Skip to content

Runwall v4.1.0 — Response Scanning and Egress Enforcement

Choose a tag to compare

@efij efij released this 29 Mar 23:10
· 26 commits to main since this release

Runwall v4.1.0 verifies the inline MCP gateway foundation and adds the next two major runtime-control layers on top of it.

Highlights:

  • verified the inline MCP / tool-call gateway against the original PRD scope
  • added deterministic response scanning before tool output reaches the runtime
  • added JSON-safe redaction so structured MCP responses stay valid where possible
  • added response-side prompt and block flows for suspicious URLs and staged shell snippets
  • added per-profile outbound destination policy for private IPs, metadata endpoints, webhooks, paste sites, gist-like hosts, blob targets, and non-allowlisted egress
  • added five new gateway-era guards:
    • mcp-response-suspicious-url-guard
    • mcp-response-shell-snippet-guard
    • mcp-egress-private-network-guard
    • mcp-egress-destination-class-guard
    • mcp-egress-policy-guard
  • updated the local gateway dashboard so request, response, and outbound decisions are easier to inspect
  • fixed Windows audit output by removing non-ASCII score bars that were breaking CI consoles

Verification:

  • claude plugin validate .
  • ./bin/runwall audit . --profile strict --format json
  • bash tests/smoke.sh
  • bash scripts/package-release.sh efij/secure-claude-code 4.1.0