Install
There are three packages. Each one opens the same setup page at http://127.0.0.1:18080/setup. The Linux package is the one that also installs the sandboxes.
Linux (amd64)
tar -xzf aiproxy-0.1.0-linux-amd64.tar.gz cd aiproxy-0.1.0-linux-amd64 ./install.sh aiproxy up
./install.sh copies the product to ~/.local/aiproxy and installs OpenShell, the Anthropic sandbox runtime (srt), nono, and landrun. Pass --no-plugins only if you want to skip those sandboxes. Sentry stays in the config and becomes available when the machine has a BlueField card. Leave aiproxy up running, then open the setup page.
macOS
Unzip aiproxy-0.1.0-macos-arm64.zip or the Intel zip. Double-click Open AiProxy.command. The first launch copies the supervisor and the policy into ~/.local/aiproxy and opens the setup page. If macOS blocks the file, right-click it, choose Open, and confirm.
This Mac package checks agent actions with the supervisor. It does not install the Linux kernel sandbox. landrun is Linux-only. OpenShell on a Mac is a separate install and is not started by this double-click.
Windows
Unzip aiproxy-0.1.0-windows-amd64.zip. Double-click Open AiProxy.bat. It copies the supervisor into %USERPROFILE%\.local\aiproxy and opens the setup page. Python 3 needs to be on PATH as python so the agent hook can run.
Configure
You do not fill in a policy by hand for the first try. The package already has policy/max-boundary.yaml.
On the setup page, press Yes, protect agents. That is the step that connects Claude Code, the Gemini CLI, and Codex to the supervisor.
Leave the Anthropic, OpenAI, and GitHub fields empty. Those keys are only for an agent that must call a model or read a private skill. The block decision does not use them.
Press No, do not install sandboxes only when you want the Linux plugin install to stay off. On a Mac or Windows package that button does not change the supervisor check.
The default boundary allows work under /workspace/**, a short list of programs, and a short list of network calls. It denies everything else, including /home/*/.ssh/** and the Mac and Windows equivalents of a private key path when that path is what the agent asks to read.
Which tools are covered
Pressing Yes writes one hook into the config file each of these programs already reads. The next launch of that program sends each file read, file write, and shell command to the supervisor before it runs. An allow proceeds. A deny is returned to the agent and the action does not run.
| How you start the agent | What happens |
|---|---|
| Claude Code in a terminal | Covered. Hook file: ~/.claude/settings.json. |
| Claude Code inside VS Code or a JetBrains IDE, including PyCharm | Covered when that window is Claude Code. It reads the same settings file. |
Gemini CLI (gemini) | Covered. Hook file: ~/.gemini/settings.json. |
| Codex CLI | Covered after you trust the hook. Codex asks once inside Codex. Open /hooks and trust it. Hook file: ~/.codex/hooks.json. |
Codex app, when it reads ~/.codex/hooks.json | Same hook, same one-time trust. |
| claude.ai, gemini.google.com, chatgpt.com, or a desktop chat that only sends the prompt to the cloud | Not covered. The tool call never happens on this computer. |
| PyCharm’s own AI assistant, or another IDE assistant that is not Claude Code, Gemini CLI, or Codex | Not covered. ai-proxy does not scan the laptop to see which app you opened. |
ai-proxy does not detect the brand of the agent by watching the screen. It only sees an action when one of those three programs calls the hook. A program that is not on the list is unchanged.
Try a block
With the setup page still open and Yes already pressed, start Claude Code, Gemini CLI, or Codex in a normal terminal. Ask it to read a file inside the project, then ask it to read an SSH private key.
Read /workspace/app/main.rs Read ~/.ssh/id_rsa
The workspace read is allowed when that path is inside the workspace grant. The SSH key read is denied. The agent should show a denial that begins with ai-proxy denied this action.
You can also ask the supervisor directly, without an agent:
~/.local/aiproxy/bin/aiproxy-supervisor init-keys ~/.local/aiproxy/bin/aiproxy-supervisor \ --policy ~/.local/aiproxy/policy/max-boundary.yaml \ --keys ~/.local/aiproxy/var/keys \ check-fs /workspace/app/main.rs ~/.local/aiproxy/bin/aiproxy-supervisor \ --policy ~/.local/aiproxy/policy/max-boundary.yaml \ --keys ~/.local/aiproxy/var/keys \ check-fs "$HOME/.ssh/id_rsa"
On Windows the program name is aiproxy-supervisor.exe and the policy path is under %USERPROFILE%\.local\aiproxy. The first command prints "decision": "allow". The second prints "decision": "deny" and exits 2.
What is in each package
| File | Use it on | What you can try |
|---|---|---|
dist/aiproxy-0.1.0-linux-amd64.tar.gz | Linux x86_64 | Supervisor, setup page, sandbox install, agent hooks, the 136-case corpus. |
dist/aiproxy-0.1.0-macos-arm64.zip | Apple silicon Mac | Supervisor, setup page, agent hooks. |
dist/aiproxy-0.1.0-macos-amd64.zip | Intel Mac | Supervisor, setup page, agent hooks. |
dist/aiproxy-0.1.0-windows-amd64.zip | 64-bit Windows | Supervisor, setup page, agent hooks. Python 3 is required for the hook. |
The numbers on the product are two different counts. The escape corpus has 136 cases, and 118 of those must be denied. The product catalog is 44 capabilities. The corpus run is aiproxy corpus from the Linux install.