QASO · agent containment
The boundary decides. The agent does not.
ai-proxy sits on the developer’s computer. A signed boundary allows or blocks the next file, program, or connection. A person sets that boundary.
Install, then press Yes.
Linux installs the sandboxes with the product. Mac and Windows open the same setup page from a double-click.
Download
Linux x86_64, Apple silicon, Intel Mac, or 64-bit Windows. Supervisor, setup page, and the default boundary are in the archive.
Open setup
Linux: ./install.sh then aiproxy up. Mac and Windows: double-click the launcher. The page is on port 18080.
Press Yes
One click writes the hook. The next tool call from Claude Code, Gemini CLI, or Codex waits for a decision.
Three machines. One page.
Get the packageLinux
Unpack and run ./install.sh. Sandboxes install unless you pass --no-plugins. Then aiproxy up.
Mac
Unzip the Apple silicon or Intel package. Double-click Open AiProxy.command. The supervisor and setup page land on the machine.
Windows
Unzip and double-click Open AiProxy.bat. Python 3 on PATH, as python, runs the agent hook.
What you get on day one.
All 44A default boundary
Workspace work is allowed. SSH keys, cloud credentials, and everything outside the short program and network lists are denied.
A signed decision
Allow and deny are signed on the machine. A missing signature fails closed. The denial shows up in the console.
A human approval
A wider boundary stays pending until a person approves it, with an expiry. The agent cannot approve itself.
Keys only when needed
Anthropic, OpenAI, and GitHub stay empty. They are stored only if an agent on that computer must call a model or read a private skill.
Hooks, not a screen watch
Yes covers Claude Code, the Gemini CLI, and Codex. The product does not scan the laptop to guess which app opened.
Linux sandboxes
OpenShell, the Anthropic sandbox runtime, nono, and landrun install with the Linux package. Sentry waits for a BlueField card.