CAIN-42 CAIN Studio

Recipes

Guard http requests

For an agent that fetches URLs, in 17 frameworks.

Last reviewed 2026-10-02

The cloud metadata address, the classic server-side request forgery target, is refused. For everything else, an egress allowlist of the hosts the agent may reach is the stronger control.

The rule

{
  "name": "http-guard",
  "effect": "deny",
  "priority": 10,
  "match_path": "/tools/http_get",
  "conditions": [
    {
      "field": "url",
      "op": "contains",
      "value": "169.254.169.254"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"url": "http://169.254.169.254/latest/meta-data/"}
Safe{"url": "https://api.github.com/repos/acme/app"}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)http_getthe function that acts
LangChainhttp_getyour agent's tool list
LangGraphhttp_getthe tools your graph's nodes call
OpenAI Agents SDKhttp_getfunction tools
CrewAIhttp_getCrewAI's before-tool-call hooks
LlamaIndexhttp_getFunctionTool
Pydantic AIhttp_getan agent capability
AutoGen (agentchat)http_getthe callables you give AssistantAgent
Google ADKhttp_getthe functions in an agent's tools
Claude Agent SDKmcp__ops__http_getPreToolUse hooks
MCP client (Python)http_getany MCP client session
OpenTelemetryhttp_getyour existing tracing
Any other frameworkhttp_getany Python callable
Claude Code hooksWebFetchClaude Code's PreToolUse hook
Cursor hooksmcp__fetch__fetchCursor's permission hooks
TypeScript / JavaScripthttp_getany async function
HTTP (any language)http_getyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem