iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
Connect Mcpwall to Claude, Cursor or any other MCP client and it stops being a tab you switch to. iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything. The mcpwall mcp server is what makes that connection.
Sits between your AI coding tool (Claude Code, Cursor, Windsurf) and MCP servers, intercepting every JSON-RPC message and enforcing YAML-defined policies.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
name — block-ssh-keysfilesystem-mcp.yaml — restricts reads/writes/listings to ${PROJECT_DIR}, blocks dotfiles and traversalgithub-mcp.yaml — logs all file reads, blocks broad private repo enumerationshell-mcp.yaml — adds network command and package install blocksPre — compiled regexes**: All patterns compiled once at startup for consistent performanceDeterministic — Same input + same rules = same output, every timeMatcher — Descriptionregex — Regular expression test on the valuepattern — Glob pattern (uses minimatch)not_under — Matches if path is NOT under the given directory. Supports ${HOME}, ${PROJECT_DIR}secrets — When true, runs the secret scanner on the valueserver — Glob pattern on the server nameInstallation goes through your MCP client rather than a global install: point it at mcpwall on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Mcpwall's toolset — name, filesystem-mcp.yaml, github-mcp.yaml and 11 more — is a fair guide to whether it matches your workflow. It is maintained by behrensd; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Mcpwall's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| name | block-ssh-keys |
| filesystem-mcp.yaml | restricts reads/writes/listings to ${PROJECT_DIR}, blocks dotfiles and traversal |
| github-mcp.yaml | logs all file reads, blocks broad private repo enumeration |
| shell-mcp.yaml | adds network command and package install blocks |
| Pre | compiled regexes**: All patterns compiled once at startup for consistent performance |
| Deterministic | Same input + same rules = same output, every time |
| Matcher | Description |
| regex | Regular expression test on the value |
| pattern | Glob pattern (uses [minimatch](https://github.com/isaacs/minimatch)) |
| not_under | Matches if path is NOT under the given directory. Supports ${HOME}, ${PROJECT_DIR} |
| secrets | When true, runs the secret scanner on the value |
| server | Glob pattern on the server name |
| response_contains | Case-insensitive substring match against response text |
| response_contains_regex | Regex match against response text |
{
"mcpServers": {
"MCP_DOCKER": {
"command": "docker",
"args": ["mcp", "gateway", "run"]
}
}
}Configuration as documented by the project. Restart the client after saving.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.