Rules and coverage

Every firewall rule mapped to OWASP, MITRE ATLAS and the MCP specification, with what each item leaves uncovered

Edit on GitHub

This maps every rule the firewall emits to four public frameworks, and states, for each framework item, whether the firewall covers it, covers it partly, or does not cover it. The page is generated from the rule definitions in the firewall's source, and a test fails if a rule id in the code has no mapping or if a mapping names a rule or an item that does not exist. launchsafe-firewall explain <rule> shows one rule's mapping in plain words.

How to read the status:

  • covered: the firewall deterministically gates the agent-side attack path the item describes. The gap column still lists what remains.
  • partly: some of the item's attack paths are gated; the gap says which are not.
  • not covered: no rule in effect addresses it. We say so rather than stretch a rule to fit.

A rule that maps to an item reduces risk on one path of it; it does not make the item go away. The firewall governs a coding agent's actions through hooks. It does not stop a model being fooled, and it is not a sandbox. Where the honest mitigation is a sandbox or managed settings, the table says so.

Summary

FrameworkCoveredPartlyNot covered
OWASP Top 10 for LLM Applications (2025)163
OWASP Top 10 for Agentic Applications181
MITRE ATLAS (agent-relevant techniques)3134
MCP specification security requirements275

Rule count: 64 rules emitted by the engine, plus the FW-APPROVED marker (approved once by a person; it is not a control and maps to nothing).

Verification status

Checked on 2026-10-09 against primary sources.

SourceStatus
OWASP Top 10 for LLM Applications (2025)Verified. All ten ids and names read from the official page (genai.owasp.org/llm-top-10)
OWASP Top 10 for Agentic ApplicationsVerified for names; descriptions from the OWASP announcement. ASI01 to ASI10 ids and names read from the announcement post; the resource page lists no items in its text and the PDF was not read
MITRE ATLAS (agent-relevant techniques)Verified against MITRE's published data (version 5.6.0 of the ATLAS data file), not the atlas.mitre.org pages, which returned 404 to the fetch tool. The data file carries a notice that it is deprecated in favour of newer data in the same repository, so a rename in a later release would not be seen
MITRE ATT&CK (supplementary)Verified except T1562.001. Titles of T1048, T1071.004, T1552, T1059, T1027, T1485, T1548, T1546, T1053, T1195.001, T1030 and T1105 were read from attack.mitre.org
MCP specification security requirementsVerified. Wording read from the 2025-06-18 tools page and the security best practices page, which now serves the 2025-11-25 text

Could not be verified:

  • AML.T0xxx for "Triggers in Multimodal Inputs": named in the research file but not present in ATLAS data 5.6.0, so it is not used (AML.T0068 LLM Prompt Obfuscation is used for FW-HIDDEN-TEXT instead).
  • ATT&CK T1562.001 (Impair Defenses: Disable or Modify Tools): page not fetchable, id from memory.
  • The research file's ATLAS v5.4.0 counts (16 tactics, 84 techniques) were not re-checked; the data file read is 5.6.0.
  • OWASP Agentic Top 10 item descriptions beyond the names (taken from the announcement post, not the full PDF).

OWASP Top 10 for LLM Applications (2025)

ItemStatusRulesGapMitigation
LLM01 Prompt InjectionPartlyFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-HIDDEN-TEXT, FW-MCP-CHANGED, FW-MCP-TOOL-HELD, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELDThe firewall does not stop a model being fooled. It limits what a fooled agent may do after reading outside content. An injected instruction that only asks for an action inside the allowed envelope (an edit in the workspace, a misleading answer to the user) is not stoppedRun the agent in an OS sandbox; deploy managed settings; review diffs before merging
LLM02 Sensitive Information DisclosurePartlyFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISH, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-CANARY-READ, FW-CANARY-EGRESS, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-AUTHCovers disclosure through the agent's own tool actions (network sends, fetches, messages, DNS, credential reads). Does not cover what the model provider sees in the prompt, leaks into the chat transcript, or data sent to a host the policy allowsKeep secrets out of the working tree; use a sandbox with network egress rules; review allow-host lists (sendAllowHosts, dataAllowHosts)
LLM03 Supply ChainPartlyFW-AGENT-SETTINGS, FW-INSTALL, FW-MCP-CHANGED, FW-MALICIOUS-PACKAGE, FW-TYPOSQUAT, FW-MCP-TOOL-HELDChecks every install and package runner offline: a version listed in the local OSV malicious-package snapshot is denied, including versions a lockfile install would fetch, and a look-alike of a popular name needs a person. Also gates installs after outside content and changes to agent and MCP configuration, and pins each MCP server. Does not catch a malicious package not yet listed, a snapshot you have not refreshed, or a malicious modelRun launchsafe-firewall update regularly; set a release-age cooldown (doctor --fix); pin and lock dependencies; use managed settings to allow-list MCP servers
LLM04 Data and Model PoisoningPartlyFW-INSTRUCTIONS-HELD, FW-INSTRUCTIONSOnly the agent's own instruction and memory files (CLAUDE.md, AGENTS.md, memory, rules), which are held as proposals after outside content. Training, fine-tuning and embedding-store poisoning are outside a coding-agent firewallControl training and RAG data at the pipeline; review instruction-file changes in code review
LLM05 Improper Output HandlingPartlyFW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLECovers model output being executed as code on the developer's machine. Does not cover output rendered by a downstream web application (XSS, injection into other systems)Validate and encode model output in the application that consumes it; sandbox code execution
LLM06 Excessive AgencyCoveredFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-AGENT-SETTINGS, FW-PERSISTENCE, FW-OUTSIDE-WRITE, FW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-PRIVILEGE, FW-SYMLINK, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-INSTALL, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-TAMPER, FW-POLICY-ERROR, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-LOG-UNRECORDED, FW-SCOPE, FW-AUTORUN, FW-PERSISTENCE-HELD, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-SAMPLING, FW-MCP-METHODThe firewall's core job: every action of the agent is classified and gated by effect, with approval required for send, destructive, persistence, privilege, agent-settings and code-execution classes, and denial for the worst. It limits autonomy per action but does not reduce the permissions the agent's tools holdGive the agent least-privilege credentials; use a sandbox for process, file-system and network isolation
LLM07 System Prompt LeakageNot coveredNoneOut of scope: the firewall governs actions, not what the model says about its own prompt. (Credential-shaped content leaving the machine is covered under LLM02)Do not put secrets in system prompts; treat the system prompt as public
LLM08 Vector and Embedding WeaknessesNot coveredNoneOut of scope: no vector store or embedding pipeline is in the firewall's pathAccess control and tenant isolation in the vector store; validate documents before embedding
LLM09 MisinformationNot coveredNoneOut of scope: the firewall cannot judge whether the model's claims or generated code are correctTests, code review, and grounding the model in trusted sources
LLM10 Unbounded ConsumptionPartlyFW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-LOOPPer-session budgets make volume visible, and loop detection turns the next action into an approval. No limit on model tokens or spend, and budgets ask rather than stopProvider-side spend limits and rate limits; agent turn and budget limits in the agent's own settings

OWASP Top 10 for Agentic Applications

ItemStatusRulesGapMitigation
ASI01 Agent Goal HijackPartlyFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-HIDDEN-TEXT, FW-SCOPE, FW-CANARY-READ, FW-CANARY-EGRESS, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELDSame gap as LLM01: the hijack itself is not prevented; the damaging actions it depends on are gated. A hijack that stays inside permitted actions is not stoppedSandbox; managed settings; human review of the agent's output
ASI02 Tool MisuseCoveredFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-OUTSIDE-WRITE, FW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-SYMLINK, FW-AGENT-BYPASS, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-SCOPE, FW-MCP-METHODTools are judged by what they do (paths, URLs, SQL, shell effects), not by name or self-description. Misuse within an allowed envelope (an allowed host, an in-project edit) remainsNarrow allow-lists; sandbox; scoped credentials
ASI03 Identity and Privilege AbusePartlyFW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISH, FW-PRIVILEGE, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTION, FW-VAULT-APPROVE, FW-MCP-AUTHGates credential-store reads, credentials sent to a service that did not issue them, metadata endpoints and elevated privileges. There is no agent identity, per-agent credential or token-scope management in the firewallPer-agent scoped, short-lived credentials; secret manager; sandbox that does not mount credential stores
ASI04 Agentic Supply ChainPartlyFW-AGENT-SETTINGS, FW-INSTALL, FW-MCP-CHANGED, FW-MALICIOUS-PACKAGE, FW-TYPOSQUAT, FW-MCP-TOOL-HELDDenies installs of versions listed as malicious and asks before a look-alike of a popular package, gates changes to agent and MCP configuration, and pins each MCP server. A hook never sees a server's full tool list, so description pinning covers only what Claude Code shows through ToolSearch. Plugins and unlisted malicious packages are not vettedAllow-list MCP servers and plugins with managed settings; pin versions; use a package-reputation scanner
ASI05 Unexpected Code ExecutionPartlyFW-AGENT-SETTINGS, FW-PERSISTENCE, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-INSTALL, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AUTORUN, FW-PERSISTENCE-HELDGates download-and-run, code from outside the project, obfuscated and opaque code, installs and build files changed after outside content. Shell analysis is static: code the firewall cannot see into is sent to a person (or denied), not understoodSandbox or container for execution; managed settings
ASI06 Memory and Context PoisoningPartlyFW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-MCP-CHANGED, FW-MCP-TOOL-HELD, FW-MCP-WITHHELDCovers the agent's file-based instructions and memory and agent settings: after outside content, writes are held as proposals. Does not cover vector or database memory, or memory managed by a third-party MCP serverReview instruction-file changes; scope and expire memory in the memory system itself
ASI07 Insecure Inter-Agent CommunicationPartlyFW-AGENT-SPAWNStarting another coding agent after outside content needs a person. There is no authentication or integrity check on messages between agentsAuthenticated agent-to-agent channels in the multi-agent framework; do not let agents act on each other's output unchecked
ASI08 Cascading FailuresPartlyFW-BUDGET-BYTES, FW-BUDGET-REQUESTS, FW-BUDGET-MCP, FW-LOOPLoop detection and MCP-call budgets catch retry storms and one-message-per-contact fan-out inside one session; unattended, the run is held with a notification. No model of failures propagating across agents or systems beyond the sessionCircuit breakers, rate limits and blast-radius limits in the orchestration layer
ASI09 Human-Agent Trust ExploitationNot coveredNoneThe firewall's approvals are written in plain words from the action itself, not from the agent's explanation, which helps, but nothing stops a person approving a harmful action out of trustUser training; keep approval requests rare and specific; require a second reviewer for sensitive actions
ASI10 Rogue AgentsPartlyFW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-TAMPER, FW-LOG-UNRECORDEDDenies tampering with the firewall and hooks, and starting another agent with its safety switched off; spawning needs a person. No behavioural monitoring or kill switch for an agent that driftsManaged settings make the hook unremovable; sandbox; monitoring and revocation at the platform level

MITRE ATLAS (agent-relevant techniques)

