Rules and coverage
Every firewall rule mapped to OWASP, MITRE ATLAS and the MCP specification, with what each item leaves uncovered
This maps every rule the firewall emits to four public frameworks, and states, for each framework item, whether the firewall covers it, covers it partly, or does not cover it. The page is generated from the rule definitions in the firewall's source, and a test fails if a rule id in the code has no mapping or if a mapping names a rule or an item that does not exist. launchsafe-firewall explain <rule> shows one rule's mapping in plain words.
How to read the status:
- covered: the firewall deterministically gates the agent-side attack path the item describes. The gap column still lists what remains.
- partly: some of the item's attack paths are gated; the gap says which are not.
- not covered: no rule in effect addresses it. We say so rather than stretch a rule to fit.
A rule that maps to an item reduces risk on one path of it; it does not make the item go away. The firewall governs a coding agent's actions through hooks. It does not stop a model being fooled, and it is not a sandbox. Where the honest mitigation is a sandbox or managed settings, the table says so.
Summary
| Framework | Covered | Partly | Not covered |
|---|---|---|---|
| OWASP Top 10 for LLM Applications (2025) | 1 | 6 | 3 |
| OWASP Top 10 for Agentic Applications | 1 | 8 | 1 |
| MITRE ATLAS (agent-relevant techniques) | 3 | 13 | 4 |
| MCP specification security requirements | 2 | 7 | 5 |
Rule count: 64 rules emitted by the engine, plus the FW-APPROVED marker (approved once by a person; it is not a control and maps to nothing).
Verification status
Checked on 2026-10-09 against primary sources.
| Source | Status |
|---|---|
| OWASP Top 10 for LLM Applications (2025) | Verified. All ten ids and names read from the official page (genai.owasp.org/llm-top-10) |
| OWASP Top 10 for Agentic Applications | Verified for names; descriptions from the OWASP announcement. ASI01 to ASI10 ids and names read from the announcement post; the resource page lists no items in its text and the PDF was not read |
| MITRE ATLAS (agent-relevant techniques) | Verified against MITRE's published data (version 5.6.0 of the ATLAS data file), not the atlas.mitre.org pages, which returned 404 to the fetch tool. The data file carries a notice that it is deprecated in favour of newer data in the same repository, so a rename in a later release would not be seen |
| MITRE ATT&CK (supplementary) | Verified except T1562.001. Titles of T1048, T1071.004, T1552, T1059, T1027, T1485, T1548, T1546, T1053, T1195.001, T1030 and T1105 were read from attack.mitre.org |
| MCP specification security requirements | Verified. Wording read from the 2025-06-18 tools page and the security best practices page, which now serves the 2025-11-25 text |
Could not be verified:
- AML.T0xxx for "Triggers in Multimodal Inputs": named in the research file but not present in ATLAS data 5.6.0, so it is not used (AML.T0068 LLM Prompt Obfuscation is used for
FW-HIDDEN-TEXTinstead). - ATT&CK T1562.001 (Impair Defenses: Disable or Modify Tools): page not fetchable, id from memory.
- The research file's ATLAS v5.4.0 counts (16 tactics, 84 techniques) were not re-checked; the data file read is 5.6.0.
- OWASP Agentic Top 10 item descriptions beyond the names (taken from the announcement post, not the full PDF).
