{"_id":"@deepsweepai/mcp-firewall","name":"@deepsweepai/mcp-firewall","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@deepsweepai/mcp-firewall","version":"0.1.0","description":"Enterprise-grade MCP firewall for conscious AI stewardship - Zero-trust security layer for Model Context Protocol servers","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./langchain":{"types":"./dist/integrations/langchain.d.ts","import":"./dist/integrations/langchain.js"},"./crewai":{"types":"./dist/integrations/crewai.d.ts","import":"./dist/integrations/crewai.js"},"./autogen":{"types":"./dist/integrations/autogen.d.ts","import":"./dist/integrations/autogen.js"}},"bin":{"mcp-firewall":"dist/cli/index.js"},"scripts":{"dev":"tsx watch src/index.ts","build":"tsc","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","test:unit":"vitest run tests/unit","test:integration":"vitest run tests/integration","test:security":"vitest run tests/security","test:performance":"vitest run tests/performance","lint":"eslint 'src/**/*.ts' 'tests/**/*.ts'","lint:fix":"eslint 'src/**/*.ts' 'tests/**/*.ts' --fix","format":"prettier --write 'src/**/*.ts' 'tests/**/*.ts'","format:check":"prettier --check 'src/**/*.ts' 'tests/**/*.ts'","typecheck":"tsc --noEmit","benchmark":"tsx scripts/benchmark.ts","security:audit":"npm audit --audit-level=high","prepublishOnly":"npm run build && npm run test","prepare":"husky || true"},"keywords":["mcp","model-context-protocol","firewall","ai-security","memory-protection","policy-enforcement","audit-logging","pii-detection","conscious-stewardship","deepsweep","langchain","crewai","autogen","agent-security"],"repository":{"type":"git","url":"git+https://github.com/deepsweep-ai/mcp-firewall.git"},"bugs":{"url":"https://github.com/deepsweep-ai/mcp-firewall/issues"},"homepage":"https://deepsweep.ai","author":{"name":"DeepSweep.ai","email":"opensource@deepsweep.ai"},"license":"MIT","engines":{"node":">=20.0.0"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0","ajv":"^8.17.1","ajv-formats":"^3.0.1","fastify":"^5.0.0","@fastify/websocket":"^11.0.1","pino":"^9.5.0","pino-pretty":"^11.3.0","yaml":"^2.6.1","commander":"^12.1.0","dotenv":"^16.4.5"},"devDependencies":{"@types/node":"^22.10.1","@types/ws":"^8.5.13","@typescript-eslint/eslint-plugin":"^8.17.0","@typescript-eslint/parser":"^8.17.0","@vitest/coverage-v8":"^2.1.6","autocannon":"^8.0.0","eslint":"^9.16.0","husky":"^9.1.7","lint-staged":"^15.2.10","prettier":"^3.4.2","tsx":"^4.19.2","typescript":"^5.7.2","vitest":"^2.1.6"},"lint-staged":{"*.ts":["eslint --fix","prettier --write"]},"funding":{"type":"github","url":"https://github.com/sponsors/deepsweep-ai"},"gitHead":"3987dc5761d3f65ded06b8f7b995805ef2a1b74b","_id":"@deepsweepai/mcp-firewall@0.1.0","_nodeVersion":"18.15.0","_npmVersion":"9.5.0","dist":{"integrity":"sha512-FJlwX0nnyDwg5BWuOVbiNj0xRk/mZrPwYtd5L1j04grnpaqNBZ9w08oD/0qw512ajn9lZM9sJywirZfged46zw==","shasum":"bcc8f4d2d0d87ac4e9776f0747684348a01f69e9","tarball":"https://registry.npmjs.org/@deepsweepai/mcp-firewall/-/mcp-firewall-0.1.0.tgz","fileCount":139,"unpackedSize":671394,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC/6QZFOsJFMr/EpWMEqBkedYZhBmvoC1iL0LojIKMC4wIgEtP5D0cNwvPu9aKFqiattKw0UWq3cKEmMfIVKiG9NmQ="}]},"_npmUser":{"name":"deepsweep","email":"brad@deepsweep.ai"},"directories":{},"maintainers":[{"name":"deepsweep","email":"brad@deepsweep.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-firewall_0.1.0_1765182880172_0.3492687745857108"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-08T08:34:40.082Z","0.1.0":"2025-12-08T08:34:40.406Z","modified":"2025-12-08T08:34:40.715Z"},"maintainers":[{"name":"deepsweep","email":"brad@deepsweep.ai"}],"description":"Enterprise-grade MCP firewall for conscious AI stewardship - Zero-trust security layer for Model Context Protocol servers","homepage":"https://deepsweep.ai","keywords":["mcp","model-context-protocol","firewall","ai-security","memory-protection","policy-enforcement","audit-logging","pii-detection","conscious-stewardship","deepsweep","langchain","crewai","autogen","agent-security"],"repository":{"type":"git","url":"git+https://github.com/deepsweep-ai/mcp-firewall.git"},"author":{"name":"DeepSweep.ai","email":"opensource@deepsweep.ai"},"bugs":{"url":"https://github.com/deepsweep-ai/mcp-firewall/issues"},"license":"MIT","readme":"# mcp-firewall\n\n> **Open source infrastructure for conscious AI stewardship**\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![Security Bounty](https://img.shields.io/badge/Bounty-$500-green.svg)](SECURITY_CHALLENGE.md)\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.7-blue.svg)](https://www.typescriptlang.org/)\n[![Node.js](https://img.shields.io/badge/Node.js-20+-green.svg)](https://nodejs.org/)\n\n---\n\n## The Movement\n\n**DeepSweep.ai is not a security product. It is the technical foundation of conscious AI stewardship.