ItemStatusRulesGapMitigation
AML.T0051 LLM Prompt InjectionPartlyFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-HIDDEN-TEXT, FW-MCP-WITHHELD, FW-MCP-SAMPLING, FW-MAIL-WITHHELDAs LLM01: consequences gated, injection not prevented (includes AML.T0051.001 Indirect)Sandbox; managed settings
AML.T0053 AI Agent Tool InvocationPartlyFW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-AGENT-BYPASS, FW-AGENT-SPAWN, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOLTool invocations are gated by effect after outside content. Invocations that are within policy are allowedLeast-privilege tool configuration; sandbox
AML.T0057 LLM Data LeakagePartlyFW-SEND-ARGS, FW-FETCH-DATA, FW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-DLP-PERSONAL, FW-CANARY-EGRESS, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-VAULT-INDEX, FW-VAULT-UNSUPPORTED, FW-VAULT-OPTIONCovers leakage through agent actions; not leakage through the model's repliesKeep secrets out of the context; output filtering
AML.T0086 Exfiltration via AI Agent Tool InvocationCoveredFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-CANARY-EGRESSSends, fetches, messages, MCP writes and SQL write-backs after outside content need a person; credentials and previously seen secrets are denied from leaving. Gap: an allowed host or an approved actionEgress allow-list at the network layer; sandbox
AML.T0025 Exfiltration via Cyber MeansPartlyFW-FETCH, FW-FETCH-DATA, FW-DLP-SEEN-SECRET, FW-SECRET-FLOW, FW-SECRET-FILE-PUBLISH, FW-CAPTURE-HOST, FW-DNS-EXFIL, FW-RAW-IP, FW-VAULT-EGRESSCovers the agent's own network actions, DNS-label encoding, capture hosts and bare IPs. Does not see traffic from processes the agent starts and then leaves runningNetwork egress controls; sandbox
AML.T0055 Unsecured CredentialsPartlyFW-CREDENTIAL-READ, FW-SECRET-FLOW, FW-SECRET-VARIABLE, FW-METADATA, FW-SECRET-FILE-PUBLISHGates agent reads of credential stores and secret files and the use of secret environment variables. Does not remove credentials that sit unprotected on diskSecret manager; remove long-lived credentials from developer machines
AML.T0083 Credentials from AI Agent ConfigurationPartlyFW-CREDENTIAL-READCredential-store patterns include the agent's own credentials file (for example ~/.claude/.credentials.json); other agent configuration that embeds tokens depends on the secret patternsKeep tokens out of agent configuration files; use environment-scoped secrets
AML.T0098 AI Agent Tool Credential HarvestingPartlyFW-DLP-CREDENTIAL, FW-CREDENTIAL-READReads of credential stores and secret flows are gated. Tokens a tool legitimately holds in its own process are out of reachScoped, short-lived tool credentials
AML.T0080 AI Agent Context PoisoningPartlyFW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-MCP-CHANGEDIncludes AML.T0080.000 Memory. File-based instructions and memory are held after outside content; other memory stores are not coveredReview instruction-file changes; memory hygiene in the memory system
