aisec

One path per computer

Install, open setup, press Yes.

You do not write a policy for the first run. The package already contains the boundary. Credentials stay empty unless an agent on that computer must call a model or read a private skill.

Linux x86_64

tar -xzf aiproxy-0.1.0-linux-amd64.tar.gz
cd aiproxy-0.1.0-linux-amd64
./install.sh
aiproxy up

./install.sh copies the product to ~/.local/aiproxy and puts aiproxy on ~/.local/bin. It then installs OpenShell, the Anthropic sandbox runtime (srt), nono, and landrun. Pass --no-plugins only when those sandboxes should stay off. Sentry is enabled in the config and becomes available when the machine has a BlueField card.

Leave aiproxy up running. Open http://127.0.0.1:18080/setup.

Apple silicon and Intel Mac

Unzip aiproxy-0.1.0-macos-arm64.zip or aiproxy-0.1.0-macos-amd64.zip. Double-click Open AiProxy.command. If macOS blocks it, right-click the file, choose Open, and confirm.

The first launch copies the supervisor and the policy to ~/.local/aiproxy and opens the setup page. This package checks agent actions with the supervisor. landrun is Linux-only, so the Mac double-click does not install the Linux kernel sandbox.

64-bit Windows

Unzip aiproxy-0.1.0-windows-amd64.zip. Double-click Open AiProxy.bat. It copies the supervisor to %USERPROFILE%\.local\aiproxy and opens the setup page.

Install Python 3 and make sure the command python works in a terminal. The agent hook is a Python script.

Agents

Press Yes on the computer where the agent runs. The hook goes into the config that program already reads.

Claude Code

Terminal, and VS Code or JetBrains when that window is Claude Code. ~/.claude/settings.json

Gemini CLI

The gemini command. Hooks turn on in ~/.gemini/settings.json.

Codex

CLI, and the app when it reads ~/.codex/hooks.json. Trust it once with /hooks.

Same Yes

You do not start a second, special copy of the agent. Start it the way you already do.

Models

ai-proxy does not sit in front of the model. Claude, Gemini, and OpenAI stay whatever the agent is already configured to call.

Anthropic

Fill this only when an agent on this computer must call Claude and does not already have a key.

OpenAI

Fill this only when an agent on this computer must call OpenAI and does not already have a key.

GitHub

Fill this only when an agent must read a private skill or repository. The block decision does not read these fields.

Next: what each agent, IDE, and model path actually does.