The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool arguments, A2A payloads for OWASP LLM01 prompt injection BEFORE they reach a downstream agent. Curated from OWASP + academia + production incidents.
Project description
🧱 Part of the MEOK A2A Substrate
This MCP is 1 of 12 agent-to-agent primitives. Run the whole pipeline (identity → trust → policy → firewall → rate-limit → handoff → audit → governance) as one signed endpoint for £499/mo including 100K calls — or £0.0002 per call pay-as-you-go.
👉 meok.ai/a2a — see the Substrate
Agent Prompt Injection Firewall MCP
Buy Starter — £29/mo
Signed attestations + unlimited audits + email support. 👉 Subscribe at meok.ai — instant HMAC signing key + Stripe-managed billing.
Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.
WAF for AI agents — block prompt injection before it reaches the LLM
Agents that blindly forward user input + retrieved documents to other agents are the #1 production AI vulnerability (OWASP LLM01). This MCP is the pre-flight gate.
By MEOK AI Labs.
Quick Install
| Client | Install |
|---|---|
| Claude Desktop | |
| Cursor | |
| VS Code | |
| Windsurf | |
| Docker | docker run -p 8000:8000 agent-prompt-injection-firewall-mcp |
| pip | pip install agent-prompt-injection-firewall-mcp |
Install
pip install agent-prompt-injection-firewall-mcp
Tools
scan_promptdefine_custom_rulelist_rulesscan_logsign_firewall_attestation
Claude Desktop
{
"mcpServers": {
"agentpromptinjectionfirewall": { "command": "agent-prompt-injection-firewall-mcp" }
}
}
Tiers
- Free — generous daily limit (100-1,000 depending on operation)
- Pro £199/mo — unlimited + signed HMAC attestations with public verify URLs — subscribe
- Enterprise £1,499/mo — multi-tenant + custom predicate DSL + SIEM webhook push — subscribe
Why this exists
The EU AI Act (Aug 2026), DORA (live), ISO 42001, and OWASP LLM01 Top-10 all demand runtime controls for agent systems — not just deployment-time audits. This MCP is that runtime control layer, emitting cryptographically signed evidence your auditor accepts.
Related MEOK A2A MCPs
agent-policy-enforcement-mcp— per-pair IAMagent-handoff-certified-mcp— signed delegation chainagent-prompt-injection-firewall-mcp— prompt injection WAFagent-rate-limiter-mcp— fleet-wide quotaagent-audit-logger-mcp— hash-chained signed loga2a-governance-bridge-mcp— map A2A to compliance frameworksmeok-attestation-verify— independent cert verifier
Wire it up — full stack
Pair this with the MEOK chain that turns one agent action into ONE signed compliance event:
- bft-progress-council-mcp — anti-loop guardrail
- agent-token-budget-mcp — hard spend cap
- agent-prompt-injection-firewall-mcp — OWASP LLM01 scan
- agent-audit-logger-mcp — hash-chained evidence
- a2a-governance-bridge-mcp — fold N attestations → 1 signed event
- agent-incident-relay-mcp — broadcast incidents to 5 regimes simultaneously
See meok.ai/mcp-stack for the full architecture and meok.ai/mcp-stack/demo for the live in-browser demo.
License
MIT — MEOK AI Labs, 2026.
Sister MCPs
Part of the MEOK A2a pack — designed to work together as a fleet. Install the whole pack with npx meok-setup --pack a2a, or pick the ones you need:
- Data Residency →
uvx agent-data-residency-mcp· PyPI · GitHub - Certified Handoff →
uvx agent-handoff-certified-mcp· PyPI · GitHub - Policy Enforcement →
uvx agent-policy-enforcement-mcp· PyPI · GitHub - Audit Logger →
uvx agent-audit-logger-mcp· PyPI · GitHub - Rate Limiter →
uvx agent-rate-limiter-mcp· PyPI · GitHub
Full catalogue + Anthropic Registry verify links: meok.ai/anthropic-registry
Protocol coverage + Universal PAYG
This MCP is part of MEOK's 47-MCP fleet that bridges every active agent-interop protocol and 30+ regulatory frameworks. See the full coverage matrix at meok.ai/protocols.
Agent interop protocols supported (8 live):
- ✅ MCP (Anthropic) — native
- ✅ A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
- ✅ IBM ACP — covered via A2A merge
- ◐ Stripe ACP (Agentic Commerce Protocol) — Q3 bridge via agent-commerce-protocol-mcp
- ◐ AP2 (Google Agent Payments) — partial via agent-commerce-payments-mcp
- ◐ x402 (Coinbase HTTP 402) — partial via api.meok.ai gateway
- → OASF / AGNTCY (Cisco Outshift + Linux Foundation) — Q3 bridge
- 👁 ANP (Cisco Agent Network) — watch-list
Pricing options:
| Option | Price | Best for |
|---|---|---|
| Self-host (this MCP) | £0 — MIT | Devs |
| This MCP Starter | £29/mo | One-MCP teams |
| This MCP Pro | £79/mo | Production + 24h SLA |
| Universal PAYG | £29/mo + £0.0002/call | Spiky usage across many MCPs |
| Substrate bundle (this category) | £99-£499/mo | A whole pack |
| MEOK Universe | £1,499/mo | All 47 MCPs, 500K calls |
Each tier above the free self-host adds HMAC-signed attestations verifiable at
verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated
buyers can deploy without vendor-lock-in objections.
💸 Try MEOK in 30 seconds — instant buy ladder
| Tier | Price | What you get | Stripe |
|---|---|---|---|
| Smoke test | £1 | Signed sample MCP-Hardening report + Article 50 PDF | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Quick Kit | £9 | EU AI Act Article 50 implementation guide (C2PA + EU-Icon) | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
| Founder Call | £29 | 30-min 1-on-1 with the founder | https://buy.stripe.com/5kQ6oJ0xS3ce8sl7ew8k91j |
Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agent_prompt_injection_firewall_mcp-1.0.9.tar.gz.
File metadata
- Download URL: agent_prompt_injection_firewall_mcp-1.0.9.tar.gz
- Upload date:
- Size: 229.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.15
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2e9f697f963041f5104e3af6c9118ecd9f7db661db450fe329deda2d8882caef
|
|
| MD5 |
72070f68b539a5bac23ced91bf164485
|
|
| BLAKE2b-256 |
591fee6fb3930e57664da4dc7048d01f1cd7f15fe7e6db229727fb768b2ebba8
|
File details
Details for the file agent_prompt_injection_firewall_mcp-1.0.9-py3-none-any.whl.
File metadata
- Download URL: agent_prompt_injection_firewall_mcp-1.0.9-py3-none-any.whl
- Upload date:
- Size: 14.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.15
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cb845d1afbd1dd31a825916507cbdebe0dfe358c41b056ee20d081c77cf3617a
|
|
| MD5 |
3f0ebba44484af88ba42d56926522a39
|
|
| BLAKE2b-256 |
b3cb9a56971413267d5d778eeb7057bcafb2cc29d5712438b5e022ddd438ceab
|