A WAF That Reads the Prompt: OWASP CRS for LLM and MCP
This story is from 2026-09-20. It is preserved in the archive; the latest stories are on the live feed.
Originally published at webofmike.com on 2026-09-20. The demo repo and every command in it were run before publishing. A conventional web application firewall reads a URL, some headers, and maybe a form body. For agent traffic that is the wrong layer. The interesting content is in the request body:…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-20 16:09 · DEV Community — AI
A WAF That Reads the Prompt: OWASP CRS for LLM and MCP