Mcpwall MCP Server

iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.

Local serverstdio

What is the Mcpwall MCP server?

Connect Mcpwall to Claude, Cursor or any other MCP client and it stops being a tab you switch to. iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything. The mcpwall mcp server is what makes that connection.

What the server does

Sits between your AI coding tool (Claude Code, Cursor, Windsurf) and MCP servers, intercepting every JSON-RPC message and enforcing YAML-defined policies.

  • Blocks sensitive file access — — .ssh/, .env, credentials, browser data
  • Blocks dangerous commands — — rm -rf, pipe-to-shell, reverse shells
  • Scans for secret leakage — — API keys, tokens, private keys (regex + entropy)
  • Scans server responses — — redacts leaked secrets, blocks prompt injection patterns, flags suspicious content
  • Logs everything — — JSON Lines audit trail of every tool call and response
  • Uses zero AI — — deterministic rules, no LLM decisions, no cloud calls

Available tools

The toolset is worth reading before you wire it up, because it tells you what the integration is really for:

  • name — block-ssh-keys
  • filesystem-mcp.yaml — restricts reads/writes/listings to ${PROJECT_DIR}, blocks dotfiles and traversal
  • github-mcp.yaml — logs all file reads, blocks broad private repo enumeration
  • shell-mcp.yaml — adds network command and package install blocks
  • Pre — compiled regexes**: All patterns compiled once at startup for consistent performance
  • Deterministic — Same input + same rules = same output, every time
  • Matcher — Description
  • regex — Regular expression test on the value
  • pattern — Glob pattern (uses minimatch)
  • not_under — Matches if path is NOT under the given directory. Supports ${HOME}, ${PROJECT_DIR}
  • secrets — When true, runs the secret scanner on the value
  • server — Glob pattern on the server name

Installation

Installation goes through your MCP client rather than a global install: point it at mcpwall on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

Where it fits

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Mcpwall's toolset — name, filesystem-mcp.yaml, github-mcp.yaml and 11 more — is a fair guide to whether it matches your workflow. It is maintained by behrensd; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Mcpwall's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 14 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Mcpwall.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Available tools

ToolWhat it does
nameblock-ssh-keys
filesystem-mcp.yamlrestricts reads/writes/listings to ${PROJECT_DIR}, blocks dotfiles and traversal
github-mcp.yamllogs all file reads, blocks broad private repo enumeration
shell-mcp.yamladds network command and package install blocks
Precompiled regexes**: All patterns compiled once at startup for consistent performance
DeterministicSame input + same rules = same output, every time
MatcherDescription
regexRegular expression test on the value
patternGlob pattern (uses [minimatch](https://github.com/isaacs/minimatch))
not_underMatches if path is NOT under the given directory. Supports ${HOME}, ${PROJECT_DIR}
secretsWhen true, runs the secret scanner on the value
serverGlob pattern on the server name
response_containsCase-insensitive substring match against response text
response_contains_regexRegex match against response text

How to install the Mcpwall MCP server

{
  "mcpServers": {
    "MCP_DOCKER": {
      "command": "docker",
      "args": ["mcp", "gateway", "run"]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Example prompts to try

  • Use Mcpwall to name.
  • Use Mcpwall to filesystem-mcp.yaml.
  • Use Mcpwall to github-mcp.yaml.

Frequently asked questions

It connects Mcpwall to MCP-compatible AI assistants such as Claude and Cursor, exposing 14 tools (name, filesystem-mcp.yaml, github-mcp.yaml, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Mcpwall directly.