AML.T0081 Modify AI Agent ConfigurationCoveredFW-INSTRUCTIONS-HELD, FW-INSTRUCTIONS, FW-AGENT-SETTINGS, FW-TAMPERChanges to .mcp.json, agent settings and hook registration need a person even when trusted; tampering with the firewall is deniedManaged settings make the registration unremovable
AML.T0101 Data Destruction via AI Agent Tool InvocationCoveredFW-DESTRUCTIVE, FW-DESTROY-ROOTDestructive commands, cloud deletions and destructive SQL need a person; wiping root or home is deniedBackups; scoped credentials; sandbox
AML.T0104 Publish Poisoned AI Agent ToolPartlyFW-AGENT-SETTINGS, FW-MCP-CHANGEDA resource-development technique performed by an attacker on a registry. The firewall cannot see publication; it gates the configuration change that would install such a toolAllow-list MCP servers and plugins; review sources before installing
AML.T0109 AI Supply Chain Rug PullPartlyFW-AGENT-SETTINGS, FW-MCP-CHANGED, FW-MCP-TOOL-HELDSwapping an approved MCP configuration is gated, and a pinned server whose launch command, tool names or observed tool descriptions change makes the session untrusted. Tools a server reveals only to the model, never through ToolSearch, are not seenPin server versions; allow-list servers; managed settings
AML.T0110 AI Agent Tool PoisoningPartlyFW-HIDDEN-TEXT, FW-MCP-CHANGED, FW-MCP-TOOL-HELDHidden-text and credential-read rules stop the common payloads. A poisoned description is not detected as such; the firewall constrains the resulting actionsReview tool descriptions; allow-list servers
AML.T0010 AI Supply Chain CompromisePartlyFW-INSTALL, FW-MALICIOUS-PACKAGE, FW-TYPOSQUATPackage installs after outside content need a person; versions listed in the local OSV snapshot are denied, lockfile installs included, and typosquats ask. A compromise not yet listed, or listed after the last update, is not caughtRun launchsafe-firewall update regularly; release-age cooldowns (doctor --fix); pin and lock dependencies
AML.T0068 LLM Prompt ObfuscationPartlyFW-HIDDEN-TEXTInvisible and hidden text in tool inputs is denied; obfuscation inside content the agent reads is not detectedNormalise untrusted input before it reaches the model
AML.T0093 Prompt Infiltration via Public-Facing ApplicationNot coveredNoneThe entry vector: the firewall assumes the attacker can place text where the agent reads it and gates the consequencesLimit what untrusted sources the agent reads; use a separate low-privilege agent for untrusted content
AML.T0054 LLM JailbreakNot coveredNoneModel-level behaviour; out of scopeModel and provider guardrails
AML.T0056 Extract LLM System PromptNot coveredNoneOut of scope (see LLM07)Treat the system prompt as public
AML.T0034 Cost HarvestingNot coveredNoneIncludes AML.T0034.002 Agentic Resource Consumption. Not mapped: the per-session budgets and loop detection limit tool-call volume, not model spendProvider spend limits

