
pyrasp embeds Runtime Application Self-Protection inside Flask, FastAPI, Django and aiohttp services, detecting attacks and prompt injection without signatures.
| Tool | rbidou/pyrasp — Runtime Application Self Protection package for Python web servers, gateways, serverless functions and MCP servers |
| Category | RASP / application-layer runtime defense |
| Primary Use | Instrumenting authorized applications from within to detect web attacks, prompt injection and data leaks on Flask, FastAPI, Django, aiohttp and MCP servers |
| Safe Use | Defensive deployment by developers and authorized security teams on their own applications, labs and production estates; purely a protection product, not an attack tool |
| Telemetry Note | Optionally emits logs, telemetry (CPU, memory, request counts) and shared threat intelligence to remote servers; defenders observe its activity through these agent reports and internal block events |
pyrasp is a Runtime Application Self Protection (RASP) package that lives inside Python applications rather than watching them from the network perimeter. Instead of filtering traffic at a proxy, it hooks into the application runtime itself, which means it sees decoded requests, framework internals and system state at the moment an attack unfolds. The README positions it for Flask, FastAPI, Django and aiohttp servers, for WSGI and ASGI gateways, and for serverless functions on Azure and Google Cloud Functions. That breadth is notable: most RASP products are commercial appliances, and pyrasp targets the Python ecosystem specifically.
The project is authored by Renaud Bidou of ParaCyberBellum and is currently at version 0.10.0. Repository metadata shows 39 stars, a Python codebase, and a topic list spanning application-security, rasp, runtime-security, django, fastapi, fastmcp, mcp-servers and the major FaaS platforms — the topics alone give you a fairly accurate map of the deployment surface. The license field reads NOASSERTION, which is worth checking before commercial redistribution. Full documentation lives at paracyberbellum.gitbook.io/pyrasp with release notes in RELEASE-NOTES.md in the repo.
What sets pyrasp apart from a classic WAF is its explicit rejection of signature-based detection. The README states it relies on decoys, thresholds, system and application internals, and machine learning to identify malicious behavior. This matters operationally: signature-free detection aims to catch novel or obfuscated payloads that pattern lists miss, at the cost of being harder to reason about when it false-positives. For defenders evaluating it, the decoy and threshold approach suggests instrumentation of both the request layer and the underlying process — consistent with the telemetry it exposes.
Beyond classic web attacks, pyrasp makes an aggressive bet on agentic AI security. It claims full protection for MCP servers, defending tools against malicious input injections and against data leaks of PII and credentials that would result from unexpected processing. It also guards LLM frontends against malicious prompt injection attempts. Given how quickly MCP servers have become an attack surface of their own, a runtime guard that inspects tool inputs inside the server process is a genuinely current capability, not a checkbox feature.
Another differentiator is Zero-Trust Application Access. The README says pyrasp can ensure that only up-to-date, authorized browsers can connect to critical applications. That pushes it slightly beyond pure detection into access control, effectively letting the application itself gate clients on posture and authorization — a small built-in ZTNA layer for applications too sensitive to trust the network path.
Architecturally, the README describes a hybrid model: the agent can run from a local configuration file or pull its configuration from a remote or cloud server, and logs and telemetry can be shipped to remote collectors as well. Threat information can be shared across agents, which implies a community or centralized intelligence feed where one agent's detection hardens the rest — a useful property for fleets of instrumented services. Telemetry covers CPU and memory usage plus request counts, giving operations teams baseline visibility alongside the security events.
There are a few sharp edges documented directly in the README. The most important: AWS Lambda functions are no longer supported since version 0.8.3. Teams running serverless Python on AWS are out of scope and should not plan deployments around it, while Azure and Google Cloud Functions remain covered. Anyone pinning older versions for Lambda compatibility should be aware they are frozen on a deprecated path, so reading RELEASE-NOTES.md before upgrading is a sensible habit.
For authorized security teams, the natural use cases are clear. AppSec engineers can embed pyrasp in their own Flask or FastAPI services as a compensating control while patches for a vulnerable dependency are in flight. Red team leads can use it to make internal lab environments more realistic, testing whether their tradecraft survives in-process detection rather than just perimeter filtering. And defenders building MCP-based automation get a guardrail against prompt injection and credential exfiltration through tool calls — arguably the most timely of its features.
Installation follows standard Python packaging, for example pip install pyrasp inside the target project, after which the agent is wired into the framework per the gitbook documentation — a Flask app, a FastAPI middleware stack or a FastMCP server each get their own integration path. The two-step mental model — install, then attach to your own application — mirrors how other in-process instrumentation like profilers or APM agents work, and it is the correct authorization boundary: you run it on code you own.
Operationally, a few things deserve attention before production rollout. Behavior-based detection plus machine learning means the first weeks are a tuning period; the threshold mechanisms need calibration against legitimate traffic or you will ship false positives into your block path. The optional remote configuration and telemetry channels should be authenticated and locked down, since an agent that accepts remote configuration is itself a sensitive component. And the non-standard license means legal review before redistribution inside commercial products.
As a whole, pyrasp is one of the more complete open-source entries in the RASP category for Python, and its MCP and LLM protection features place it squarely in the current conversation about agentic AI security. It is purely defensive tooling, best evaluated by engineers who control the applications they instrument, with the README, the gitbook docs and the release notes providing the authoritative picture of what the current 0.10.0 release actually covers.
rbidou/pyrasp.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.