OWASP Top 10 for LLM Applications (2025)
| Item | Status | Rules | Gap | Mitigation |
|---|---|---|---|---|
| LLM01 Prompt Injection | Partly | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-HIDDEN-TEXT, FW-MCP-CHANGED, FW-MCP-TOOL-HELD, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELD | The firewall does not stop a model being fooled. It limits what a fooled agent may do after reading outside content. An injected instruction that only asks for an action inside the allowed envelope (an edit in the workspace, a misleading answer to the user) is not stopped | Run the agent in an OS sandbox; deploy managed settings; review diffs before merging |
| LLM02 Sensitive Information Disclosure | Partly | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISH, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-CANARY-READ, FW-CANARY-EGRESS, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-AUTH | Covers disclosure through the agent's own tool actions (network sends, fetches, messages, DNS, credential reads). Does not cover what the model provider sees in the prompt, leaks into the chat transcript, or data sent to a host the policy allows | Keep secrets out of the working tree; use a sandbox with network egress rules; review allow-host lists (sendAllowHosts, dataAllowHosts) |
| LLM03 Supply Chain | Partly | FW-AGENT-SETTINGS, FW-INSTALL, FW-MCP-CHANGED, FW-MALICIOUS-PACKAGE, FW-TYPOSQUAT, FW-MCP-TOOL-HELD | Checks every install and package runner offline: a version listed in the local OSV malicious-package snapshot is denied, including versions a lockfile install would fetch, and a look-alike of a popular name needs a person. Also gates installs after outside content and changes to agent and MCP configuration, and pins each MCP server. Does not catch a malicious package not yet listed, a snapshot you have not refreshed, or a malicious model | Run launchsafe-firewall update regularly; set a release-age cooldown (doctor --fix); pin and lock dependencies; use managed settings to allow-list MCP servers |
| LLM04 Data and Model Poisoning | Partly | FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS | Only the agent's own instruction and memory files (CLAUDE.md, AGENTS.md, memory, rules), which are held as proposals after outside content. Training, fine-tuning and embedding-store poisoning are outside a coding-agent firewall | Control training and RAG data at the pipeline; review instruction-file changes in code review |
| LLM05 Improper Output Handling | Partly | FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE | Covers model output being executed as code on the developer's machine. Does not cover output rendered by a downstream web application (XSS, injection into other systems) | Validate and encode model output in the application that consumes it; sandbox code execution |
| LLM06 Excessive Agency | Covered | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-AGENT-SETTINGS, FW-PERSISTENCE, FW-OUTSIDE-WRITE, FW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-PRIVILEGE, FW-SYMLINK, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-INSTALL, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-TAMPER, FW-POLICY-ERROR, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-LOG-UNRECORDED, FW-SCOPE, FW-AUTORUN, FW-PERSISTENCE-HELD, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-SAMPLING, FW-MCP-METHOD | The firewall's core job: every action of the agent is classified and gated by effect, with approval required for send, destructive, persistence, privilege, agent-settings and code-execution classes, and denial for the worst. It limits autonomy per action but does not reduce the permissions the agent's tools hold | Give the agent least-privilege credentials; use a sandbox for process, file-system and network isolation |
| LLM07 System Prompt Leakage | Not covered | None | Out of scope: the firewall governs actions, not what the model says about its own prompt. (Credential-shaped content leaving the machine is covered under LLM02) | Do not put secrets in system prompts; treat the system prompt as public |
| LLM08 Vector and Embedding Weaknesses | Not covered | None | Out of scope: no vector store or embedding pipeline is in the firewall's path | Access control and tenant isolation in the vector store; validate documents before embedding |
| LLM09 Misinformation | Not covered | None | Out of scope: the firewall cannot judge whether the model's claims or generated code are correct | Tests, code review, and grounding the model in trusted sources |
| LLM10 Unbounded Consumption | Partly | FW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-LOOP | Per-session budgets make volume visible, and loop detection turns the next action into an approval. No limit on model tokens or spend, and budgets ask rather than stop | Provider-side spend limits and rate limits; agent turn and budget limits in the agent's own settings |
OWASP Top 10 for Agentic Applications
| Item | Status | Rules | Gap | Mitigation |
|---|---|---|---|---|
| ASI01 Agent Goal Hijack | Partly | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-HIDDEN-TEXT, FW-SCOPE, FW-CANARY-READ, FW-CANARY-EGRESS, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELD | Same gap as LLM01: the hijack itself is not prevented; the damaging actions it depends on are gated. A hijack that stays inside permitted actions is not stopped | Sandbox; managed settings; human review of the agent's output |
