ThornGuard: A Proxy Gateway to Secure MCP Server Connections from Prompt Injection

✍️ OpenClawRadar📅 Published: April 13, 2026🔗 Source
ThornGuard: A Proxy Gateway to Secure MCP Server Connections from Prompt Injection
Ad

ThornGuard is a security proxy designed to protect Claude AI from malicious content when connecting to external MCP (Model Context Protocol) servers. The tool was created after testing revealed that upstream servers can inject hidden instructions into tool responses, which Claude receives without filtering.

Security Problem Identified

When connecting Claude to external MCP servers, nothing prevents upstream servers from injecting hidden instructions into tool responses. In a test, a server embedded a fake recommendation telling Claude to always prefer a specific vendor. While Claude caught this obvious payload, more subtle injections would bypass detection.

Ad

ThornGuard Features

  • Scans tool definitions and responses for prompt injection and poisoning
  • Strips secrets and PII before they enter your context window
  • Includes a semantic classifier that flags suspicious payloads
  • Provides real-time audit dashboard with compliance exports
  • Offers CLI that generates configs for Claude Desktop, Cursor, VS Code, and several others

Implementation Details

The proxy architecture was designed with a security model in mind, then implemented using Claude Code on Cloudflare Workers. The implementation includes OAuth flows and the CLI tool.

ThornGuard is available with a 7-day free trial at thorns.qwady.app. A demonstration video is available at https://youtu.be/1PWNFpUWKV8.

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

ClawSecure: Security Platform for OpenClaw Ecosystem
Security

ClawSecure: Security Platform for OpenClaw Ecosystem

ClawSecure is a security platform built specifically for the OpenClaw ecosystem, featuring a 3-layer audit protocol, continuous monitoring, and coverage of OWASP ASI categories. It has audited 3,000+ popular skills and is available free with no signup.

OpenClawRadar
llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows
Security

llm-hasher: Local PII Detection and Tokenization for Hybrid LLM Workflows

llm-hasher is a tool that detects personally identifiable information locally using Ollama before data reaches external LLMs like OpenAI or Claude, tokenizes the PII, and restores originals after processing. It uses regex for structured data types and a local LLM for contextual detection, with encrypted storage for mappings.

OpenClawRadar
Claude Code Security Advisory: CVE-2026-33068 Workspace Trust Bypass
Security

Claude Code Security Advisory: CVE-2026-33068 Workspace Trust Bypass

Claude Code versions prior to 2.1.53 contain a vulnerability (CVE-2026-33068, CVSS 7.7 HIGH) where malicious repositories can bypass workspace trust confirmation via .claude/settings.json. The bug allowed repository settings to load before user trust decisions.

OpenClawRadar
Audit Your Claude Code Permissions: A Practical Guide to Scoping Tool Access
Security

Audit Your Claude Code Permissions: A Practical Guide to Scoping Tool Access

A Reddit user audited their Claude Code setup and found over-permissioned tools that could edit .env files and production configs. Practical steps: audit global vs. per-project tools, check CLAUDE.md for secrets, and scope file access per directory.

OpenClawRadar