aisec

Everything this build supports

Start the agent the way you already do.

Install, press Yes once, then open Claude Code, the Gemini CLI, or Codex. The supervisor decides before a file read, a file write, or a shell command from those programs.

Leave the page up

aiproxy up or the double-click launcher keeps setup on port 18080. The hook still calls the supervisor binary if you close the page.

Start the agent

Claude Code, gemini, or Codex. There is no second “protected” copy to launch.

Read the denial

An allow continues. A deny returns to the agent with the reason, and the action does not run.

Agents and IDEs

Yes writes one hook. A missing supervisor or policy denies the action. An unknown tool with no path, command, or URL is left alone.

Claude Code terminal

~/.claude/settings.json, PreToolUse. A deny exits 2, which is what Claude Code treats as a block.

Claude Code in an IDE

VS Code or JetBrains, including PyCharm, when that window is Claude Code and reads the same settings file.

Gemini CLI

~/.gemini/settings.json, BeforeTool, with hooks turned on. A deny is a decision of deny, or exit code 2.

Codex

~/.codex/hooks.json. Inside Codex, open /hooks and trust the hook once. The Codex app uses the same file when it reads it.

Outside this product

claude.ai, gemini.google.com, chatgpt.com, and a desktop chat that only sends the prompt to the cloud. PyCharm’s own assistant. Any agent that was never given this hook. On Windows the hook command is python.

Models and accounts

The model stays the one the agent already uses. There is no TLS interception and no credential broker in this build.

Anthropic

Only if this computer’s agent must call Claude and has no key of its own.

OpenAI

Only if this computer’s agent must call OpenAI and has no key of its own.

GitHub

Only if an agent must read a private skill. Stored at artifacts/setup/credentials.json, mode 0600. The page reports whether a field is set.

Default boundary

policy/max-boundary.yaml is already active. A path outside these grants is denied. .. is collapsed first. A symlink is judged by that path string.

Read and write

/workspace/**

Read only

/usr /lib /lib64

Explicit deny

ssh, aws, shadow

/home/*/.ssh/**, /root/.ssh/**, the aws equivalents, /etc/shadow. A Mac /Users/…/.ssh path and a Windows profile path sit outside the grants, so they are denied too.

Programs

curl, git with a placeholder hash pin, python3, /workspace/.tools/**. The sample pin is aaaa…, not a measurement of git on your machine.

Network

GET api.github.com /repos/**, git writes denied. POST api.openai.com /v1/**. GET registry.npmjs.org.

Secrets in a body

AKIA, ghp_, private-key blocks, api_key, including base64 and a secret split across lines. Gzip, hex, unicode, and a secret split across requests are named and not in this build.

Try a decision

On Linux or Mac, after the files are in ~/.local/aiproxy. Windows uses aiproxy-supervisor.exe under %USERPROFILE%\.local\aiproxy\bin.

~/.local/aiproxy/bin/aiproxy-supervisor init-keys
~/.local/aiproxy/bin/aiproxy-supervisor \
  --policy ~/.local/aiproxy/policy/max-boundary.yaml \
  --keys ~/.local/aiproxy/var/keys \
  check-fs /workspace/app/main.rs
~/.local/aiproxy/bin/aiproxy-supervisor \
  --policy ~/.local/aiproxy/policy/max-boundary.yaml \
  --keys ~/.local/aiproxy/var/keys \
  check-fs "$HOME/.ssh/id_rsa"

The workspace path prints "decision": "allow". The SSH key prints "decision": "deny" and exits 2. The same binary accepts check-exec, check-net, and eval. With Yes pressed, ask the agent to read those two paths. The denial begins ai-proxy denied this action.

Console

Setup and the embedded admin are on port 18080. Home redirects to /setup. Admin is /console. The wider operator console is in the product source and the design-partner demo, not a second process inside the download.

Boundaries

GET and POST /v1/boundaries.

Approvals

A wider grant stays pending until a person approves it. It expires. The agent cannot approve itself.

Denials

GET /v1/denials. Setup can run the built-in pair: workspace allow, SSH key deny.

Enrollment

POST /v1/agents/enroll records an agent. It does not discover apps by scanning the desktop.

Packs

github-dev, nodejs, python-ml, synthetic. scripts/pack_regression.py checks them on Linux.

Skill check

POST /v1/skills/scan on a directory you choose. It does not need a model key. Export signing is POST /v1/export/sign.

A customer who already terminates TLS for their own model traffic can pass a signed supervisor decision through that path. The gate fails closed. This build also accepts the lab marker AIPROXY_SSE_BYPASS_OK=1, which the Linux launcher sets so the local page can run.

