Skip to main content

Agentic MCP proxy

Agentic AI introduces a risk class that prompt inspection alone never sees: indirect prompt injection. Nobody types anything malicious. The attacker plants instructions in a wiki page, a document, or an email that the AI agent fetches through a tool. The MCP proxy sits between the agent and its tool servers and inspects both directions.

Wrap a server​

lumen-agent mcp wraps any stdio MCP server. The agent client launches the proxy, and the proxy launches the real server:

lumen-agent mcp --policy mcp-policy.yaml -- python3 tool_server.py
  • Tool calls, from client to server, are inspected as prompts: arguments carrying secrets can be redacted before they reach a third-party server.
  • Tool results, from server to client, are inspected as responses, because third-party data entering the model's context is exactly where indirect injection lives. A poisoned result is blocked before the model reads it:
the model receives: Blocked by Lumen policy: rule pr_injection: prompt_injection score 0.98 >= 0.80

See Indirect injection for what this looks like as a finding in the console.

Streamable HTTP with SSE​

MCP's second transport, streamable HTTP with SSE, is part of the same design, and it is not implemented yet. Today lumen-agent mcp wraps stdio servers only, so a remote MCP server reached over HTTP is not inspected. Point the tools you want covered at stdio servers until this lands.

note

Claude Code sessions get a second, complementary guard through the agent's hook collector, which sees the local actions, such as shell commands and file writes, that no MCP proxy witnesses.