Open-Source MCP Proxy Aggrete Blocks AI Tool Attacks Using Deterministic Rules
A new open-source tool called Aggrete acts as a proxy for Model Context Protocol (MCP) systems, blocking known AI security attacks through deterministic rules rather than probabilistic AI-based filters. Unlike model-driven defenses, Aggrete applies fixed policy rules before any upstream server is contacted, ensuring the same request always receives the same response. The tool addresses three major attack types: the "lethal trifecta" prompt-injection exfiltration method documented by Invariant Labs in 2025, tool poisoning via hidden instructions in tool descriptions, and rug pulls where tool definitions are swapped after approval. Aggrete counters these by tracking session-level data flows, fingerprinting tools on first use, and scanning descriptions for malicious patterns — all without involving a language model in the decision. The project is installable via pip and ships with reproducible attack demonstration scripts that run locally without servers, API keys, or network access.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in