iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
This MCP server acts as “iptables for MCP.” It blocks dangerous tool calls, scans for secret leakage, and logs everything. The package is described as rule-based with “no AI” and “no cloud,” designed to sit between an MCP client and tools.
🛠️ Key Features
Blocks dangerous tool calls
Scans for secret leakage
Logs all activity
Rule-based (“pure rules”)
🚀 Use Cases
Preventing harmful or unsafe MCP tool invocations
Detecting potential secret leakage during MCP usage
Auditing MCP interactions via logging
⚡ Developer Benefits
Security controls focused on tool-call safety
Secret scanning for leakage prevention
Operational visibility through comprehensive logs
⚠️ Limitations
The provided excerpt does not specify supported tools, configuration options, or deployment details beyond acting “between” client and tools.
iptables for MCP. Blocks dangerous tool calls, scans for secret leakage, logs everything. No AI, no cloud, pure rules.
Sits between your AI coding tool (Claude Code, Cursor, Windsurf) and MCP servers, intercepting every JSON-RPC message and enforcing YAML-defined policies.
MCP servers have full access to your filesystem, shell, databases, and APIs. When an AI agent calls tools/call, the server executes whatever the agent asks — reading SSH keys, running rm -rf, exfiltrating secrets. There's no built-in policy layer.
mcpwall adds one. It's a transparent stdio proxy that:
Blocks sensitive file access — .ssh/, .env, credentials, browser data
That's it. mcpwall now sits in front of all your Docker MCP servers, logging every tool call and blocking dangerous ones. No config file needed — sensible defaults apply automatically.
Option 2: Interactive setup
bash
npx mcpwall init
This finds your existing MCP servers in Claude Code, Cursor, Windsurf, and VS Code configs and wraps them. Optionally pick a security profile:
Matches if path is NOT under the given directory. Supports ${HOME}, ${PROJECT_DIR}
secrets
When true, runs the secret scanner on the value
The special key _any_value applies the matcher to ALL argument values.
Outbound rules (response inspection)
Outbound rules scan server responses before they reach your AI client. Add them to the same config file:
yaml
outbound_rules:# Redact secrets leaked in responses-name:redact-secrets-in-responsesmatch:secrets:trueaction:redactmessage:"Secret detected in server response"# Block prompt injection patterns-name:block-prompt-injectionmatch:response_contains:-"ignore previous instructions"-"provide contents of ~/.ssh"action:denymessage:"Prompt injection detected"# Flag suspiciously large responses-name:flag-large-responsesmatch:response_size_exceeds:102400action:log_only
Outbound matchers
Matcher
Description
tool
Glob pattern on the tool that produced the response (requires request-response correlation)
server
Glob pattern on the server name
secrets
When true, scans response for secret patterns (uses same secrets.patterns config)
response_contains
Case-insensitive substring match against response text
response_contains_regex
Regex match against response text
response_size_exceeds
Byte size threshold for the serialized response
Outbound actions
Action
Behavior
allow
Forward response unchanged
deny
Replace response with [BLOCKED BY MCPWALL] message
redact
Surgically replace matched secrets with [REDACTED BY MCPWALL], forward modified response
Exit codes: 0 = allowed, 1 = denied or redacted, 2 = input/config error. Pipe-friendly — use in CI or scripts.
Audit Logs
All tool calls are logged by default — both allowed and denied. Logs are written as JSON Lines to ~/.mcpwall/logs/YYYY-MM-DD.jsonl:
json
{"ts":"2026-02-16T14:30:00Z","method":"tools/call","tool":"read_file","action":"allow","rule":null}{"ts":"2026-02-16T14:30:05Z","method":"tools/call","tool":"read_file","args":"[REDACTED]","action":"deny","rule":"block-ssh-keys","message":"Blocked: access to SSH keys"}
Denied entries have args redacted to prevent secrets from leaking into logs.
mcpwall also prints color-coded output to stderr so you can see decisions in real time.
Security Design
Bidirectional scanning: Both inbound requests and outbound responses are evaluated against rules
Fail closed on invalid config: Bad regex in a rule crashes at startup, never silently passes traffic
Fail open on malformed messages by default: Non-JSON-RPC lines are forwarded raw for compatibility; use --strict to reject malformed JSON-RPC instead
Args redacted on deny: Blocked tool call arguments are never written to logs
Surgical redaction: Secrets in responses are replaced in-place, preserving the JSON-RPC response structure
mcpwall is not affiliated with or endorsed by Anthropic or the Model Context Protocol project. MCP is an open protocol maintained by the Agentic AI Foundation under the Linux Foundation.