Repository navigation
Runwall v4.1.0 — Response Scanning and Egress Enforcement
Runwall v4.1.0 verifies the inline MCP gateway foundation and adds the next two major runtime-control layers on top of it.
Highlights:
- verified the inline MCP / tool-call gateway against the original PRD scope
- added deterministic response scanning before tool output reaches the runtime
- added JSON-safe redaction so structured MCP responses stay valid where possible
- added response-side prompt and block flows for suspicious URLs and staged shell snippets
- added per-profile outbound destination policy for private IPs, metadata endpoints, webhooks, paste sites, gist-like hosts, blob targets, and non-allowlisted egress
- added five new gateway-era guards:
- mcp-response-suspicious-url-guard
- mcp-response-shell-snippet-guard
- mcp-egress-private-network-guard
- mcp-egress-destination-class-guard
- mcp-egress-policy-guard
- updated the local gateway dashboard so request, response, and outbound decisions are easier to inspect
- fixed Windows audit output by removing non-ASCII score bars that were breaking CI consoles
Verification:
- claude plugin validate .
- ./bin/runwall audit . --profile strict --format json
- bash tests/smoke.sh
- bash scripts/package-release.sh efij/secure-claude-code 4.1.0