| ASI02 Tool Misuse | Covered | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-OUTSIDE-WRITE, FW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-SYMLINK, FW-AGENT-BYPASS, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-SCOPE, FW-MCP-METHOD | Tools are judged by what they do (paths, URLs, SQL, shell effects), not by name or self-description. Misuse within an allowed envelope (an allowed host, an in-project edit) remains | Narrow allow-lists; sandbox; scoped credentials |
| ASI03 Identity and Privilege Abuse | Partly | FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISH, FW-PRIVILEGE, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-AUTH | Gates credential-store reads, credentials sent to a service that did not issue them, metadata endpoints and elevated privileges. There is no agent identity, per-agent credential or token-scope management in the firewall | Per-agent scoped, short-lived credentials; secret manager; sandbox that does not mount credential stores |
| ASI04 Agentic Supply Chain | Partly | FW-AGENT-SETTINGS, FW-INSTALL, FW-MCP-CHANGED, FW-MALICIOUS-PACKAGE, FW-TYPOSQUAT, FW-MCP-TOOL-HELD | Denies installs of versions listed as malicious and asks before a look-alike of a popular package, gates changes to agent and MCP configuration, and pins each MCP server. A hook never sees a server's full tool list, so description pinning covers only what Claude Code shows through ToolSearch. Plugins and unlisted malicious packages are not vetted | Allow-list MCP servers and plugins with managed settings; pin versions; use a package-reputation scanner |
| ASI05 Unexpected Code Execution | Partly | FW-AGENT-SETTINGS, FW-PERSISTENCE, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-INSTALL, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AUTORUN, FW-PERSISTENCE-HELD | Gates download-and-run, code from outside the project, obfuscated and opaque code, installs and build files changed after outside content. Shell analysis is static: code the firewall cannot see into is sent to a person (or denied), not understood | Sandbox or container for execution; managed settings |
| ASI06 Memory and Context Poisoning | Partly | FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-MCP-CHANGED, FW-MCP-TOOL-HELD, FW-MCP-WITHHELD | Covers the agent's file-based instructions and memory and agent settings: after outside content, writes are held as proposals. Does not cover vector or database memory, or memory managed by a third-party MCP server | Review instruction-file changes; scope and expire memory in the memory system itself |
| ASI07 Insecure Inter-Agent Communication | Partly | FW-AGENT-SPAWN | Starting another coding agent after outside content needs a person. There is no authentication or integrity check on messages between agents | Authenticated agent-to-agent channels in the multi-agent framework; do not let agents act on each other's output unchecked |
| ASI08 Cascading Failures | Partly | FW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-LOOP | Loop detection and MCP-call budgets catch retry storms and one-message-per-contact fan-out inside one session; unattended, the run is held with a notification. No model of failures propagating across agents or systems beyond the session | Circuit breakers, rate limits and blast-radius limits in the orchestration layer |
| ASI09 Human-Agent Trust Exploitation | Not covered | None | The firewall's approvals are written in plain words from the action itself, not from the agent's explanation, which helps, but nothing stops a person approving a harmful action out of trust | User training; keep approval requests rare and specific; require a second reviewer for sensitive actions |
| ASI10 Rogue Agents | Partly | FW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-TAMPER, FW-LOG-UNRECORDED | Denies tampering with the firewall and hooks, and starting another agent with its safety switched off; spawning needs a person. No behavioural monitoring or kill switch for an agent that drifts | Managed settings make the hook unremovable; sandbox; monitoring and revocation at the platform level |
MITRE ATLAS (agent-relevant techniques)
| Item | Status | Rules | Gap | Mitigation |
|---|---|---|---|---|
| AML.T0051 LLM Prompt Injection | Partly | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-HIDDEN-TEXT, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELD | As LLM01: consequences gated, injection not prevented (includes AML.T0051.001 Indirect) | Sandbox; managed settings |
| AML.T0053 AI Agent Tool Invocation | Partly | FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL | Tool invocations are gated by effect after outside content. Invocations that are within policy are allowed | Least-privilege tool configuration; sandbox |
| AML.T0057 LLM Data Leakage | Partly | FW-SEND-ARGS, FW-FETCH-DATA, FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CANARY-EGRESS, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTION | Covers leakage through agent actions; not leakage through the model's replies | Keep secrets out of the context; output filtering |