Linux sandboxes

./install.sh installs these unless you pass --no-plugins or set AIPROXY_NO_PLUGINS=1. “No, do not install sandboxes” is the only decline.

OpenShell 0.1.2

Runs a sandbox around the agent on Linux. The 136 fixtures still call the supervisor stub. This package does not pin a production OpenShell build.

srt 0.0.78

Anthropic sandbox runtime. A canary that should be unreadable was blocked in the build test.

nono 0.79.0

Same canary, blocked on Linux.

landrun 0.1.17

Linux kernel with Landlock. Same canary, blocked. landrun is Linux-only.

Sentry

Enabled in config. The probe marks it available when a BlueField card or a DOCA stack is present. This build does not drive Sentry quarantine.

Mac and Windows

Those packages include the supervisor, the setup page, and the hook. They do not install these sandboxes.

Linux commands

After ./install.sh, aiproxy is on ~/.local/bin.

aiproxy up

Control plane on port 18080.

aiproxy status

/healthz plus which sandboxes are present.

aiproxy agents

Same as Yes. --disable removes the hook entries this product added.

aiproxy plugins

Installs OpenShell, srt, nono, and landrun again.

aiproxy corpus

136 cases. 118 must be denied. 18 must be allowed.

aiproxy features

Prints the 44-row counts. The 18-case suite is scripts/escape_suite.sh.

44 capabilities

Partial still counts toward 44. Mac and Windows rows mean kernel-sandbox parity. The zips themselves are real.

in this build

Default boundary

Already active. policy/max-boundary.yaml.

in this build

File allow and deny

check-fs, and file tools from a hooked agent.

in this build

Dot-dot collapse

A path with .. is collapsed before the decision.

in this build

Program allow list

check-exec, and shell tools from a hooked agent.

partial

Program hash pin

The field exists. The sample git pin is the placeholder aaaa….

in this build

Network rules

check-net on host, method, and path.

in this build

Git write class

The GitHub endpoint denies git writes.

in this build

Secret patterns

AKIA, ghp_, private keys, api_key.

in this build

Base64 and split lines

Same body scan, including a secret joined across lines.

not in this build

Gzip, hex, unicode

Multi-request bodies are named so the limit is visible.

in this build

Local Ed25519 keys

aiproxy-supervisor init-keys.

in this build

Organization signature

POST /v1/export/sign.

in this build

Fail closed

A decision with an empty signature is rejected.

in this build

Supervisor decisions

check-fs, check-exec, check-net, eval.

partial

OpenShell grades the corpus

OpenShell runs a Linux sandbox. The 136 fixtures still call the supervisor stub.

not in this build

Credential binder

Keys are stored when you type them. They are not injected per call.

not in this build

Separate prover

The supervisor evaluates the policy.

in this build

18-case suite

scripts/escape_suite.sh on Linux.

in this build

136-case corpus

aiproxy corpus. 118 denies, 18 allows.

not in this build

Live agent in CI

The corpus is fixture JSON. CI does not drive a Claude or Codex session.

not in this build

Symlink follow

The path string is what gets judged.

in this build

Boundaries

Admin, /v1/boundaries.

in this build

Approvals with expiry

A person approves or rejects. The approval expires.

in this build

Denial log

Admin, /v1/denials.

in this build

Agent enrollment

POST /v1/agents/enroll.

partial

SSE bypass

Fails closed. This build also honors AIPROXY_SSE_BYPASS_OK=1.

in this build

Plugin status

GET /v1/plugins and aiproxy status.

in this build

Setup and admin

/setup and /console on port 18080.

in this build

Operator console

In the product source and the demo. The download’s admin is /console.

in this build

Browser walkthrough

Recorded against the demo console. It is not a required install step.

in this build

Four packs

github-dev, nodejs, python-ml, synthetic.

in this build

Pack regression

scripts/pack_regression.py on Linux.

in this build

Evidence videos

Kept with the build evidence. They are not required to install.

in this build

Commercial documents

0.1.0 is a design-partner candidate.

in this build

OpenShell sandbox

Linux install.

partial

Sentry

Available when BlueField or DOCA is present. This build does not drive quarantine.

in this build

Anthropic sandbox

Linux install of srt.

in this build

nono

Linux install.

in this build

landrun

Linux install. Needs Landlock.

not in this build

macOS kernel sandbox

The Mac zips run the supervisor and the hook.

not in this build

Windows kernel sandbox

The Windows zip runs the supervisor and the hook. Python 3 is required for the hook.

not this product

Packet interception

Decisions are host checks on the path, the program, and the destination.

not in this build

Our own microVM

OpenShell’s driver may use one. This package does not ship a separate microVM.