Leave the page up
aiproxy up or the double-click launcher keeps setup on port 18080. The hook still calls the supervisor binary if you close the page.
Everything this build supports
Install, press Yes once, then open Claude Code, the Gemini CLI, or Codex. The supervisor decides before a file read, a file write, or a shell command from those programs.
aiproxy up or the double-click launcher keeps setup on port 18080. The hook still calls the supervisor binary if you close the page.
Claude Code, gemini, or Codex. There is no second “protected” copy to launch.
An allow continues. A deny returns to the agent with the reason, and the action does not run.
Yes writes one hook. A missing supervisor or policy denies the action. An unknown tool with no path, command, or URL is left alone.
~/.claude/settings.json, PreToolUse. A deny exits 2, which is what Claude Code treats as a block.
VS Code or JetBrains, including PyCharm, when that window is Claude Code and reads the same settings file.
~/.gemini/settings.json, BeforeTool, with hooks turned on. A deny is a decision of deny, or exit code 2.
~/.codex/hooks.json. Inside Codex, open /hooks and trust the hook once. The Codex app uses the same file when it reads it.
claude.ai, gemini.google.com, chatgpt.com, and a desktop chat that only sends the prompt to the cloud. PyCharm’s own assistant. Any agent that was never given this hook. On Windows the hook command is python.
The model stays the one the agent already uses. There is no TLS interception and no credential broker in this build.
Only if this computer’s agent must call Claude and has no key of its own.
Only if this computer’s agent must call OpenAI and has no key of its own.
Only if an agent must read a private skill. Stored at artifacts/setup/credentials.json, mode 0600. The page reports whether a field is set.
policy/max-boundary.yaml is already active. A path outside these grants is denied. .. is collapsed first. A symlink is judged by that path string.
/home/*/.ssh/**, /root/.ssh/**, the aws equivalents, /etc/shadow. A Mac /Users/…/.ssh path and a Windows profile path sit outside the grants, so they are denied too.
curl, git with a placeholder hash pin, python3, /workspace/.tools/**. The sample pin is aaaa…, not a measurement of git on your machine.
GET api.github.com /repos/**, git writes denied. POST api.openai.com /v1/**. GET registry.npmjs.org.
AKIA, ghp_, private-key blocks, api_key, including base64 and a secret split across lines. Gzip, hex, unicode, and a secret split across requests are named and not in this build.
On Linux or Mac, after the files are in ~/.local/aiproxy. Windows uses aiproxy-supervisor.exe under %USERPROFILE%\.local\aiproxy\bin.
~/.local/aiproxy/bin/aiproxy-supervisor init-keys ~/.local/aiproxy/bin/aiproxy-supervisor \ --policy ~/.local/aiproxy/policy/max-boundary.yaml \ --keys ~/.local/aiproxy/var/keys \ check-fs /workspace/app/main.rs ~/.local/aiproxy/bin/aiproxy-supervisor \ --policy ~/.local/aiproxy/policy/max-boundary.yaml \ --keys ~/.local/aiproxy/var/keys \ check-fs "$HOME/.ssh/id_rsa"
The workspace path prints "decision": "allow". The SSH key prints "decision": "deny" and exits 2. The same binary accepts check-exec, check-net, and eval. With Yes pressed, ask the agent to read those two paths. The denial begins ai-proxy denied this action.
Setup and the embedded admin are on port 18080. Home redirects to /setup. Admin is /console. The wider operator console is in the product source and the design-partner demo, not a second process inside the download.
GET and POST /v1/boundaries.
A wider grant stays pending until a person approves it. It expires. The agent cannot approve itself.
GET /v1/denials. Setup can run the built-in pair: workspace allow, SSH key deny.
POST /v1/agents/enroll records an agent. It does not discover apps by scanning the desktop.
github-dev, nodejs, python-ml, synthetic. scripts/pack_regression.py checks them on Linux.
POST /v1/skills/scan on a directory you choose. It does not need a model key. Export signing is POST /v1/export/sign.
A customer who already terminates TLS for their own model traffic can pass a signed supervisor decision through that path. The gate fails closed. This build also accepts the lab marker AIPROXY_SSE_BYPASS_OK=1, which the Linux launcher sets so the local page can run.
./install.sh installs these unless you pass --no-plugins or set AIPROXY_NO_PLUGINS=1. “No, do not install sandboxes” is the only decline.
Runs a sandbox around the agent on Linux. The 136 fixtures still call the supervisor stub. This package does not pin a production OpenShell build.
Anthropic sandbox runtime. A canary that should be unreadable was blocked in the build test.
Same canary, blocked on Linux.
Linux kernel with Landlock. Same canary, blocked. landrun is Linux-only.
Enabled in config. The probe marks it available when a BlueField card or a DOCA stack is present. This build does not drive Sentry quarantine.
Those packages include the supervisor, the setup page, and the hook. They do not install these sandboxes.
After ./install.sh, aiproxy is on ~/.local/bin.
Control plane on port 18080.
/healthz plus which sandboxes are present.
Same as Yes. --disable removes the hook entries this product added.
Installs OpenShell, srt, nono, and landrun again.
136 cases. 118 must be denied. 18 must be allowed.
Prints the 44-row counts. The 18-case suite is scripts/escape_suite.sh.
Partial still counts toward 44. Mac and Windows rows mean kernel-sandbox parity. The zips themselves are real.
Already active. policy/max-boundary.yaml.
check-fs, and file tools from a hooked agent.
A path with .. is collapsed before the decision.
check-exec, and shell tools from a hooked agent.
The field exists. The sample git pin is the placeholder aaaa….
check-net on host, method, and path.
The GitHub endpoint denies git writes.
AKIA, ghp_, private keys, api_key.
Same body scan, including a secret joined across lines.
Multi-request bodies are named so the limit is visible.
aiproxy-supervisor init-keys.
POST /v1/export/sign.
A decision with an empty signature is rejected.
check-fs, check-exec, check-net, eval.
OpenShell runs a Linux sandbox. The 136 fixtures still call the supervisor stub.
Keys are stored when you type them. They are not injected per call.
The supervisor evaluates the policy.
scripts/escape_suite.sh on Linux.
aiproxy corpus. 118 denies, 18 allows.
The corpus is fixture JSON. CI does not drive a Claude or Codex session.
The path string is what gets judged.
Admin, /v1/boundaries.
A person approves or rejects. The approval expires.
Admin, /v1/denials.
POST /v1/agents/enroll.
Fails closed. This build also honors AIPROXY_SSE_BYPASS_OK=1.
GET /v1/plugins and aiproxy status.
/setup and /console on port 18080.
In the product source and the demo. The download’s admin is /console.
Recorded against the demo console. It is not a required install step.
github-dev, nodejs, python-ml, synthetic.
scripts/pack_regression.py on Linux.
Kept with the build evidence. They are not required to install.
0.1.0 is a design-partner candidate.
Linux install.
Available when BlueField or DOCA is present. This build does not drive quarantine.
Linux install of srt.
Linux install.
Linux install. Needs Landlock.
The Mac zips run the supervisor and the hook.
The Windows zip runs the supervisor and the hook. Python 3 is required for the hook.
Decisions are host checks on the path, the program, and the destination.
OpenShell’s driver may use one. This package does not ship a separate microVM.