2026-10-11 18:03 UTC

Independent testing will determine whether Customhouse’s deterministic MCP proxy reliably blocks agent-driven data exfiltration without materially disrupting legitimate MCP workflows.

state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security mcp-security agent-exfiltration deterministic-proxyVineet PantCustomhouse

What is this?

Customhouse is presented as a deterministic MCP proxy, associated with Vineet Pant and reportedly first named Bulkhead, designed to prevent AI agents from exfiltrating data while preserving legitimate MCP tool use. The supplied web snippets establish the broader pattern: MCP proxies can mediate tool discovery and execution, enforce allowlists and other guardrails, and log agent interactions to reduce exfiltration risk. However, none of the snippets independently tests or even specifically documents Customhouse, so the claim that it reliably blocks exfiltration without materially disrupting valid workflows remains unverified; the web answer asserting confirmation is unsupported by the listed results.

Why it matters to Scott

The core position is already explicit in Scott’s SiloOS and Architecture, Not Vibes pages: treat agents as untrusted and enforce data and capability boundaries through deterministic, proxy-mediated controls. Customhouse could still matter as an MCP-specific implementation and test case for whether this architecture prevents exfiltration without unacceptable workflow friction, directly informing SiloOS and Scott’s production MCP connector; however, the supplied evidence provides no independent results yet.
ip:framework.siloosip:framework.architecture-not-vibesip:concept.proxy-mediated-tokenisationdev:project.silo-osdev:project.mcp-ip-wikiradar:concept.mcp-securityradar:concept.agent-securityradar:opencode-guardians-tool-call-verificationradar:wardline-agent-traffic-proxy
queries asked of Scott's wikis
  • deterministic controls around untrusted agents
  • MCP tool-call security and authorization
  • agent data exfiltration threat models
  • proxy guardrails versus model-based safety
  • capability boundaries for coding agents
  • security controls that preserve agent usability

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Customhouse – deterministic MCP proxy that blocks agent exfiltrationvineetpant11
🟧 echo.github ⭐The repository’s first commit introduced the project (then named Bulkhead) and its core thesis: “the model cannot be trusted to decide what Vineet Pant——
🟧 hnBlocking prompt injection deterministically costs 40% false positivesvineetpant20

Interpretation history

Decision trace