The AI Firewall: Inside experimental-ext-interceptors

How a proposed middleware extension is turning the Model Context Protocol from a raw communication channel into a secure, auditable standard.

7 min read • View on GitHub • More from modelcontextprotocol

A chaotic telephone switchboard being replaced by clean, glowing layers of glass. This represents the transition from ad-hoc custom proxies to a standardized middleware layer.
SEP-1763 aims to replace fragile custom proxy networks with a unified interception standard.

Standardizing interceptors in the same plug-and-play fashion that made MCP tools successful.

Key Takeaways

The "M x N" Proxy Nightmare

The Model Context Protocol gave AI models a universal plug to connect to external data. It did not, however, provide a way to filter the electricity passing through that plug. Developers are currently forced to build custom, fragile sidecars to handle PII redaction, logging, or prompt injection blocks. This creates an unscalable matrix of bespoke proxies.

Hedcut portrait of sambhav

The Asymmetry of Trust

The most elegant part of this architecture lives inside the execution engine. It recognizes that trust boundaries are asymmetric. If you send data to an untrusted server, you must mutate and sanitize it first, then validate the final payload. If you receive data from an untrusted server, you must validate it first before allowing any local mutations.

A split composition showing two conveyor belts handling packages differently based on direction. This illustrates the alternating execution order of mutation and validation.
Outgoing requests are sanitized before inspection. Incoming responses are inspected before unwrapping.

The Three Pillars of Interception

The project abstracts interception into three distinct types: Validation, Mutation, and Observability. Validation blocks malicious payloads. Mutation transforms them. Observability logs them. To balance speed and safety, validations run in parallel, while mutations are forced to execute sequentially.

The execution pipeline dynamically adjusts its strict sequential and parallel processing based on the direction of the payload.

The Decorator Illusion

The implementation relies heavily on the Decorator pattern. A wrapper class intercepts standard client calls and injects the complex, multi-stage pipeline. This allows developers to bolt interception logic onto any existing client without rewriting their core application logic.

var client = new InterceptingMcpClient(baseClient)
    .WithInterceptors(interceptors);

// The complex pipeline is entirely hidden from the caller
await client.CallToolAsync(toolRequest);

Building a Polyglot Standard

While the C# SDK is the primary reference, the repository is structured as a polyglot monorepo. It lays the groundwork for Python, TypeScript, and Go implementations. Sophisticated continuous integration ensures that as the proposed protocol evolves, the behavior remains identical across entirely different technology stacks.