarang39/wardline) [](https://kabirnarang39.github.io/wardline/docs/) [](https://deepwiki.com/kabirnarang39/wardline) [](LICENSE) [](CONTRIBUTING.md) [](https://github.com/kabirnarang39/wardline/stargazers)


Wardline is an open-source proxy that sits between your AI agents and everything they call (MCP servers, tools, gRPC upstreams) and enforces identity, policy, budget, and audit — with statistical anomaly detection that blocks a compromised agent in real time, no rule written for the attack and no human in the loop. One static Go binary; no database, IdP, or sidecar to start.

make demo   # spins up a mock MCP server + Wardline and runs the scenario above

The same run in the built-in read-only dashboard — the block, the anomaly that triggered it, and the policy behind it:

How it works

Any caller — an AI agent, a CLI/IDE, or an app — reaches its MCP/gRPC upstreams only through Wardline, which applies identity, policy, budget, and anomaly detection in-process and writes every decision to the audit trail.

Full design: Architecture.

Key Features

  • Real-time anomaly auto-block

Four self-baselining heuristics (rate spike, novel tool, deny-rate spike, and a combined ml_score z-score via Welford's algorithm — no training data, no external model) that don't just alert: auto_block rejects a flagged identity's calls for a bounded TTL. Enforcement, not a log line.

  • Three policy backends, one binary

Static YAML, embedded OPA/Rego, and embedded AWS Cedar — switched by a single policy_backend config key, with no external process and no network hop.

  • Identity & access

Short-lived RS256 JWT issuance with refresh tokens and JWKS rotation, OIDC / mTLS-SPIFFE bootstrap, Kubernetes-style RBAC, SCIM 2.0 provisioning, and end-to-end tenant isolation.

  • Budget & rate control

Two-tier per-identity and per-tenant rate limits — both must clear for a call to proceed.

  • Compliance & audit

Structured JSON audit trail, wardline export-evidence (checksummed, RSA-signable bundle for an auditor), configurable retention, and wardline infer-policy to generate a starter allow-list from observed traffic.

  • Federation & observability

Cross-instance correlation over signed, pseudonymized anomaly summaries; OpenTelemetry tracing; a live web dashboard; and HA multi-replica deployment with shared state over Postgres.

Getting Started

# From source (always works)
go build -o wardline ./cmd/wardline

# Or pull the published multi-arch image (built for each tagged release)
docker pull ghcr.io/kabirnarang39/wardline:latest
./wardline validate-policy --file policy.yaml.example
./wardline validate-config --config wardline.yaml.example
./wardline serve --config wardline.yaml.example

Point upstream at a real MCP server (a proxied call 502s until you do — for a quick test, python3 -m http.server 9000). Every request carries an X-Wardline-Identity header; policy matches on that value plus the MCP tool name:

curl -X POST http://localhost:8080 \
  -H "X-Wardline-Identity: agent-abc123" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","method":"tools/call","params":{"name":"read_file"}}'

Prebuilt binaries (linux/darwin/windows · amd64/arm64) and multi-arch images ship on every v* tag via Releases and GHCR.

Documentation

Full docs, per-feature design notes, and honest known-limitations live on the docs site:

  • Getting Started — install, quickstart, configuration
  • Concepts — architecture, policy backends, identity, audit
  • Features — every capability in depth
  • Deployment — Docker, Helm, HA, observability
  • [Framework integrations](docs/integrations/) — LangChain, LlamaIndex, OpenAI Agents SDK, CrewAI, raw MCP

Full capability list

Everything below is shipped and testable under [internal/features/](internal/features/). The v0.1 baseline (proxy + policy + audit) is always on; everything else is gated by a config flag.

| Capability | Docs | |---|---| | Policy backends — YAML · OPA/Rego · AWS Cedar | Policy backends | | Anomaly detection + auto-block | Anomaly detection | | Budget enforcement (per-identity + per-tenant) | Budget | | Credential issuance (JWT + refresh + JWKS) | Credentials | | SSO (OIDC) / mTLS-SPIFFE bootstrap | SSO · mTLS | | RBAC + SCIM + tenancy | RBAC · SCIM | | Federation (cross-instance correlation) | Federation | | Compliance evidence export + retention | Compliance | | Auto-generated sandbox policy | infer-policy | | Policy packs (12 embedded + -packs-dir) | Policy packs | | gRPC transport passthrough | gRPC | | Postgres storage + HA deployment | HA | | Web dashboard | Dashboard | | OpenTelemetry tracing | Observability | | Taint tracking (untrusted-read gating) | Taint tracking | | Approval workflow (needsapproval + approve-and-retry) | Approval workflow | | Per-job budget ceiling (hard cap per tenant/identity/session job) | Per-job budget ceiling |

Performance

Reproducible with go test -bench, not marketing numbers. BenchmarkDecider_Decide (default YAML backend, Apple Silicon): ~33 ns / 0 allocations at 10 rules, ~2.4 µs at 1000 rules. The ml_score false-positive claim is regression-guarded by TestDetector_MLScore_FalsePositiveRateOnSteadyTraffic (asserts 0% false positives on steady traffic, budget

License

[Apache 2.0](LICENSE).

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.