Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
bpolania avatar

Bulwark

  • 4 repo stars
  • Updated February 25, 2026
  • bpolania/bulwark

Bulwark is a MCP server that governs AI agents with content scanning, policy evaluation, audit logs, and session management.

About

Bulwark is an MCP server for AI agent governance aimed at developers and small teams who ship agent features but cannot afford silent policy violations or untracked sessions. It exposes Model Context Protocol tools over stdio so Claude Code, Cursor, and similar clients can scan content, evaluate policies, maintain audit logs, and manage authenticated operator sessions from one place. You point BULWARK_CONFIG at a bulwark.yaml file and authenticate operators with BULWARK_SESSION_TOKEN when your workflow needs accountable control rather than hope-and-prompt discipline. Use it when agents touch sensitive domains, customer data, or regulated wording—not for every hobby script. Version 0.2.0 packages the server as a containerized mcp start entrypoint, which fits developers already running MCP stacks in Docker or local orchestration.

  • Content scanning on agent inputs and outputs against configurable policies
  • Audit logs for operator review and compliance trails
  • Policy evaluation engine driven by bulwark.yaml configuration
  • Session management with operator tokens (bwk_sess_...) for authenticated control
  • stdio MCP transport via OCI image ghcr.io/bpolania/bulwark:v0.2.0

Bulwark by the numbers

  • Data as of Jul 7, 2026 (Skillselion catalog sync)
claude mcp add Bulwark -- npx -y bpolania/bulwark

Add your badge

Show developers this MCP server is listed on Skillselion. Paste this into your README.

Listed on Skillselion
repo stars4
Last updatedFebruary 25, 2026
Repositorybpolania/bulwark

What it does

Run policy checks, content scans, and audited agent sessions when you need guardrails around what Claude or Codex can say and do in production.

Who is it for?

Best when you're shipping customer-facing agents and need lightweight policy and audit hooks without building a custom compliance platform.

Skip if: Skip if you only need local linting on code or and have no agent surface area requiring content or session governance.

What you get

After you register Bulwark, your agent stack can enforce policies from YAML, log decisions, and tie operator actions to authenticated sessions.

  • Policy-evaluated agent interactions with configurable scanning
  • Persisted audit log stream for governance review
  • Managed operator sessions bound to secret session tokens

By the numbers

  • Server version 0.2.0
  • stdio transport via OCI image ghcr.io/bpolania/bulwark:v0.2.0
  • Two configured environment variables: BULWARK_CONFIG and BULWARK_SESSION_TOKEN
README.md

Bulwark

Open-source governance layer for AI agents.

Bulwark sits between AI agents and external tools, enforcing policies, managing credentials, inspecting content, and maintaining a complete audit trail. One policy governs all your agents — Claude Code, OpenClaw, Codex, or any MCP/HTTP client.

Why Bulwark?

AI agents are powerful but ungoverned. They can access any tool, leak any credential, and leave no audit trail. Bulwark fixes this:

  • Policy enforcement — YAML-based rules control which tools agents can use, with glob patterns, scope-based precedence, and hot-reload
  • Credential management — Agents never see real secrets. Bulwark injects credentials at the last mile, encrypted at rest with age
  • Content inspection — Scan requests and responses for secrets, PII, and prompt injection. Block or redact automatically
  • Audit logging — Every action recorded in a tamper-evident SQLite database with blake3 hash chains
  • Rate limiting — Token-bucket rate limits per session, operator, tool, or globally. Cost tracking with budget enforcement
  • MCP-native — Works as an MCP gateway or HTTP forward proxy. Governance metadata on every tool call response

Install

# Homebrew (macOS / Linux)
brew install bpolania/tap/bulwark

# Docker
docker pull ghcr.io/bpolania/bulwark

# From source
git clone https://github.com/bpolania/bulwark.git
cd bulwark && cargo build --release

Quick Start: Govern Claude Code with GitHub

This walkthrough connects Claude Code to GitHub through Bulwark. Every tool call is policy-evaluated, audited, and credential-injected — in about 5 minutes.