**\n\nEvery AI agent you deploy operates in a trust vacuum—no verifiable memory integrity, no forensic accountability, no consensus validation. This is architecturally unacceptable.\n\nWe are building the infrastructure that makes aligned, accountable AI systems possible:\n\n- **Verifiable Integrity:** Cryptographic proof that agent memory hasn't been tampered with\n- **Forensic Accountability:** Complete audit trails showing every decision\n- **Distributed Consensus:** Multi-agent validation before high-stakes actions\n- **Graceful Degradation:** Flash-freeze compromised sessions, rollback to last-known-good state\n\n---\n\n## Quick Start (60 seconds)\n\n### Option 1: Docker (Fastest)\n\n```bash\ndocker run -d \\\n  -p 8080:8080 \\\n  -v $(pwd)/policy.yaml:/etc/deepsweep/policy.yaml \\\n  -e UPSTREAM_MCP_URL=http://your-mcp-server:3000 \\\n  deepsweep/mcp-firewall:latest\n```\n\n### Option 2: npm\n\n```bash\nnpm install -g @deepsweepai/mcp-firewall\nmcp-firewall start --upstream http://localhost:3000 --policy ./my-policy.yaml\n```\n\n### Option 3: Integrate into your code\n\n```typescript\nimport { createFirewall, protectLangChain, protectCrew } from '@deepsweepai/mcp-firewall';\n\n// Standalone firewall\nconst firewall = createFirewall({\n  upstream: { url: 'http://localhost:3000' },\n});\n\n// LangChain protection\nimport { ChatOpenAI } from 'langchain/chat_models/openai';\nconst model = new ChatOpenAI();\nconst protectedModel = protectLangChain(model, { policy: 'no-pii' });\n\n// CrewAI with consensus\nconst protectedCrew = protectCrew(crew, { consensus: 0.67 });\n```\n\n**That's it.** Your agents are now protected.\n\n---\n\n## Security Challenge: $500 Bounty\n\n**Break our firewall. Win $500.**\n\n| Severity | Bounty | Criteria |\n|----------|--------|----------|\n| **Critical** | **$500** | RCE, complete firewall bypass, data exfiltration despite policies |\n| **High** | **$200** | Policy evasion, PII detection bypass, unauthorized tool access |\n| **Medium** | **$100** | Schema validation bypass, rate limit circumvention |\n| **Low** | **$50** | DoS vectors, edge case crashes, documentation issues |\n\nSee [SECURITY_CHALLENGE.md](SECURITY_CHALLENGE.md) for rules.\n\n---\n\n## Features\n\n### Core Protection\n\n- ✅ Zero-trust MCP request filtering\n- ✅ Policy engine with YAML/JSON configuration\n- ✅ Automatic PII detection & redaction\n- ✅ Tool authorization (allowlist/blocklist)\n- ✅ Rate limiting & DoS prevention\n- ✅ Response sanitization\n- ✅ Suspicious pattern detection (prototype pollution, injection attacks)\n\n### Stewardship\n\n- ✅ Cryptographic memory checksums (SHA-256, SHA3-256)\n- ✅ Forensic audit trails with retention policies\n- ✅ Multi-agent consensus validation (CrewAI)\n- ✅ Policy hot-reload (zero downtime)\n- ✅ Constant-time comparison (timing attack prevention)\n\n### Integrations\n\n- ✅ **LangChain / LangGraph** - One-line wrapper\n- ✅ **CrewAI** - Consensus-based protection\n- ✅ **AutoGen** - Group chat and conversation protection\n- ✅ **Raw MCP SDK** - Direct protocol integration\n- ✅ **Any MCP-compliant server**\n\n### Infrastructure\n\n- ✅ Docker / Docker Compose\n- ✅ Kubernetes-ready (health/readiness probes)\n- ✅ Prometheus metrics endpoint\n- ✅ WebSocket support\n- ✅ Structured JSON logging\n\n---\n\n## Architecture\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│                     MCP FIREWALL                            │\n├─────────────────────────────────────────────────────────────┤\n│                                                             │\n│  ┌─────────────┐   ┌──────────────┐   ┌─────────────────┐  │\n│  │   Schema    │   │    Policy    │   │     Memory      │  │\n│  │ Validation  │──▶│    Engine    │──▶│   Validation    │  │\n│  └─────────────┘   └──────────────┘   └─────────────────┘  │\n│         │                 │                    │            │\n│         ▼                 ▼                    ▼            │\n│  ┌─────────────┐   ┌──────────────┐   ┌─────────────────┐  │\n│  │     PII     │   │     Rate     │   │     Audit       │  │\n│  │  Detection  │   │   Limiter    │   │     Logger      │  │\n│  └─────────────┘   └──────────────┘   └─────────────────┘  │\n│                                                             │\n└─────────────────────────────────────────────────────────────┘\n                            │\n                            ▼\n                   ┌─────────────────┐\n                   │  Upstream MCP   │\n                   │     Server      │\n                   └─────────────────┘\n```\n\nSee [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) for detailed design.