---
title: "silmaril-vscode-firewall"
description: "Silmaril Firewall protection for local VS Code agent harnesses."
canonical: https://agentpluginsdirectory.com/plugins/silmaril-vscode-firewall
last-updated: 2026-10-11
---

# silmaril-vscode-firewall
Silmaril Firewall protection for local VS Code agent harnesses.
- Slug: silmaril-vscode-firewall
- Publisher: Silmaril Security
- Repository: https://github.com/Silmaril-Security/VSCodeFirewallPlugin
- Manifest: plugin.json
- Version: 0.2.4
- License: Apache-2.0
- Category (editorial): security
- Skills: 0
- MCP servers: 0
- Stars: 0
- Repository created: 2026-08-26
- Repository last pushed: 2026-10-05
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/silmaril-vscode-firewall
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What silmaril-vscode-firewall does, in the publisher's words

Silmaril Firewall protection for local agent sessions in Visual Studio Code.

The plugin uses VS Code's Agent Plugins 1.0 hook contract, so one installation covers the Local, Copilot, Claude, and Codex harnesses when they execute on the local Mac. It classifies the current user prompt, tool call, or successful tool response without reading the unstable transcript file.

Shadow classifies silently. Warn preserves the event and returns one fixed, content-free warning. Block stops a submitted prompt, denies a tool before execution, or stops further processing after a completed tool. A PostToolUse block never claims that the completed side effect was undone. Missing configuration, unavailable Node, API failures, malformed inputs, and timeouts fail open.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/Silmaril-Security/VSCodeFirewallPlugin/HEAD/README.md