Prerequisites: Claude Code installed, a GitHub personal access token, and Node.js/npm (for the GitHub MCP server).

1. Initialize and verify

bulwark init my-project && cd my-project
bulwark doctor

doctor runs 9 diagnostic checks. All should pass.

2. Store your GitHub token

bulwark cred add github-token --type bearer_token
# Prompts for the token — hidden input, encrypted with age at rest

Configure the credential-to-tool binding in your bindings file so Bulwark knows to inject this token for GitHub tool calls.

3. Configure the upstream GitHub server

Edit bulwark.yaml:

mcp_gateway:
  upstream_servers:
    - name: github
      command: "npx"
      args: ["-y", "@modelcontextprotocol/server-github"]
      env:
        GITHUB_PERSONAL_ACCESS_TOKEN: "${GITHUB_TOKEN}"

policy:
  policies_dir: "./policies"
  hot_reload: true

audit:
  enabled: true

inspect:
  enabled: true
  inspect_requests: true
  inspect_responses: true

Make sure GITHUB_TOKEN is set in your shell (export GITHUB_TOKEN=ghp_...).

4. Write a policy

cat > policies/base.yaml << 'EOF'
metadata:
  name: quickstart-policy
  scope: global

rules:
  - name: allow-reads
    description: "Allow all read operations"
    match:
      actions: ["read_*", "get_*", "list_*", "search_*"]
    verdict: allow
    priority: 10

  - name: allow-github-writes
    description: "Allow creating issues, comments, PRs"
    match:
      tools: ["github__*"]
      actions: ["create_*", "update_*"]
    verdict: allow
    priority: 10

  - name: block-destructive
    description: "Block all delete and force-push operations"
    match:
      actions: ["delete_*", "force_push_*"]
    verdict: deny
    priority: 20
    message: "Destructive operations are blocked by policy"

  - name: default-deny
    match: {}
    verdict: deny
    priority: -100
    message: "No policy explicitly allows this action"
EOF

bulwark policy validate

5. Create a session and connect Claude Code

# Create a session (--ttl is in seconds: 28800 = 8 hours)
bulwark session create --operator $(whoami) --agent-type claude-code --ttl 28800
# → Token: bwk_sess_7f3a...

export BULWARK_SESSION="bwk_sess_7f3a..."   # paste your actual token

# Register Bulwark as an MCP server in Claude Code
claude mcp add --transport stdio bulwark \
  --env BULWARK_SESSION=$BULWARK_SESSION \
  -- bulwark mcp start

6. Use Claude Code — now governed

Start Claude Code. GitHub tools appear namespaced as github__list_issues, github__create_issue, etc.

Try it:

"List the open issues in my repo"

Open a second terminal:

bulwark audit tail
22:01:03  github__list_issues   ✓ allow   3ms  (allow-reads)

Every call is logged with the verdict, matched rule, and timing. Now try something destructive:

"Delete issue #1"

22:02:01  github__delete_issue  ✗ deny    <1ms (block-destructive)

Blocked. Sub-millisecond — policy evaluation happens in memory. The agent gets a structured error explaining which rule denied it.

What just happened

Claude Code connected to Bulwark (not directly to GitHub). For every tool call, Bulwark validated the session, scanned for secrets/PII, evaluated the policy, injected the real GitHub token, scanned the response, and recorded a tamper-evident audit event. Same agent experience — full governance underneath.

Going Deeper

Content inspection — 13 built-in patterns scan for AWS keys, GitHub tokens, private keys, PII, and prompt injection. Redaction happens before content reaches the agent.

bulwark inspect rules
bulwark inspect scan --text "my key is AKIAIOSFODNN7EXAMPLE"

Policy replay — Preview the impact of policy changes against real audit history before deploying:

bulwark policy test --dir ./new-policies/ --since 1h

Audit forensics — Reconstruct a session timeline and verify the hash chain:

bulwark session inspect <session-id>
bulwark audit verify
bulwark audit export --since 24h --format json

HTTP proxy mode — For non-MCP agents, Bulwark runs as a forward proxy with TLS interception:

bulwark proxy start
bulwark ca export   # trust the CA in your HTTP client

Architecture

┌─────────────┐     ┌──────────────────────────────────────────────┐     ┌──────────────┐
│             │     │                  Bulwark                      │     │              │
│  AI Agent   │────>│  Session > Inspect > Policy > Inject > Proxy │────>│  Upstream    │
│  (Claude,   │<────│  <── Audit <── Inspect <── Response <─────── │<────│  Tool/API    │
│   Codex,    │     │                                              │     │              │
│   custom)   │     └──────────────────────────────────────────────┘     └──────────────┘
└─────────────┘

Integration Modes

Mode Transport Best For
MCP Gateway (stdio) stdio/JSON-RPC Claude Code, OpenClaw, any MCP client
MCP Gateway (HTTP) Streamable HTTP Remote agents, MCP registry, multi-agent
HTTP Proxy HTTP/HTTPS Codex, curl, any HTTP client

Example Policy

# policies/base.yaml
metadata:
  name: my-policy
  scope: global

rules:
  - name: allow-reads
    verdict: allow
    priority: 10
    match:
      actions: ["read*", "get*", "list*"]

  - name: block-destructive-in-prod
    verdict: deny
    priority: 100
    match:
      actions: ["delete*", "drop*"]
    conditions:
      environments: ["production"]

  - name: default-deny
    verdict: deny
    match: {}

See examples/policies/ for complete policy sets (startup, enterprise, development, multi-agent).

CLI

bulwark init <path>              # Scaffold a new project
bulwark proxy start              # Start HTTP/HTTPS proxy
bulwark mcp start                # Start MCP gateway (stdio)
bulwark mcp serve                # Start MCP gateway (HTTP)
bulwark doctor                   # Diagnose setup issues (9 checks)
bulwark status                   # Health dashboard
bulwark policy validate          # Validate policy files
bulwark policy test --dir <path> # Test policies against audit log
bulwark session create|list|revoke|inspect
bulwark cred add|list|remove|test
bulwark audit search|tail|stats|export|verify
bulwark inspect scan|rules       # Content inspection
bulwark ca export|path           # CA certificate management
bulwark completions <shell>      # Shell completions (bash/zsh/fish)

Documentation

Development

git clone https://github.com/bpolania/bulwark.git
cd bulwark
cargo build --workspace
cargo test --workspace          # 487 tests
cargo clippy --workspace --all-targets -- -D warnings

Project Structure

crates/
  cli/        # CLI binary and commands
  proxy/      # HTTP/HTTPS forward proxy with TLS MITM
  mcp/        # MCP governance gateway
  config/     # Configuration loading and types
  policy/     # YAML policy engine with hot-reload
  vault/      # Credential storage and session management
  audit/      # Tamper-evident audit logging
  inspect/    # Content inspection (secrets, PII, injection)
  ratelimit/  # Token-bucket rate limiter and cost tracker
  common/     # Shared types and error definitions

License

Apache 2.0. See LICENSE.

Recommended MCP Servers

How it compares

Agent governance MCP server with audit and policy tooling, not a general-purpose LLM proxy or a static security scanner skill.

FAQ

Who is Bulwark for?

Bulwark is for developers and small teams running Claude Code or similar agents who need scanning, policies, and audit trails around autonomous sessions.

When should I use Bulwark?

Use Bulwark when you are in Ship or hardening agent workflows and need configurable rules, logged evaluations, and operator session tokens before going live.

How do I add Bulwark to my agent?

Add the stdio MCP server using the OCI package ghcr.io/bpolania/bulwark:v0.2.0 with arguments mcp start, set BULWARK_CONFIG to your bulwark.yaml path, and supply BULWARK_SESSION_TOKEN for operator auth.

Security & Pentestingauditcomplianceappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.