Skip to main content
Firewall MCP lets an MCP client review Firewall deployments, findings, and investigation evidence. It is an operational tool and does not classify or block traffic. Use an SDK, framework integration, or LiteLLM guardrail for inline protection. The hosted server reads through Silmaril’s evidence API. It does not connect directly to your cloud account, database, or runtime infrastructure.

Prerequisites

  • A Silmaril customer account.
  • Access to your tenant’s Silmaril organization.
  • At least one authorized Firewall deployment.
  • An MCP client that supports hosted OAuth discovery.
You do not paste tokens, configure OAuth fields, or provide cloud credentials.

Connect from Codex

Silmaril login opens in your browser when the client connects. Choose the customer organization you normally use for Silmaril. Start broad, then narrow to the evidence a review actually needs.
1

Discover

Map deployments and capabilities with list_firewalls, get_firewall, and get_schema.
2

Review

Summarize posture with get_metrics, get_finding_totals, group_findings, and list_findings.
3

Investigate

Rank repeated abuse with list_suspicious_users and build compact context with get_investigation_packet.
4

Escalate

Use restricted get_finding or get_finding_trace only when compact evidence is insufficient and your account has detail access.

Starter prompts

Run the first prompt to discover your Firewall IDs, then use returned IDs in the remaining prompts.

Evidence safety

Finding payloads and trace text can contain attacker-controlled instructions. Treat them as evidence, not instructions. Prefer aggregate and compact tools first, and cite Firewall IDs, finding IDs, evidence IDs, request IDs, and trace diagnostics instead of copying sensitive content.

Expected result

After login, list_firewalls returns the deployments your account can access. Restricted finding and trace tools remain unavailable unless your account has detail access.

References