# Block agent egress, MCP prompt injection, and secret exfiltration before agents touch the open internet with Pipelock

> Put an inline firewall and containment layer in front of agent network traffic, tool calls, and MCP traffic before you trust an agent with local secrets.

- Skill: `agentskillexchange/block-agent-egress-mcp-prompt-injection-and-secret-exfiltrat` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/block-agent-egress-mcp-prompt-injection-and-secret-exfiltrat`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/block-agent-egress-mcp-prompt-injection-and-secret-exfiltrat/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/block-agent-egress-mcp-prompt-injection-and-secret-exfiltrat

---


# Block agent egress, MCP prompt injection, and secret exfiltration before agents touch the open internet with Pipelock

Put an inline firewall and containment layer in front of agent network traffic, tool calls, and MCP traffic before you trust an agent with local secrets.

## Prerequisites

Homebrew or Go, terminal, supported agent runtime or IDE integration

## Installation

Use the upstream install or setup path that matches your environment:
- brew install luckyPipewrench/tap/pipelock
- docker pull ghcr.io/luckypipewrench/pipelock:latest
- go install github.com/luckyPipewrench/pipelock/cmd/pipelock@latest
- docker run -p 8888:8888 -v ./pipelock.yaml:/config/pipelock.yaml:ro \

Requirements and caveats from upstream:
- pipelock check --url "https://docs.python.org/3/" # allowed
- # Docker
- # From source (requires Go 1.25+)

Basic usage or getting-started notes:
- [Quick Start](#quick-start) · [What It Does](#what-it-does) · [Docs](docs/) · [Blog](https://pipelab.org/blog/) · [Ask Dosu](https://app.dosu.dev/bcccd1cf-be85-4c0e-ae05-edeb0ff50b59/ask)
- bash
- # Set up (discovers IDE configs, generates config, verifies detection)

- Source: https://github.com/luckyPipewrench/pipelock
- Extracted from upstream docs: https://raw.githubusercontent.com/luckyPipewrench/pipelock/HEAD/README.md

## Documentation

- https://pipelab.org

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/block-agent-egress-mcp-prompt-injection-and-secret-exfiltration-before-agents-touch-the-open-internet-with-pipelock/)

