A JSON-RPC firewall for MCP agents — inspects every tools/call between an LLM and its MCP servers, blocking argument injection and capability creep before they reach the host.