Independent testing will determine whether Customhouse’s deterministic MCP proxy reliably blocks agent-driven data exfiltration without materially disrupting legitimate MCP workflows.
state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security mcp-security agent-exfiltration deterministic-proxyVineet PantCustomhouse
What is this?
Customhouse is presented as a deterministic MCP proxy, associated with Vineet Pant and reportedly first named Bulkhead, designed to prevent AI agents from exfiltrating data while preserving legitimate MCP tool use. The supplied web snippets establish the broader pattern: MCP proxies can mediate tool discovery and execution, enforce allowlists and other guardrails, and log agent interactions to reduce exfiltration risk. However, none of the snippets independently tests or even specifically documents Customhouse, so the claim that it reliably blocks exfiltration without materially disrupting valid workflows remains unverified; the web answer asserting confirmation is unsupported by the listed results.
Why it matters to Scott
The core position is already explicit in Scott’s SiloOS and Architecture, Not Vibes pages: treat agents as untrusted and enforce data and capability boundaries through deterministic, proxy-mediated controls. Customhouse could still matter as an MCP-specific implementation and test case for whether this architecture prevents exfiltration without unacceptable workflow friction, directly informing SiloOS and Scott’s production MCP connector; however, the supplied evidence provides no independent results yet.
ip:framework.siloosip:framework.architecture-not-vibesip:concept.proxy-mediated-tokenisationdev:project.silo-osdev:project.mcp-ip-wikiradar:concept.mcp-securityradar:concept.agent-securityradar:opencode-guardians-tool-call-verificationradar:wardline-agent-traffic-proxy
queries asked of Scott's wikis
- deterministic controls around untrusted agents
- MCP tool-call security and authorization
- agent data exfiltration threat models
- proxy guardrails versus model-based safety
- capability boundaries for coding agents
- security controls that preserve agent usability
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-08-22T09:24:18Z
The artifact-specific episode has faded without independent testing, deployment evidence, or benchmark context, and no confirming event is presently expected. The broader deterministic-boundary pattern remains relevant, but Customhouse has not earned continued active tracking.
2026-08-20T08:34:28Z
No independent test, deployment report, or benchmark context has appeared; the 40% false-positive result remains an isolated first-party warning, so the case is still unresolved but no longer time-sensitive.
2026-08-18T07:36:17Z
The first quantified first-party result shifts Customhouse from a merely available artifact to an implementation with a potentially severe usability constraint: deterministic blocking reportedly produces 40% false positives. This weakens the workflow-preservation side of the hypothesis but still requires independent testing and benchmark details.
2026-08-18T07:22:25Z
evidence attached: hn.story.49342237 — First-party documentation reports a substantial false-positive cost for deterministic prompt-injection blocking, materially contextualizing the proxy’s usability tradeoff.
2026-08-16T10:31:05Z
The reobservation adds no independent testing, adoption, or implementation evidence; the case remains a concrete but unvalidated artifact awaiting results on both exfiltration prevention and workflow disruption.
2026-08-16T10:29:08Z
grounded: known/medium — The core position is already explicit in Scott’s SiloOS and Architecture, Not Vibes pages: treat agents as untrusted and enforce data and capability boundaries
2026-08-16T10:26:28Z
origin walked (codex/luna, conf 0.97): anchor hn.story.49318414 -> echo.github.b617f5419e by Vineet Pant
2026-08-16T10:24:51Z
case created — A newly released security proxy is a concrete artifact, but it has only one low-engagement observation and no independent validation yet.
Decision trace
- 08-22 19:24expireThe artifact-specific episode has faded without independent testing, deployment evidence, or benchmark context, and no confirming event is presently expected. The broader deterministic-boundary patter
- 08-22 19:24alert_silentThe staleness trigger contains no consequential new evidence; the known first-party false-positive result was already surfaced, so there is nothing new for Scott before the next briefing.
- 08-22 19:24alert_routeThe staleness trigger contains no consequential new evidence; the known first-party false-positive result was already surfaced, so there is nothing new for Scott before the next briefing.
- 08-20 18:34repriceNo independent test, deployment report, or benchmark context has appeared; the 40% false-positive result remains an isolated first-party warning, so the case is still unresolved but no longer time-sen
- 08-20 18:34alert_silentThe staleness trigger adds no consequential evidence, and the previously reported usability tradeoff has already been surfaced; wait for independent validation or a materially detailed benchmark.
- 08-20 18:34alert_routeThe staleness trigger adds no consequential evidence, and the previously reported usability tradeoff has already been surfaced; wait for independent validation or a materially detailed benchmark.
- 08-18 17:36repriceThe first quantified first-party result shifts Customhouse from a merely available artifact to an implementation with a potentially severe usability constraint: deterministic blocking reportedly produ
- 08-18 17:36alert_shadowThe quantified tradeoff directly affects whether this security architecture is practical for Scott’s MCP connector and SiloOS work, making it useful today as a test-design constraint; it is not urgent
- 08-18 17:36alert_routeThe quantified tradeoff directly affects whether this security architecture is practical for Scott’s MCP connector and SiloOS work, making it useful today as a test-design constraint; it is not urgent
- 08-18 17:23alert_shadowThe project author has published a concrete, quantified usability tradeoff that directly affects whether this MCP proxy pattern is practical for Scott’s connector and SiloOS work. This establishes a f
- 08-18 17:23alert_routeThe project author has published a concrete, quantified usability tradeoff that directly affects whether this MCP proxy pattern is practical for Scott’s connector and SiloOS work. This establishes a f
- 08-18 17:22attachFirst-party documentation reports a substantial false-positive cost for deterministic prompt-injection blocking, materially contextualizing the proxy’s usability tradeoff.
- 08-18 17:22propose_attachFirst-party documentation reports a substantial false-positive cost for deterministic prompt-injection blocking, materially contextualizing the proxy’s usability tradeoff.
- 08-16 20:31repriceThe reobservation adds no independent testing, adoption, or implementation evidence; the case remains a concrete but unvalidated artifact awaiting results on both exfiltration prevention and workflow
- 08-16 20:31alert_silentNothing consequential changed beyond an unchanged reobservation, so there is no new delta worth interrupting Scott for; wait for an independent security test, benchmark, or production deployment repor
- 08-16 20:31alert_routeNothing consequential changed beyond an unchanged reobservation, so there is no new delta worth interrupting Scott for; wait for an independent security test, benchmark, or production deployment repor
- 08-16 20:29alert_silentThe repository establishes that an MCP-specific deterministic reference-monitor implementation exists, but the supplied evidence contains no independent testing, adoption, release milestone, or concre
- 08-16 20:29surface_candidateThe repository establishes that an MCP-specific deterministic reference-monitor implementation exists, but the supplied evidence contains no independent testing, adoption, release milestone, or concre
- 08-16 20:29alert_routeThe repository establishes that an MCP-specific deterministic reference-monitor implementation exists, but the supplied evidence contains no independent testing, adoption, release milestone, or concre
- 08-16 20:29groundThe core position is already explicit in Scott’s SiloOS and Architecture, Not Vibes pages: treat agents as untrusted and enforce data and capability boundaries through deterministic, proxy-mediated co
- 08-16 20:26promote_anchororigin walk conf 0.97
- 08-16 20:24createA newly released security proxy is a concrete artifact, but it has only one low-engagement observation and no independent validation yet.