MCP specification security requirements

ItemStatusRulesGapMitigation
MCP-TOOLS-HITL: a human in the loop with the ability to deny tool invocations (tools, SHOULD)CoveredFW-SEND, FW-MESSAGE, FW-SEND-ARGS, FW-FETCH, FW-FETCH-DATA, FW-REMOTE-CODE, FW-OBFUSCATED, FW-UNTRUSTED-CODE, FW-TAINTED-MANIFEST, FW-OPAQUE-CODE, FW-UNCLASSIFIABLE, FW-UNKNOWN-TOOL, FW-BLOCKED-TOOL, FW-SCOPE, FW-VAULT-APPROVERisky tool calls are held for a person who can approve or reject (ask, or a queue when no one is there); the rest are allowed. Applies only to agents that run the hookManaged settings so the hook cannot be removed
MCP-TOOLS-CONFIRM: clients SHOULD prompt for confirmation on sensitive operations and show tool inputs before callingPartlyFW-SEND, FW-MESSAGE, FW-SEND-ARGSPrompts appear for the sensitive classes, in plain words and with the exact action. Calls the policy allows are not shown to the user firstAgent-side permission prompts for everything else
MCP-ANNOTATIONS-UNTRUSTED: clients MUST consider tool annotations untrusted unless from trusted serversCoveredFW-DESTRUCTIVE, FW-DESTROY-ROOT, FW-HIDDEN-TEXT, FW-UNKNOWN-TOOL, FW-MCP-CHANGED, FW-MCP-TOOL-HELDThe firewall reads no tool annotations or descriptions to decide. Tools are judged by their arguments and effect, and a server's trust comes from its source in config, not from its name or claimsNone needed for the firewall; a hint-trusting client elsewhere would still be exposed
MCP-TOOLS-RESULTS: clients SHOULD validate tool results before passing them to the LLMPartlyFW-MCP-WITHHELDThrough the MCP gateway, every result is scanned: hidden text aimed at the agent is withheld into quarantine, other hidden text is stripped, and visible agent-directed text is annotated. The scan is pattern-based (not paraphrased or semantic injections, not text in images). Without the gateway, results are recorded as outside content, which taints the session and tightens later actionsWrap MCP servers with launchsafe-firewall mcp wrap-config; the taint rule stays the primary control
MCP-LIST-CHANGED: notifications/tools/list_changed (rug pull)PartlyFW-AGENT-SETTINGS, FW-MCP-CHANGED, FW-MCP-TOOL-HELDChanges to the MCP configuration files are gated, and a pinned server that exposes a new tool after the grace window makes the session untrusted until you accept it. The hook does not receive list_changed notifications; it sees new tools when they are called or shown through ToolSearch. Through the gateway every tools/list is pinned, and a changed or new tool is hidden until reviewedPin versions; managed-settings allow-list of servers
MCP-LOCAL-SERVER: local MCP server compromise (consent before executing startup commands, sandboxing)PartlyFW-AGENT-SETTINGS, FW-MCP-CHANGEDWriting a config that launches a server needs a person. The firewall does not sandbox the server or highlight dangerous patterns inside its startup command beyond the normal shell analysisRun servers in a sandbox or container with minimal file-system and network access
MCP-SSRF: server-side request forgery (private ranges, metadata endpoints, redirects)PartlyFW-METADATA, FW-RAW-IPThe agent's own requests to metadata endpoints and bare IPs are denied. The MCP client's OAuth-discovery fetches are not routed through the hookEgress proxy for MCP clients; block private ranges at the network layer
MCP-TOKEN-PASSTHROUGH: servers MUST NOT accept tokens not issued to themPartlyFW-DLP-CREDENTIAL, FW-DLP-SEEN-SECRET, FW-SECRET-VARIABLE, FW-VAULT-EGRESS, FW-VAULT-UNBOUND, FW-MCP-AUTHA server-side requirement. The firewall stops the agent carrying a credential to a destination that did not issue it, which is the client-side half; the gateway never forwards a client's Authorization header and sends an upstream token only to the origin of the resource it was issued forServer operators validate token audience
MCP-CONFUSED-DEPUTY: OAuth proxy servers MUST implement per-client consentNot coveredNoneA requirement on OAuth proxy servers; nothing in an agent hook can enforce itUse only servers that implement it; allow-list servers
MCP-SESSION-HIJACKING: session hijackingNot coveredNoneServer-side transport requirementServer operators: non-deterministic session ids, verify every request
MCP-OAUTH-URL: OAuth authorization URL validationNot coveredNoneA client-implementation requirement on URL schemes and how URLs are openedUse an MCP client that validates schemes
MCP-STDIO-PROXY: stdio transport security in proxy scenariosPartlyFW-MCP-METHODThe gateway is itself a proxy: it frames stdio strictly (one bounded message per line), refuses unknown methods both ways, binds its HTTP listener to 127.0.0.1 with Origin and Host checks and a per-client bearer, and validates header-body agreement. It does not sandbox the wrapped serverRun servers in a sandbox or container
MCP-SCOPE: scope minimizationNot coveredNoneToken scopes are granted outside the agent's tool calls; the firewall does not inspect themRequest narrow scopes; avoid omnibus tokens
MCP-SERVER-DUTIES: servers MUST validate inputs, apply access control, rate limit, sanitise outputsNot coveredNoneServer obligations; the firewall is client-sideChoose servers that meet them; managed-settings allow-list

