secpipe: The Zero-Trust Agent: Inside pipelock

How a single Go binary acts as a local firewall to stop autonomous coding agents from exfiltrating your secrets.

7 min read • View on GitHub • More from FuzzingLabs

A mechanical robot arm reaching into a physical filing cabinet past a bypassed ghostly vault door, illustrating the vulnerability of runtime agent access.
Static defenses fail when an autonomous agent is already inside the perimeter.
Key Takeaways

The Runtime Blind Spot

We are giving autonomous AI agents the keys to our local machines, but we are protecting them with outdated, pre-execution static analysis. Recent research exposed a terrifying reality of modern agent development: roughly 7% of standard agent skills on ClawHub contain critical security flaws that expose API keys. Static analysis tools cannot catch an agent deciding to POST your AWS keys to a random server at runtime due to a hallucinated parameter or a prompt injection attack.

The Untrusted Colleague

Instead of trying to write perfectly secure agent prompts or relying on model guardrails, pipelock assumes the agent will eventually act insecurely. It places a hard, local-first boundary around the process, enforcing Data Loss Prevention (DLP) and SSRF protection regardless of what the LLM decides to do. It introduces the zero-trust network paradigm to local AI development.

Firewall for AI agents. DLP scanning, SSRF protection, bidirectional MCP scanning, tool poisoning detection, and prompt injection blocking.

luckyPipewrench, Project Creator · luckyPipewrench/pipelock

Intercepting the Protocol

Under the hood, pipelock acts as a forward proxy, intercepting both standard HTTP traffic and Model Context Protocol (MCP) communications. It inspects payloads bidirectionally, ensuring that outbound requests don't contain secrets and inbound prompts don't contain injection payloads. Built entirely in Go, it handles high-throughput local traffic with negligible latency overhead.

The Bidirectional Proxy Flow intercepting and validating agent traffic.

The Zero-Code Integration

Security tools that require developers to rewrite their agent orchestration logic are rarely adopted. Because pipelock is a standalone Go binary operating as a proxy, developers simply export an HTTP proxy environment variable, and the agent is instantly contained. No code changes are required to secure the runtime environment.

# Start the pipelock daemon
pipelock serve --config ~/.pipelock.yaml

# Route agent traffic through the firewall
export HTTP_PROXY=http://127.0.0.1:8080
export HTTPS_PROXY=http://127.0.0.1:8080

# Run your agent normally
claude

Static Scanning vs. Runtime Containment

While static tools find known bad code before execution, pipelock stops unknown bad behavior in flight. Static scanning is a precursor defense; runtime containment is the active shield that protects your environment when the static defenses fail.

A split scene comparing a passive checklist on a desk to an active industrial turnstile scanning a package.
Static scanning passively checks code before execution, while runtime containment actively inspects payloads in flight.
FeatureStatic Agent ScannersRuntime Firewalls (pipelock)
Execution PhasePre-runIn-flight
Detection MethodSignature matchingPayload and Network inspection
Primary DefenseFinding vulnerable codeBlocking exfiltration and SSRF
IntegrationCI/CD pipelineLocal daemon/proxy