The AI Firewall: Inside experimental-ext-interceptors
How a proposed middleware extension is turning the Model Context Protocol from a raw communication channel into a secure, auditable standard.

Standardizing interceptors in the same plug-and-play fashion that made MCP tools successful.
- The experimental interceptors repository formalizes middleware for the Model Context Protocol, solving the fragmented proxy integration problem.
- Execution order shifts dynamically based on trust boundaries, mutating outgoing data first but validating incoming data first.
- The architecture separates concerns into parallel non-blocking observability and validation, alongside sequential blocking mutation.
- A decorator pattern allows developers to inject complex interception pipelines into existing MCP clients with a single extension method.
The "M x N" Proxy Nightmare
The Model Context Protocol gave AI models a universal plug to connect to external data. It did not, however, provide a way to filter the electricity passing through that plug. Developers are currently forced to build custom, fragile sidecars to handle PII redaction, logging, or prompt injection blocks. This creates an unscalable matrix of bespoke proxies.
The Asymmetry of Trust
The most elegant part of this architecture lives inside the execution engine. It recognizes that trust boundaries are asymmetric. If you send data to an untrusted server, you must mutate and sanitize it first, then validate the final payload. If you receive data from an untrusted server, you must validate it first before allowing any local mutations.
The Three Pillars of Interception
The project abstracts interception into three distinct types: Validation, Mutation, and Observability. Validation blocks malicious payloads. Mutation transforms them. Observability logs them. To balance speed and safety, validations run in parallel, while mutations are forced to execute sequentially.
The Decorator Illusion
The implementation relies heavily on the Decorator pattern. A wrapper class intercepts standard client calls and injects the complex, multi-stage pipeline. This allows developers to bolt interception logic onto any existing client without rewriting their core application logic.
var client = new InterceptingMcpClient(baseClient)
.WithInterceptors(interceptors);
// The complex pipeline is entirely hidden from the caller
await client.CallToolAsync(toolRequest);
Building a Polyglot Standard
While the C# SDK is the primary reference, the repository is structured as a polyglot monorepo. It lays the groundwork for Python, TypeScript, and Go implementations. Sophisticated continuous integration ensures that as the proposed protocol evolves, the behavior remains identical across entirely different technology stacks.