Rule index

Every rule in effect, with its mappings. ATT&CK ids are supplementary (ATLAS has no agent-specific technique for these) and are not counted above.

RuleWhat it stopsOWASP LLMOWASP AgenticATLASATT&CKMCP
FW-SENDSending data out after reading outside contentLLM01, LLM02, LLM06ASI01, ASI02AML.T0086, AML.T0051NoneMCP-TOOLS-HITL, MCP-TOOLS-CONFIRM
FW-MESSAGESending a message to people after reading outside contentLLM01, LLM02, LLM06ASI01, ASI02AML.T0086, AML.T0051NoneMCP-TOOLS-HITL, MCP-TOOLS-CONFIRM
FW-SEND-ARGSHanding private data to an outside service as tool argumentsLLM01, LLM02, LLM06ASI01, ASI02AML.T0086, AML.T0051, AML.T0057NoneMCP-TOOLS-HITL, MCP-TOOLS-CONFIRM
FW-FETCHContacting a destination you did not name after reading outside contentLLM01, LLM02ASI01, ASI02AML.T0086, AML.T0025NoneMCP-TOOLS-HITL
FW-FETCH-DATAAn address that can carry data outLLM02ASI02AML.T0025, AML.T0057T1048MCP-TOOLS-HITL
FW-DLP-CREDENTIALA credential leaving for a destination that did not issue itLLM02ASI03AML.T0057, AML.T0098T1048MCP-TOKEN-PASSTHROUGH
FW-DLP-SEEN-SECRETA secret this session read, leaving the machineLLM02ASI03AML.T0057, AML.T0025T1048MCP-TOKEN-PASSTHROUGH
FW-DLP-PERSONALPersonal or financial data leaving the machineLLM02ASI03AML.T0057T1048None
FW-CREDENTIAL-READReading a credential storeLLM02, LLM06ASI03AML.T0055, AML.T0083, AML.T0098T1552None
FW-SECRET-FLOWReading a secret and contacting the network in one commandLLM02, LLM06ASI03AML.T0055, AML.T0025T1552, T1048None
FW-SECRET-VARIABLEA secret environment variable sent to a service that did not issue itLLM02ASI03AML.T0055T1552MCP-TOKEN-PASSTHROUGH
FW-METADATAAsking the cloud metadata service for credentialsLLM02ASI03AML.T0055T1552MCP-SSRF
FW-SECRET-FILE-PUBLISHPublishing after credentials were copied into a fileLLM02ASI03AML.T0055, AML.T0025T1552None
FW-CAPTURE-HOSTA data-capture, tunnelling or denied hostLLM02ASI02AML.T0025T1048None
FW-DNS-EXFILA host name built to carry dataLLM02ASI02AML.T0025T1048, T1071.004None
FW-RAW-IPContacting a bare IP addressLLM02ASI02AML.T0025T1048MCP-SSRF
FW-INSTRUCTIONS-HELDChanging the agent's instructions or memory after outside contentLLM01, LLM04ASI06AML.T0080, AML.T0081NoneNone
FW-INSTRUCTIONSChanging the agent's instructions or memory (strict mode)LLM01, LLM04ASI06AML.T0080, AML.T0081NoneNone
FW-AGENT-SETTINGSChanging settings that make code run in every sessionLLM03, LLM06ASI04, ASI05AML.T0081, AML.T0104, AML.T0109NoneMCP-LOCAL-SERVER, MCP-LIST-CHANGED
FW-PERSISTENCEWriting something that runs code later on its ownLLM06ASI05NoneT1546, T1053None
FW-OUTSIDE-WRITEWriting outside the project after outside contentLLM06ASI02NoneNoneNone
FW-DESTRUCTIVEDestroying data or infrastructureLLM06ASI02AML.T0101T1485MCP-ANNOTATIONS-UNTRUSTED
FW-DESTROY-ROOTErasing the home directory, the disk or the rootLLM06ASI02AML.T0101T1485MCP-ANNOTATIONS-UNTRUSTED
FW-PRIVILEGERunning with elevated privilegesLLM06ASI03NoneT1548None
FW-SYMLINKA link to a protected fileLLM06ASI02NoneNoneNone
FW-REMOTE-CODEDownloading code and running it directlyLLM05, LLM06ASI05AML.T0053T1059, T1105MCP-TOOLS-HITL
FW-OBFUSCATEDDecoding hidden text and running itLLM05, LLM06ASI05AML.T0053T1059, T1027MCP-TOOLS-HITL
FW-UNTRUSTED-CODERunning code that came from outside the projectLLM05, LLM06ASI05AML.T0053T1059MCP-TOOLS-HITL
FW-TAINTED-MANIFESTRunning a build or task file changed after outside contentLLM05, LLM06ASI05AML.T0053T1059MCP-TOOLS-HITL
FW-INSTALLDownloading and running packages after outside contentLLM03, LLM06ASI04, ASI05AML.T0010T1195.001None
FW-OPAQUE-CODERunning code the firewall cannot see into, after outside contentLLM05, LLM06ASI05AML.T0053T1059MCP-TOOLS-HITL