| AML.T0086 Exfiltration via AI Agent Tool Invocation | Covered | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-CANARY-EGRESS | Sends, fetches, messages, MCP writes and SQL write-backs after outside content need a person; credentials and previously seen secrets are denied from leaving. Gap: an allowed host or an approved action | Egress allow-list at the network layer; sandbox |
| AML.T0025 Exfiltration via Cyber Means | Partly | FW-FETCH, FW-FETCH-DATA, FW-DLP-SEEN-SECRET, FW-SECRET-FLOW, FW-SECRET-FILE-PUBLISH, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-VAULT-EGRESS | Covers the agent's own network actions, DNS-label encoding, capture hosts and bare IPs. Does not see traffic from processes the agent starts and then leaves running | Network egress controls; sandbox |
| AML.T0055 Unsecured Credentials | Partly | FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISH | Gates agent reads of credential stores and secret files and the use of secret environment variables. Does not remove credentials that sit unprotected on disk | Secret manager; remove long-lived credentials from developer machines |
| AML.T0083 Credentials from AI Agent Configuration | Partly | FW-CREDENTIAL-READ | Credential-store patterns include the agent's own credentials file (for example ~/.claude/.credentials.json); other agent configuration that embeds tokens depends on the secret patterns | Keep tokens out of agent configuration files; use environment-scoped secrets |
| AML.T0098 AI Agent Tool Credential Harvesting | Partly | FW-DLP-CREDENTIAL, FW-CREDENTIAL-READ | Reads of credential stores and secret flows are gated. Tokens a tool legitimately holds in its own process are out of reach | Scoped, short-lived tool credentials |
| AML.T0080 AI Agent Context Poisoning | Partly | FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-MCP-CHANGED | Includes AML.T0080.000 Memory. File-based instructions and memory are held after outside content; other memory stores are not covered | Review instruction-file changes; memory hygiene in the memory system |
| AML.T0081 Modify AI Agent Configuration | Covered | FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-AGENT-SETTINGS, FW-TAMPER | Changes to .mcp.json, agent settings and hook registration need a person even when trusted; tampering with the firewall is denied | Managed settings make the registration unremovable |
| AML.T0101 Data Destruction via AI Agent Tool Invocation | Covered | FW-DESTRUCTIVE, FW-DESTROY-ROOT | Destructive commands, cloud deletions and destructive SQL need a person; wiping root or home is denied | Backups; scoped credentials; sandbox |
| AML.T0104 Publish Poisoned AI Agent Tool | Partly | FW-AGENT-SETTINGS, FW-MCP-CHANGED | A resource-development technique performed by an attacker on a registry. The firewall cannot see publication; it gates the configuration change that would install such a tool | Allow-list MCP servers and plugins; review sources before installing |
| AML.T0109 AI Supply Chain Rug Pull | Partly | FW-AGENT-SETTINGS, FW-MCP-CHANGED, FW-MCP-TOOL-HELD | Swapping an approved MCP configuration is gated, and a pinned server whose launch command, tool names or observed tool descriptions change makes the session untrusted. Tools a server reveals only to the model, never through ToolSearch, are not seen | Pin server versions; allow-list servers; managed settings |
| AML.T0110 AI Agent Tool Poisoning | Partly | FW-HIDDEN-TEXT, FW-MCP-CHANGED, FW-MCP-TOOL-HELD | Hidden-text and credential-read rules stop the common payloads. A poisoned description is not detected as such; the firewall constrains the resulting actions | Review tool descriptions; allow-list servers |
| AML.T0010 AI Supply Chain Compromise | Partly | FW-INSTALL, FW-MALICIOUS-PACKAGE, FW-TYPOSQUAT | Package installs after outside content need a person; versions listed in the local OSV snapshot are denied, lockfile installs included, and typosquats ask. A compromise not yet listed, or listed after the last update, is not caught | Run launchsafe-firewall update regularly; release-age cooldowns (doctor --fix); pin and lock dependencies |
| AML.T0068 LLM Prompt Obfuscation | Partly | FW-HIDDEN-TEXT | Invisible and hidden text in tool inputs is denied; obfuscation inside content the agent reads is not detected | Normalise untrusted input before it reaches the model |
| AML.T0093 Prompt Infiltration via Public-Facing Application | Not covered | None | The entry vector: the firewall assumes the attacker can place text where the agent reads it and gates the consequences | Limit what untrusted sources the agent reads; use a separate low-privilege agent for untrusted content |
| AML.T0054 LLM Jailbreak | Not covered | None | Model-level behaviour; out of scope | Model and provider guardrails |
| AML.T0056 Extract LLM System Prompt | Not covered | None | Out of scope (see LLM07) | Treat the system prompt as public |
| AML.T0034 Cost Harvesting | Not covered | None | Includes AML.T0034.002 Agentic Resource Consumption. Not mapped: the per-session budgets and loop detection limit tool-call volume, not model spend | Provider spend limits |
MCP specification security requirements
| Item | Status | Rules | Gap | Mitigation |
|---|---|---|---|---|
