Skip to content

About

πŸ” Egress inspection & secret-leak firewall for local AI agents β€” see what your agents send, catch secrets before they leak, and stop rotating your keys three times a week. macOS menu bar app + Go daemon.

Topics

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

741 Commits

Folders and files

Repository files navigation

secure-agent

CI macOS License

See what your local AI agents do, review security findings, and control sensitive file access and outbound secret exposure.

Secure Agent combines a native macOS menu bar app, a local web console, a Go daemon and harness hooks. It tracks agent sessions, process families, model-call costs, file activity and network destinations. Optional guards can stop supported tool calls; an opt-in proxy inspects routed payloads for secret leaks.

Secure Agent security console

Get started

  1. Download SecureAgent-<version>.dmg from the latest release.
  2. Drag Secure Agent.app to Applications and launch it. Requires macOS 14+.
  3. Choose your harness in Setup. Install Claude Code or Cursor hooks, or continue with the selected harness's observation path.
  4. Start an agent session and check its observed coverage. Enable file telemetry, guard prompts, traffic routing and local analysis separately as needed.

Follow Getting started, then Your first observed session to see evidence and export a report. For problems, use Troubleshooting. To build from source, use Development.

These docs describe the current main checkout. The published release may have an earlier setup flow or fewer features; consult its release notes.

What you can do

Goal Guide
Review findings and incidents, tune alerts, inspect session history Console and CLI
Gate sensitive file access, register secrets, inspect routed payloads File and egress protection
Inspect session memory/CPU and configure resource budgets Resources
Find worktrees, review cleanup and track reclaimed disk space Worktrees and cleanup
Chat with local Ollama and confirm proposed commands Local chat and commands
Collect signed events and posture from several nodes Fleet

Understand the coverage

File guarding, system observation and payload inspection are separate capabilities. Claude Code and Cursor have supported guard hooks; other harnesses have varying process and transcript coverage. See the harness coverage table.

Named guard rules and the firewall default to monitoring. Some hook safety checks always deny credential-printing and guard/harness mutations. Guard prompts, firewall blocking and automatic resource interventions require separate configuration. Unrouted or tunneled traffic is not payload-inspected, and a manual hook check does not prove a live session invokes it. Read the protection guide and limits before relying on enforcement.

macOS is the primary platform for the app, Endpoint Security telemetry and DMG distribution. The daemon, CLI and collector also build on Linux with CGO_ENABLED=0, using /proc for process/network sampling. See Linux and headless setup.

Documentation and contributing

The documentation index links every guide and reference, including Configuration, API, Architecture and the threat models.

For development and pull requests, read Contributing. Report vulnerabilities through the security policy.

Distributed under the MIT License.

About

πŸ” Egress inspection & secret-leak firewall for local AI agents β€” see what your agents send, catch secrets before they leak, and stop rotating your keys three times a week. macOS menu bar app + Go daemon.

Topics

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages