earl
View on GitHubSecure CLI proxy for AI agents — HCL-defined operation templates with OS keychain secrets, MCP integration, and prompt injection protection
Earl is a Rust CLI and MCP server that gives agents access to external services through human-authored HCL operation templates. It keeps credentials in OS or external secret stores and limits agent-controlled inputs to template parameters.
Use Cases
Expose allowlisted service operations to AI agentsConnect agents to HTTP and GraphQL APIsProvide agents access to gRPC and SQL operationsStore and resolve credentials without exposing secrets to the modelRestrict agent requests with reviewed operation templatesReduce prompt-injection risk from external service responses
Built With
- Language
- Rust
Tags
MCP server · AI agents · secure tool access · CLI · HCL templates · secrets management · prompt injection protection · SSRF protection · HTTP · GraphQL · gRPC · SQL · Bash