| MCP-TOOLS-HITL: a human in the loop with the ability to deny tool invocations (tools, SHOULD) | Covered | FW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-SCOPE, FW-VAULT-APPROVE | Risky tool calls are held for a person who can approve or reject (ask, or a queue when no one is there); the rest are allowed. Applies only to agents that run the hook | Managed settings so the hook cannot be removed |
| MCP-TOOLS-CONFIRM: clients SHOULD prompt for confirmation on sensitive operations and show tool inputs before calling | Partly | FW-SEND, FW-MESSAGE, FW-SEND-ARGS | Prompts appear for the sensitive classes, in plain words and with the exact action. Calls the policy allows are not shown to the user first | Agent-side permission prompts for everything else |
| MCP-ANNOTATIONS-UNTRUSTED: clients MUST consider tool annotations untrusted unless from trusted servers | Covered | FW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-HIDDEN-TEXT, FW-UNKNOWN-TOOL, FW-MCP-CHANGED, FW-MCP-TOOL-HELD | The firewall reads no tool annotations or descriptions to decide. Tools are judged by their arguments and effect, and a server's trust comes from its source in config, not from its name or claims | None needed for the firewall; a hint-trusting client elsewhere would still be exposed |
| MCP-TOOLS-RESULTS: clients SHOULD validate tool results before passing them to the LLM | Partly | FW-MCP-WITHHELD | Through the MCP gateway, every result is scanned: hidden text aimed at the agent is withheld into quarantine, other hidden text is stripped, and visible agent-directed text is annotated. The scan is pattern-based (not paraphrased or semantic injections, not text in images). Without the gateway, results are recorded as outside content, which taints the session and tightens later actions | Wrap MCP servers with launchsafe-firewall mcp wrap-config; the taint rule stays the primary control |
MCP-LIST-CHANGED: notifications/tools/list_changed (rug pull) | Partly | FW-AGENT-SETTINGS, FW-MCP-CHANGED, FW-MCP-TOOL-HELD | Changes to the MCP configuration files are gated, and a pinned server that exposes a new tool after the grace window makes the session untrusted until you accept it. The hook does not receive list_changed notifications; it sees new tools when they are called or shown through ToolSearch. Through the gateway every tools/list is pinned, and a changed or new tool is hidden until reviewed | Pin versions; managed-settings allow-list of servers |
| MCP-LOCAL-SERVER: local MCP server compromise (consent before executing startup commands, sandboxing) | Partly | FW-AGENT-SETTINGS, FW-MCP-CHANGED | Writing a config that launches a server needs a person. The firewall does not sandbox the server or highlight dangerous patterns inside its startup command beyond the normal shell analysis | Run servers in a sandbox or container with minimal file-system and network access |
| MCP-SSRF: server-side request forgery (private ranges, metadata endpoints, redirects) | Partly | FW-METADATA, FW-RAW-IP | The agent's own requests to metadata endpoints and bare IPs are denied. The MCP client's OAuth-discovery fetches are not routed through the hook | Egress proxy for MCP clients; block private ranges at the network layer |
| MCP-TOKEN-PASSTHROUGH: servers MUST NOT accept tokens not issued to them | Partly | FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-SECRET-VARIABLE, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-MCP-AUTH | A server-side requirement. The firewall stops the agent carrying a credential to a destination that did not issue it, which is the client-side half; the gateway never forwards a client's Authorization header and sends an upstream token only to the origin of the resource it was issued for | Server operators validate token audience |
| MCP-CONFUSED-DEPUTY: OAuth proxy servers MUST implement per-client consent | Not covered | None | A requirement on OAuth proxy servers; nothing in an agent hook can enforce it | Use only servers that implement it; allow-list servers |
| MCP-SESSION-HIJACKING: session hijacking | Not covered | None | Server-side transport requirement | Server operators: non-deterministic session ids, verify every request |
| MCP-OAUTH-URL: OAuth authorization URL validation | Not covered | None | A client-implementation requirement on URL schemes and how URLs are opened | Use an MCP client that validates schemes |
| MCP-STDIO-PROXY: stdio transport security in proxy scenarios | Partly | FW-MCP-METHOD | The gateway is itself a proxy: it frames stdio strictly (one bounded message per line), refuses unknown methods both ways, binds its HTTP listener to 127.0.0.1 with Origin and Host checks and a per-client bearer, and validates header-body agreement. It does not sandbox the wrapped server | Run servers in a sandbox or container |
| MCP-SCOPE: scope minimization | Not covered | None | Token scopes are granted outside the agent's tool calls; the firewall does not inspect them | Request narrow scopes; avoid omnibus tokens |
| MCP-SERVER-DUTIES: servers MUST validate inputs, apply access control, rate limit, sanitise outputs | Not covered | None | Server obligations; the firewall is client-side | Choose servers that meet them; managed-settings allow-list |
Rule index
Every rule in effect, with its mappings. ATT&CK ids are supplementary (ATLAS has no agent-specific technique for these) and are not counted above.
