Skip to main content

The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool arguments, A2A payloads for OWASP LLM01 prompt injection BEFORE they reach a downstream agent. Curated from OWASP + academia + production incidents.

Project description

MCP Scorecard: 84/100

🧱 Part of the MEOK A2A Substrate

This MCP is 1 of 12 agent-to-agent primitives. Run the whole pipeline (identity → trust → policy → firewall → rate-limit → handoff → audit → governance) as one signed endpoint for £499/mo including 100K calls — or £0.0002 per call pay-as-you-go.

👉 meok.ai/a2a — see the Substrate

Agent Prompt Injection Firewall MCP

Buy Starter — £29/mo

Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.

Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.

PyPI Python MCPize

WAF for AI agents — block prompt injection before it reaches the LLM

Agents that blindly forward user input + retrieved documents to other agents are the #1 production AI vulnerability (OWASP LLM01). This MCP is the pre-flight gate.

By MEOK AI Labs.

Quick Install

Client Install
Claude Desktop Install in Claude
Cursor Install in Cursor
VS Code Install in VS Code
Windsurf Install in Windsurf
Docker docker run -p 8000:8000 agent-prompt-injection-firewall-mcp
pip pip install agent-prompt-injection-firewall-mcp

Install

pip install agent-prompt-injection-firewall-mcp

Tools

  • scan_prompt
  • define_custom_rule
  • list_rules
  • scan_log
  • sign_firewall_attestation

Claude Desktop

{
  "mcpServers": {
    "agentpromptinjectionfirewall": { "command": "agent-prompt-injection-firewall-mcp" }
  }
}

Tiers

  • Free — generous daily limit (100-1,000 depending on operation)
  • Pro £199/mo — unlimited + signed HMAC attestations with public verify URLs — subscribe
  • Enterprise £1,499/mo — multi-tenant + custom predicate DSL + SIEM webhook push — subscribe

Why this exists

The EU AI Act (Aug 2026), DORA (live), ISO 42001, and OWASP LLM01 Top-10 all demand runtime controls for agent systems — not just deployment-time audits. This MCP is that runtime control layer, emitting cryptographically signed evidence your auditor accepts.

Related MEOK A2A MCPs

Wire it up — full stack

Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:

  1. bft-progress-council-mcp — anti-loop guardrail
  2. agent-token-budget-mcp — hard spend cap
  3. agent-prompt-injection-firewall-mcp — OWASP LLM01 scan
  4. agent-audit-logger-mcp — hash-chained evidence
  5. a2a-governance-bridge-mcp — fold N attestations → 1 signed event
  6. agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously

See meok.ai/mcp-stack for the full architecture and meok.ai/mcp-stack/demo for the live in-browser demo.

License

MIT — MEOK AI Labs, 2026.

Sister MCPs

Part of the MEOK A2a pack — designed to work together as a fleet. Install the whole pack with npx meok-setup --pack a2a, or pick the ones you need:

  • Data Residencyuvx agent-data-residency-mcp · PyPI · GitHub
  • Certified Handoffuvx agent-handoff-certified-mcp · PyPI · GitHub
  • Policy Enforcementuvx agent-policy-enforcement-mcp · PyPI · GitHub
  • Audit Loggeruvx agent-audit-logger-mcp · PyPI · GitHub
  • Rate Limiteruvx agent-rate-limiter-mcp · PyPI · GitHub

Full catalogue + Anthropic Registry verify links: meok.ai/anthropic-registry

Protocol coverage + Universal PAYG

This MCP is part of MEOK's 47-MCP fleet that bridges every active agent-interop protocol and 30+ regulatory frameworks. See the full coverage matrix at meok.ai/protocols.

Agent interop protocols supported (8 live):

  • MCP (Anthropic) — native
  • A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
  • IBM ACP — covered via A2A merge
  • Stripe ACP (Agentic Commerce Protocol) — Q3 bridge via agent-commerce-protocol-mcp
  • AP2 (Google Agent Payments) — partial via agent-commerce-payments-mcp
  • x402 (Coinbase HTTP 402) — partial via api.meok.ai gateway
  • OASF / AGNTCY (Cisco Outshift + Linux Foundation) — Q3 bridge
  • 👁 ANP (Cisco Agent Network) — watch-list

Pricing options:

Option Price Best for
Self-host (this MCP) £0 — MIT Devs
This MCP Starter £29/mo One-MCP teams
This MCP Pro £79/mo Production + 24h SLA
Universal PAYG £29/mo + £0.0002/call Spiky usage across many MCPs
Substrate bundle (this category) £99-£499/mo A whole pack
MEOK Universe £1,499/mo All 47 MCPs, 500K calls

Each tier above the free self-host adds HMAC-signed attestations verifiable at verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated buyers can deploy without vendor-lock-in objections.

💸 Try MEOK in 30 seconds — instant buy ladder

Tier Price What you get Stripe
Smoke test £1 Signed sample MCP-Hardening report + Article 50 PDF https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Quick Kit £9 EU AI Act Article 50 implementation guide (C2PA + EU-Icon) https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Founder Call £29 30-min 1-on-1 with the founder https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t

Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_prompt_injection_firewall_mcp-1.0.10.tar.gz (228.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file agent_prompt_injection_firewall_mcp-1.0.10.tar.gz.

File metadata

File hashes

Hashes for agent_prompt_injection_firewall_mcp-1.0.10.tar.gz
Algorithm Hash digest
SHA256 a5e47bd45a0b77ab2a77329b7cb1e4b24abcd153ec2b934f78ec239c07ecb1f8
MD5 69ed8e6671341c5fdf557426c2331306
BLAKE2b-256 f001423069fd1837639c1cd8b53af1262f63259365648e5eb956eed9cbf16d0d

See more details on using hashes here.

File details

Details for the file agent_prompt_injection_firewall_mcp-1.0.10-py3-none-any.whl.

File metadata

File hashes

Hashes for agent_prompt_injection_firewall_mcp-1.0.10-py3-none-any.whl
Algorithm Hash digest
SHA256 bdfe9f766eb98d6ff498c3e03effc3323669aece2c5f597908074f7ae95591a3
MD5 85b3dd60f98890c28ef7c918fe8312f9
BLAKE2b-256 3058789f04a74fdbbdad0759bdf008395f9d461db6beea8953bff318352514d4

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page