FW-UNCLASSIFIABLEPart of the action is only known at run timeLLM05, LLM06ASI05AML.T0053T1059MCP-TOOLS-HITL
FW-AGENT-BYPASSStarting a coding agent with its safety switched offLLM06ASI02, ASI10AML.T0053NoneNone
FW-AGENT-SPAWNStarting another coding agent after outside contentLLM06ASI07, ASI10AML.T0053NoneNone
FW-TAMPERChanging the firewall itselfLLM06ASI10AML.T0081T1562.001None
FW-POLICY-ERRORThe policy file is invalidLLM06NoneNoneNoneNone
FW-HIDDEN-TEXTInvisible characters in a path, address or commandLLM01ASI01AML.T0051, AML.T0068, AML.T0110NoneMCP-ANNOTATIONS-UNTRUSTED
FW-UNKNOWN-TOOLA tool the firewall does not knowLLM06ASI02AML.T0053NoneMCP-TOOLS-HITL, MCP-ANNOTATIONS-UNTRUSTED
FW-BLOCKED-TOOLA tool the policy blocksLLM06ASI02AML.T0053NoneMCP-TOOLS-HITL
FW-APPROVEDApproved once by a personNoneNoneNoneNoneNone
FW-LOG-UNRECORDEDAn allowed action the decision log could not recordLLM06ASI10NoneT1562.001None
FW-SCOPEActing outside the task you gaveLLM06ASI01, ASI02NoneNoneMCP-TOOLS-HITL
FW-MCP-CHANGEDAn MCP server changed since it was pinnedLLM03, LLM01ASI04, ASI06AML.T0109, AML.T0110, AML.T0104, AML.T0080NoneMCP-LIST-CHANGED, MCP-ANNOTATIONS-UNTRUSTED, MCP-LOCAL-SERVER
FW-MALICIOUS-PACKAGEA package version listed as maliciousLLM03ASI04AML.T0010T1195.001None
FW-TYPOSQUATA misspelt popular packageLLM03ASI04AML.T0010T1195.001None
FW-AUTORUNA change that makes code run automaticallyLLM06ASI05NoneT1546, T1053None
FW-PERSISTENCE-HELDA git hook or auto-run file held as a proposalLLM06ASI05NoneT1546, T1053None
FW-BUDGET-BYTESOutbound data budget reachedLLM10, LLM02ASI08NoneT1030None
FW-BUDGET-REQUESTSOutbound request budget reachedLLM10, LLM02ASI08NoneT1030None
FW-BUDGET-MCPMCP call budget reachedLLM10, LLM02ASI08NoneT1030None
FW-LOOPThe agent seems stuckLLM10ASI08NoneNoneNone
FW-CANARY-READA decoy file was touchedLLM02ASI01NoneNoneNone
FW-CANARY-EGRESSA decoy value leaving the machineLLM02ASI01AML.T0086, AML.T0057NoneNone
FW-VAULT-EGRESSA vaulted secret leaving for a destination it is not bound toLLM02, LLM06ASI03AML.T0057, AML.T0025T1048MCP-TOKEN-PASSTHROUGH
FW-VAULT-UNBOUNDA vault reference that names no secret, or goes where its secret is not boundLLM02, LLM06ASI03AML.T0057T1048MCP-TOKEN-PASSTHROUGH
FW-VAULT-INDEXSending while the vault index cannot be trustedLLM02ASI03AML.T0057T1048None
FW-VAULT-UNSUPPORTEDA vault reference where the firewall cannot put the value in safelyLLM02ASI03AML.T0057NoneNone
FW-VAULT-OPTIONA vault value given to curl or wget with an option off the allowlistLLM02, LLM06ASI03AML.T0057T1048None
FW-VAULT-APPROVEUsing a financial or personal value from the vaultLLM02, LLM06ASI03NoneNoneMCP-TOOLS-HITL
FW-MCP-TOOL-HELDA changed or new MCP tool, hidden until reviewedLLM03, LLM01ASI04, ASI06AML.T0109, AML.T0110NoneMCP-LIST-CHANGED, MCP-ANNOTATIONS-UNTRUSTED
FW-MCP-WITHHELDAn MCP result carrying hidden instructions, withheldLLM01ASI01, ASI06AML.T0051NoneMCP-TOOLS-RESULTS
FW-MCP-SAMPLINGAn MCP server asking to run your modelLLM01, LLM06ASI01AML.T0051NoneNone
FW-MCP-METHODAn MCP method the gateway does not knowLLM06ASI02NoneNoneMCP-STDIO-PROXY
FW-MCP-AUTHAn upstream token kept to its own serverLLM02ASI03NoneNoneMCP-TOKEN-PASSTHROUGH
FW-MAIL-WITHHELDA mail message with hidden instructions for the agent withheldLLM01ASI01AML.T0051NoneNone

What no mapping fixes

  • A fooled agent working inside its allowed envelope. Use an OS sandbox.
  • A repository that disables the hook. Use managed settings (launchsafe-firewall install --managed).
  • Agents without hook support.
  • Anything the model provider, the MCP server or the package registry does on its own side.

See also Threat model and Incidents.

On this page