Dev open-sources MCP security proxy that blocks agent data exfiltration via chained tool calls

dgencare · reddit · 2026-10-01

Reddit user dgencare released an open-source proxy that sits in front of MCP servers to stop a nasty attack class: prompt injections hidden in docs, webpages, or tool descriptions trick agents into chaining a "read something sensitive" call with a "send it out" call — something the MCP protocol itself doesn't prevent.

The policy pipeline includes tag-based chaining rules, session taint tracking (leaked secrets get fingerprinted and blocked from exfiltration even when encoded), response redaction, rug-pull detection on tool definitions, and a human approval gate, with a live traffic dashboard.

It's self-hostable via a single Docker Compose (app + postgres), licensed Apache 2.0 + Commons Clause — free to use, fork, and modify, but can't be resold as a service. The author is soliciting feedback from anyone running MCP infra who has hit this exfil pattern in the wild.

Original post →

More from coding & agent

coding & agent channel →