Open-source 12-attack benchmark for MCP firewalls plus sealwall, a zero-dependency proxy

vishalmurugan1986 · reddit · 2026-10-06

As MCP connects agents straight to filesystems, shells and APIs, indirect prompt injection and tool poisoning are real threats (e.g. tools hiding <IMPORTANT> instructions that exfiltrate /.ssh/idrsa). The author shipped two things:

1. bench.py (open 12-attack benchmark): tests any stdio proxy against path traversals, symlink escapes, casing tricks, batch bypasses, tool poisoning, secret leaks and output injection; a no-proxy baseline shows what actually reaches the server.

2. sealwall (zero-dependency proxy): pure Python stdlib proxy wrapping any stdio or streamable-HTTP MCP server:

Quick test: pip install sealwall, or python bench.py --wrap "sealwall --policy policy. --". The author notes the benchmark is a regression test, not absolute proof, and invites attacks sealwall misses.

Original post →

More from coding & agent

coding & agent channel →