Recipes
Guard http requests
For an agent that fetches URLs, in 17 frameworks.
Last reviewed 2026-10-02
The cloud metadata address, the classic server-side request forgery target, is refused. For everything else, an egress allowlist of the hosts the agent may reach is the stronger control.
The rule
{
"name": "http-guard",
"effect": "deny",
"priority": 10,
"match_path": "/tools/http_get",
"conditions": [
{
"field": "url",
"op": "contains",
"value": "169.254.169.254"
}
]
}Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.
| Risky | {"url": "http://169.254.169.254/latest/meta-data/"} |
|---|---|
| Safe | {"url": "https://api.github.com/repos/acme/app"} |
Pick your framework
| Framework | Tool name CAIN sees | Plugs into |
|---|---|---|
| Python (any function) | http_get | the function that acts |
| LangChain | http_get | your agent's tool list |
| LangGraph | http_get | the tools your graph's nodes call |
| OpenAI Agents SDK | http_get | function tools |
| CrewAI | http_get | CrewAI's before-tool-call hooks |
| LlamaIndex | http_get | FunctionTool |
| Pydantic AI | http_get | an agent capability |
| AutoGen (agentchat) | http_get | the callables you give AssistantAgent |
| Google ADK | http_get | the functions in an agent's tools |
| Claude Agent SDK | mcp__ops__http_get | PreToolUse hooks |
| MCP client (Python) | http_get | any MCP client session |
| OpenTelemetry | http_get | your existing tracing |
| Any other framework | http_get | any Python callable |
| Claude Code hooks | WebFetch | Claude Code's PreToolUse hook |
| Cursor hooks | mcp__fetch__fetch | Cursor's permission hooks |
| TypeScript / JavaScript | http_get | any async function |
| HTTP (any language) | http_get | your own call site |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem