Open-source 12-attack benchmark for MCP firewalls plus sealwall, a zero-dependency proxy
vishalmurugan1986 · reddit · 2026-10-06
As MCP connects agents straight to filesystems, shells and APIs, indirect prompt injection and tool poisoning are real threats (e.g. tools hiding <IMPORTANT> instructions that exfiltrate /.ssh/idrsa). The author shipped two things:
1. bench.py (open 12-attack benchmark): tests any stdio proxy against path traversals, symlink escapes, casing tricks, batch bypasses, tool poisoning, secret leaks and output injection; a no-proxy baseline shows what actually reaches the server.
2. sealwall (zero-dependency proxy): pure Python stdlib proxy wrapping any stdio or streamable-HTTP MCP server:
- Path allowlists with canonicalization, symlink and traversal resolution before tools run
- Tool-poisoning & rug-pull defense: strips hidden instructions, pins tool definitions on first sight
- Secret scanning: blocks API keys/tokens/private keys in arguments and redacts them from outputs
- Hash-chained HMAC-SHA256 JSONL audit logs to catch tampering
- Standalone HTML evidence reports
Quick test: pip install sealwall, or python bench.py --wrap "sealwall --policy policy. --". The author notes the benchmark is a regression test, not absolute proof, and invites attacks sealwall misses.
More from coding & agent
- Creator hands repetitive workflow to Codex and GPT-6 Astra, keeps creative calls — socialwithaayan · 2026-10-06
- Monica CRM MCP Server wraps REST API with 21 natural-language tools — modelcontextprotocol · 2026-10-06
- React Compiler core member's go-to prompt: make AI restate your goals before it works — sujingshen · 2026-10-06
- dotey explains Codex Project vs Claude Projects: forum boards vs Slack channels — dotey · 2026-10-06
- A Planted 'P.S.' Fooled Jev, TypeSafe's New Decision Model — a Simple Rule Caught It — Internal-Lie-5197 · 2026-10-06
- Claude Code's New Dreaded Message: 'Compacted While Idle, Before the Prompt Cache Expired' — dSebastien · 2026-10-06