| Rule | What it stops | OWASP LLM | OWASP Agentic | ATLAS | ATT&CK | MCP |
|---|---|---|---|---|---|---|
FW-SEND | Sending data out after reading outside content | LLM01, LLM02, LLM06 | ASI01, ASI02 | AML.T0086, AML.T0051 | None | MCP-TOOLS-HITL, MCP-TOOLS-CONFIRM |
FW-MESSAGE | Sending a message to people after reading outside content | LLM01, LLM02, LLM06 | ASI01, ASI02 | AML.T0086, AML.T0051 | None | MCP-TOOLS-HITL, MCP-TOOLS-CONFIRM |
FW-SEND-ARGS | Handing private data to an outside service as tool arguments | LLM01, LLM02, LLM06 | ASI01, ASI02 | AML.T0086, AML.T0051, AML.T0057 | None | MCP-TOOLS-HITL, MCP-TOOLS-CONFIRM |
FW-FETCH | Contacting a destination you did not name after reading outside content | LLM01, LLM02 | ASI01, ASI02 | AML.T0086, AML.T0025 | None | MCP-TOOLS-HITL |
FW-FETCH-DATA | An address that can carry data out | LLM02 | ASI02 | AML.T0025, AML.T0057 | T1048 | MCP-TOOLS-HITL |
FW-DLP-CREDENTIAL | A credential leaving for a destination that did not issue it | LLM02 | ASI03 | AML.T0057, AML.T0098 | T1048 | MCP-TOKEN-PASSTHROUGH |
FW-DLP-SEEN-SECRET | A secret this session read, leaving the machine | LLM02 | ASI03 | AML.T0057, AML.T0025 | T1048 | MCP-TOKEN-PASSTHROUGH |
FW-DLP-PERSONAL | Personal or financial data leaving the machine | LLM02 | ASI03 | AML.T0057 | T1048 | None |
FW-CREDENTIAL-READ | Reading a credential store | LLM02, LLM06 | ASI03 | AML.T0055, AML.T0083, AML.T0098 | T1552 | None |
FW-SECRET-FLOW | Reading a secret and contacting the network in one command | LLM02, LLM06 | ASI03 | AML.T0055, AML.T0025 | T1552, T1048 | None |
FW-SECRET-VARIABLE | A secret environment variable sent to a service that did not issue it | LLM02 | ASI03 | AML.T0055 | T1552 | MCP-TOKEN-PASSTHROUGH |
FW-METADATA | Asking the cloud metadata service for credentials | LLM02 | ASI03 | AML.T0055 | T1552 | MCP-SSRF |
FW-SECRET-FILE-PUBLISH | Publishing after credentials were copied into a file | LLM02 | ASI03 | AML.T0055, AML.T0025 | T1552 | None |
FW-CAPTURE-HOST | A data-capture, tunnelling or denied host | LLM02 | ASI02 | AML.T0025 | T1048 | None |
FW-DNS-EXFIL | A host name built to carry data | LLM02 | ASI02 | AML.T0025 | T1048, T1071.004 | None |
FW-RAW-IP | Contacting a bare IP address | LLM02 | ASI02 | AML.T0025 | T1048 | MCP-SSRF |
FW-INSTRUCTIONS-HELD | Changing the agent's instructions or memory after outside content | LLM01, LLM04 | ASI06 | AML.T0080, AML.T0081 | None | None |
FW-INSTRUCTIONS | Changing the agent's instructions or memory (strict mode) | LLM01, LLM04 | ASI06 | AML.T0080, AML.T0081 | None | None |
FW-AGENT-SETTINGS | Changing settings that make code run in every session | LLM03, LLM06 | ASI04, ASI05 | AML.T0081, AML.T0104, AML.T0109 | None | MCP-LOCAL-SERVER, MCP-LIST-CHANGED |
FW-PERSISTENCE | Writing something that runs code later on its own | LLM06 | ASI05 | None | T1546, T1053 | None |
