Works with the AI tools you already use
mcp semantic firewall policy generator
Generate portable, fail-closed security policy files for MCP agents to prevent unauthorized destructive tool calls.
$14
mcp semantic firewall policy generator
Example session with this skill installed
Generate a policy for my MCP database server. I want to allow all reads, but any delete affecting more than 5 rows needs human approval via our PagerDuty API. Use AgentFence YAML format.
- Read your context and instructions
- Compiled the mcp semantic firewall
I have inventoried the database tools and mapped them to blast-radius tiers. The resulting policy uses an explicit-deny-wins evaluation order and includes a cumulative session window to prevent threshold bypasses.
MCP Semantic Firewall Policy
# Generated by MCP Semantic Firewall Policy Generator
# Schema Version: 2026-08-06
# Integrity Hash: 5e8f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f
# Target Enforcer: AgentFence
defaults:
decision: ask
evaluation_order: explicit-deny-wins
tools:
- name_pattern: "read_*"
decision: allow
classification: low-sensitivity-read
wildcard_reinventory_required: true
- name_pattern: "delete_*"
decision: ask
classification: destructive-write
constraints:
- field: "row_count"
operator: "gt"
value: 5
cumulative_scope: session
cumulative_limit: 20
approval_channel: "pagerduty://service/P12345/trigger"
verification: "empirical_dry_run"
- name_pattern: "*"
decision: deny
Next steps
1.
Pin the Hash: Store the Integrity Hash in your CI/CD secrets or a protected config store. Configure your enforcer to fail if the file's current SHA-256 (canonicalized) does not match this pin.
2.
Set Write Permissions: Ensure the filesystem path for this YAML is owned by a root or ops identity and is read-only for the service account running the agent.
3.
Wire PagerDuty: Confirm the approval_channel URI is correctly routed in your gateway to trigger the specific escalation policy.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most MCP tool security relies on agent reasoning, which fails if the agent is compromised or over-confident. This skill generates the technical config layer that agents cannot bypass: a portable, static approve/deny/human-in-the-loop policy file. It treats tool risk as a function of blast radius and reversibility, not just tool names, producing machine-readable artifacts that enforcers like AgentFence or custom proxies can consume.
What it does
- Inventory and classification identifies every tool in the stack and maps it to blast-radius categories like single-record, bulk, or cross-system.
- Fail-closed policy generation emits a neutral JSON schema where unmatched calls default to deny or ask, never allow.
- Integrity hardening computes canonicalized content hashes (SHA-256) and schema versions to detect unauthorized policy modifications by the agent.
- Cumulative tracking defines session and window-based limits to prevent "salami slicing" attacks where multiple small calls evade single-call thresholds.
- Enforcer mapping translates the neutral policy into specific formats for AgentFence, OPA Rego, or custom gateways.
How it works
- Inventory tools by reading their handler signatures to determine what they can do, rather than what they are named.
- Draft rules in a human-readable table to define thresholds for auto-approval versus human-in-the-loop escalation.
- Generate artifacts by producing the hardened JSON policy file and specific enforcer mappings.
- Deploy and verify by following provided guidance to store policies and reference hashes in locations inaccessible to the agent.
Frameworks & tools
This skill produces artifacts compatible with the Model Context Protocol (MCP). It supports output formats for AgentFence, Open Policy Agent (OPA/Rego), and standard JSON/YAML enforcers.
Why this beats prompting it yourself
Prompt-based constraints are suggestions the agent can ignore when under pressure or compromised. This skill produces a technical config artifact that sits outside the agent's reasoning loop, providing a verifiable "semantic firewall" that works even if the agent is actively trying to bypass it.
Use cases
- Restricting destructive database writes to require human approval via a specific Slack channel.
- Preventing an agent from "salami slicing" a bulk delete into fifty single-row calls.
- Hardening a production MCP deployment against self-modifying policy attacks.
- Translating informal company rules into versioned, machine-readable security policies.
Known limitations
Does not provide a running proxy or interceptor; you must provide the enforcer. Requires an external human-in-the-loop channel for escalation rules to be effective.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 day ago
- Passed all security checks, Safe to install