Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.
Run the underlying MCP server directly — without Agent-CoreX routing.
npx -y mcp-firewallAgent-CoreX intelligently routes which tools from behrensd/mcp-firewall your AI agent actually needs per request — reducing token usage and cost.
agent-corex.json
{
"mcpServers": {
"mcp-firewall": {
"command": "npx",
"args": [
"-y",
"mcp-firewall"
]
}
}
}Connect in 2 minutes. Only pay for the tools your agent actually uses.
Recommended: intelligent tool routing, lower costs
uvx agent-corex mcp add mcp-firewallAgent-CoreX selects only the tools your agent needs, cutting token usage by up to 60%.
Use behrensd/mcp-firewall directly without routing
npx -y mcp-firewallNew to Agent-CoreX? View setup guide →