FW-OUTSIDE-WRITE | Writing outside the project after outside content | LLM06 | ASI02 | None | None | None |
FW-DESTRUCTIVE | Destroying data or infrastructure | LLM06 | ASI02 | AML.T0101 | T1485 | MCP-ANNOTATIONS-UNTRUSTED |
FW-DESTROY-ROOT | Erasing the home directory, the disk or the root | LLM06 | ASI02 | AML.T0101 | T1485 | MCP-ANNOTATIONS-UNTRUSTED |
FW-PRIVILEGE | Running with elevated privileges | LLM06 | ASI03 | None | T1548 | None |
FW-SYMLINK | A link to a protected file | LLM06 | ASI02 | None | None | None |
FW-REMOTE-CODE | Downloading code and running it directly | LLM05, LLM06 | ASI05 | AML.T0053 | T1059, T1105 | MCP-TOOLS-HITL |
FW-OBFUSCATED | Decoding hidden text and running it | LLM05, LLM06 | ASI05 | AML.T0053 | T1059, T1027 | MCP-TOOLS-HITL |
FW-UNTRUSTED-CODE | Running code that came from outside the project | LLM05, LLM06 | ASI05 | AML.T0053 | T1059 | MCP-TOOLS-HITL |
FW-TAINTED-MANIFEST | Running a build or task file changed after outside content | LLM05, LLM06 | ASI05 | AML.T0053 | T1059 | MCP-TOOLS-HITL |
FW-INSTALL | Downloading and running packages after outside content | LLM03, LLM06 | ASI04, ASI05 | AML.T0010 | T1195.001 | None |
FW-OPAQUE-CODE | Running code the firewall cannot see into, after outside content | LLM05, LLM06 | ASI05 | AML.T0053 | T1059 | MCP-TOOLS-HITL |
FW-UNCLASSIFIABLE | Part of the action is only known at run time | LLM05, LLM06 | ASI05 | AML.T0053 | T1059 | MCP-TOOLS-HITL |
FW-AGENT-BYPASS | Starting a coding agent with its safety switched off | LLM06 | ASI02, ASI10 | AML.T0053 | None | None |
FW-AGENT-SPAWN | Starting another coding agent after outside content | LLM06 | ASI07, ASI10 | AML.T0053 | None | None |
FW-TAMPER | Changing the firewall itself | LLM06 | ASI10 | AML.T0081 | T1562.001 | None |
FW-POLICY-ERROR | The policy file is invalid | LLM06 | None | None | None | None |
FW-HIDDEN-TEXT | Invisible characters in a path, address or command | LLM01 | ASI01 | AML.T0051, AML.T0068, AML.T0110 | None | MCP-ANNOTATIONS-UNTRUSTED |
FW-UNKNOWN-TOOL | A tool the firewall does not know | LLM06 | ASI02 | AML.T0053 | None | MCP-TOOLS-HITL, MCP-ANNOTATIONS-UNTRUSTED |
FW-BLOCKED-TOOL | A tool the policy blocks | LLM06 | ASI02 | AML.T0053 | None | MCP-TOOLS-HITL |
FW-APPROVED | Approved once by a person | None | None | None | None | None |
FW-LOG-UNRECORDED | An allowed action the decision log could not record | LLM06 | ASI10 | None | T1562.001 | None |
FW-SCOPE | Acting outside the task you gave | LLM06 | ASI01, ASI02 | None | None | MCP-TOOLS-HITL |
FW-MCP-CHANGED | An MCP server changed since it was pinned | LLM03, LLM01 | ASI04, ASI06 | AML.T0109, AML.T0110, AML.T0104, AML.T0080 | None | MCP-LIST-CHANGED, MCP-ANNOTATIONS-UNTRUSTED, MCP-LOCAL-SERVER |
FW-MALICIOUS-PACKAGE | A package version listed as malicious | LLM03 | ASI04 | AML.T0010 | T1195.001 | None |