\n\n---\n\n## Configuration\n\n### Environment Variables\n\n| Variable | Default | Description |\n|----------|---------|-------------|\n| `UPSTREAM_MCP_URL` | `http://localhost:3000` | Upstream MCP server URL |\n| `PORT` | `8080` | Proxy server port |\n| `METRICS_PORT` | `9090` | Prometheus metrics port |\n| `POLICY_PATH` | `./policy.yaml` | Policy file path |\n| `LOG_LEVEL` | `info` | Log level (trace/debug/info/warn/error) |\n| `ENABLE_PII_DETECTION` | `true` | Enable PII scanning |\n| `ENABLE_MEMORY_CHECKSUM` | `true` | Enable memory integrity checks |\n| `RATE_LIMIT_MAX` | `100` | Max requests per window |\n| `RATE_LIMIT_WINDOW_MS` | `60000` | Rate limit window (ms) |\n\n### Policy File Example\n\n```yaml\nversion: \"1.0\"\nname: production\ndescription: Production security policy\n\nrules:\n  - id: block-sensitive-tools\n    name: Block sensitive filesystem operations\n    priority: 100\n    conditions:\n      - field: method\n        operator: in\n        value: [\"fs.delete\", \"fs.write\", \"exec.shell\"]\n    action: DENY\n\n  - id: require-auth\n    name: Require authentication header\n    priority: 90\n    conditions:\n      - field: context.clientId\n        operator: equals\n        value: \"anonymous\"\n    action: DENY\n\n  - id: log-all\n    name: Log all requests\n    priority: 10\n    conditions:\n      - field: type\n        operator: equals\n        value: \"request\"\n    action: LOG\n\ndefaults:\n  action: ALLOW\n  enablePiiDetection: true\n  enableMemoryChecksum: true\n```\n\n---\n\n## API Reference\n\n### Core Classes\n\n```typescript\n// Create firewall\nconst firewall = createFirewall({\n  upstream: { url: 'http://localhost:3000' },\n  security: { enablePiiDetection: true },\n});\n\n// Process request\nconst response = await firewall.proxyRequest(request, context);\n\n// Get metrics\nconst metrics = firewall.getMetrics(); // Prometheus format\nconst metricsObj = firewall.getMetricsObject(); // JSON\n\n// Reload policy\nawait firewall.reloadPolicy();\n```\n\n### LangChain Integration\n\n```typescript\nimport { protectLangChain } from '@deepsweepai/mcp-firewall';\n\nconst protectedChain = protectLangChain(chain, {\n  piiDetection: true,\n  auditLog: true,\n  onViolation: (v) => console.log('Blocked:', v),\n});\n\nconst result = await protectedChain.invoke(input);\n```\n\n### CrewAI Integration\n\n```typescript\nimport { protectCrew } from '@deepsweepai/mcp-firewall';\n\nconst protectedCrew = protectCrew(crew, {\n  consensus: 0.67, // Require 67% agent agreement\n  memoryChecksum: true,\n  piiDetection: true,\n});\n\nconst result = await protectedCrew.kickoff({ task: 'analyze data' });\n```\n\nSee [docs/API.md](docs/API.md) for complete reference.\n\n---\n\n## Development\n\n```bash\n# Clone repository\ngit clone https://github.com/deepsweep-ai/mcp-firewall.git\ncd mcp-firewall\n\n# Install dependencies\nnpm install\n\n# Run in development mode\nnpm run dev\n\n# Run tests\nnpm test\n\n# Build\nnpm run build\n\n# Run benchmarks\nnpm run benchmark\n```\n\n---\n\n## Community\n\n- **Discord:** [Join our community](https://discord.com/invite/Db5Zth2RKR)\n- **GitHub Discussions:** [Ask questions](https://github.com/deepsweep-ai/mcp-firewall/discussions)\n- **Security:** security@deepsweep.ai\n\n---\n\n## Contributing\n\nWe welcome contributions from security researchers, AI engineers, and conscious stewards.\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\n**Good First Issues:** [GitHub Issues](https://github.com/deepsweep-ai/mcp-firewall/labels/good%20first%20issue)\n\n---\n\n## License\n\nMIT © DeepSweep.ai\n\nSee [LICENSE](LICENSE) for details.\n\n---\n\n**Built with consciousness. Deployed with confidence.**\n\n[Website](https://deepsweep.ai) | [Docs](https://docs.deepsweep.ai) | [Security](SECURITY_CHALLENGE.md)\n","readmeFilename":"README.md","_rev":"1-1bec864ecaee4aeff194c479ceb65249"}