| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
An MCP server that lets an LLM author, validate, and test Wirefilter WAF and Smart Firewall rules — grounded in live schema and real CVE exploit templates instead of guesswork.
What it does:
Runs anywhere Python 3.12+ runs · ships as a Claude Desktop bundle, a stdio MCP server, or an HTTP container
# Prerequisites: mcpb (npm install -g @anthropic-ai/mcpb)
make pack # produces the thin, portable gen0sec-mcp-server.mcpbOpen the generated gen0sec-mcp-server.mcpb file — Claude Desktop installs it in about a minute, after which the tools, resources, and prompts are available.
The GitHub release ships two .mcpb files:
The extension picks the right path automatically; the only difference is whether a one-time network install can happen at first launch. Set Path to Python executable in the extension config to a Python ≥ 3.12 if the default python3 isn't suitable.
Building locally:
make pack # thin bundle (release default)
make vendor-multi # add this host's ABI dir to server/lib/<abi-tag>/
make pack-offline # offline bundle from whatever ABI dirs are presentThe full cross-platform offline bundle is assembled in CI, where each target is vendored natively (see .github/workflows/offline-bundle.yaml).
Add to ~/.cursor/mcp.json (%USERPROFILE%\.cursor\mcp.json on Windows):
{
"mcpServers": {
"waf-rule-mcp": {
"command": "uv",
"args": [
"run",
"--project", "/absolute/path/to/mcp-server",
"/absolute/path/to/mcp-server/server/main.py"
],
"env": {
"WAF_VALIDATION_API_URL": "https://public.gen0sec.com/v1/waf/validate"
}
}
}
}WAF_VALIDATION_API_URL is optional — if unset, the value from server/config.yaml is used. Restart Cursor to apply.
docker build -t waf-rule-mcp .
docker run -p 8000:8000 waf-rule-mcpThen point your MCP client at it:
{
"mcpServers": {
"waf-rule-mcp": { "url": "http://localhost:8000" }
}
}The WAF rule validation API must be reachable for the validation tools to work. Set its URL via WAF_VALIDATION_API_URL or server/config.yaml.
| Tool | Purpose |
|---|---|
| fetch_cve_vulnerability_template | Retrieve a CVE-indexed vulnerability template from a preferred source (Nuclei Open Source or Nuclei Paid API) |
| fetch_cve_from_all_sources | Fetch a CVE template from all enabled sources for cross-source comparison |
| list_cve_sources | List the registered CVE source plugins and their status |
| validate_waf_expression | Validate a Wirefilter rule expression (rule_type selects the scheme) |
| validate_waf_expression_with_tests | Validate a Wirefilter rule and match it against test data (mock data if none given) |
| get_waf_context | Fetch WAF context from Wirefilter docs: actions, expressions, fields, functions, operators, values |
| get_rule_fields | Fetch the live, authoritative Wirefilter field/function schema directly from the rules-validator |
| URI | Reference |
|---|---|
| wafcontext://actions | Actions available in the Rules language |
| wafcontext://expressions | Expressions available in the Rules language |
| wafcontext://fields | Fields available in the Rules language |
| wafcontext://functions | Functions available in the Rules language |
| wafcontext://operators | Operators available in the Rules language |
| wafcontext://values | Values available in the Rules language |
| Prompt | Generates a rule from… |
|---|---|
| natural_waf_rule_generation_prompt | a natural-language description |
| cve_waf_rule_generation_prompt | a CVE index |
| smart_firewall_rule_generation_prompt | a natural-language description, as an L3/L4 + JA4 Smart Firewall rule (no http.* fields; block/allow actions) |
flowchart TD
LLM([Agentic LLM / MCP client]) <--> MCP
subgraph MCP[Gen0Sec WAF Rule MCP Server]
T[Tools]
R["Resources<br/>wafcontext://*"]
P[Prompts]
RU[Resource updater<br/>periodic refresh]
end
T -->|validate / fields| RV[Wirefilter rules-validator API]
R -->|live schema| RV
T -->|CVE templates| CS
subgraph CS[CVE sources]
N1[Nuclei Open Source<br/>GitHub]
N2[Nuclei Paid<br/>ProjectDiscovery API]
end
RU -.refreshes.-> CS
RU -.refreshes.-> RV
| Gen0Sec Docs | Product documentation and guides |
| server/config.yaml | Validation API URL, CVE source toggles, update intervals |
| manifest.json | Claude Desktop bundle manifest and user-configurable options |
| Wirefilter | The rule expression language this server targets |
| Back | FazBrowse Home | New Git URL |