FW-TYPOSQUAT | A misspelt popular package | LLM03 | ASI04 | AML.T0010 | T1195.001 | None |
FW-AUTORUN | A change that makes code run automatically | LLM06 | ASI05 | None | T1546, T1053 | None |
FW-PERSISTENCE-HELD | A git hook or auto-run file held as a proposal | LLM06 | ASI05 | None | T1546, T1053 | None |
FW-BUDGET-BYTES | Outbound data budget reached | LLM10, LLM02 | ASI08 | None | T1030 | None |
FW-BUDGET-REQUESTS | Outbound request budget reached | LLM10, LLM02 | ASI08 | None | T1030 | None |
FW-BUDGET-MCP | MCP call budget reached | LLM10, LLM02 | ASI08 | None | T1030 | None |
FW-LOOP | The agent seems stuck | LLM10 | ASI08 | None | None | None |
FW-CANARY-READ | A decoy file was touched | LLM02 | ASI01 | None | None | None |
FW-CANARY-EGRESS | A decoy value leaving the machine | LLM02 | ASI01 | AML.T0086, AML.T0057 | None | None |
FW-VAULT-EGRESS | A vaulted secret leaving for a destination it is not bound to | LLM02, LLM06 | ASI03 | AML.T0057, AML.T0025 | T1048 | MCP-TOKEN-PASSTHROUGH |
FW-VAULT-UNBOUND | A vault reference that names no secret, or goes where its secret is not bound | LLM02, LLM06 | ASI03 | AML.T0057 | T1048 | MCP-TOKEN-PASSTHROUGH |
FW-VAULT-INDEX | Sending while the vault index cannot be trusted | LLM02 | ASI03 | AML.T0057 | T1048 | None |
FW-VAULT-UNSUPPORTED | A vault reference where the firewall cannot put the value in safely | LLM02 | ASI03 | AML.T0057 | None | None |
FW-VAULT-OPTION | A vault value given to curl or wget with an option off the allowlist | LLM02, LLM06 | ASI03 | AML.T0057 | T1048 | None |
FW-VAULT-APPROVE | Using a financial or personal value from the vault | LLM02, LLM06 | ASI03 | None | None | MCP-TOOLS-HITL |
FW-MCP-TOOL-HELD | A changed or new MCP tool, hidden until reviewed | LLM03, LLM01 | ASI04, ASI06 | AML.T0109, AML.T0110 | None | MCP-LIST-CHANGED, MCP-ANNOTATIONS-UNTRUSTED |
FW-MCP-WITHHELD | An MCP result carrying hidden instructions, withheld | LLM01 | ASI01, ASI06 | AML.T0051 | None | MCP-TOOLS-RESULTS |
FW-MCP-SAMPLING | An MCP server asking to run your model | LLM01, LLM06 | ASI01 | AML.T0051 | None | None |
FW-MCP-METHOD | An MCP method the gateway does not know | LLM06 | ASI02 | None | None | MCP-STDIO-PROXY |
FW-MCP-AUTH | An upstream token kept to its own server | LLM02 | ASI03 | None | None | MCP-TOKEN-PASSTHROUGH |
FW-MAIL-WITHHELD | A mail message with hidden instructions for the agent withheld | LLM01 | ASI01 | AML.T0051 | None | None |
What no mapping fixes
- A fooled agent working inside its allowed envelope. Use an OS sandbox.
- A repository that disables the hook. Use managed settings (
launchsafe-firewall install --managed). - Agents without hook support.
- Anything the model provider, the MCP server or the package registry does on its own side.
See also Threat model and Incidents.