See what your local AI agents do, review security findings, and control sensitive file access and outbound secret exposure.
Secure Agent combines a native macOS menu bar app, a local web console, a Go daemon and harness hooks. It tracks agent sessions, process families, model-call costs, file activity and network destinations. Optional guards can stop supported tool calls; an opt-in proxy inspects routed payloads for secret leaks.
- Download
SecureAgent-<version>.dmgfrom the latest release. - Drag Secure Agent.app to Applications and launch it. Requires macOS 14+.
- Choose your harness in Setup. Install Claude Code or Cursor hooks, or continue with the selected harness's observation path.
- Start an agent session and check its observed coverage. Enable file telemetry, guard prompts, traffic routing and local analysis separately as needed.
Follow Getting started, then Your first observed session to see evidence and export a report. For problems, use Troubleshooting. To build from source, use Development.
These docs describe the current main checkout. The published release may have an earlier setup flow or fewer features; consult its release notes.
| Goal | Guide |
|---|---|
| Review findings and incidents, tune alerts, inspect session history | Console and CLI |
| Gate sensitive file access, register secrets, inspect routed payloads | File and egress protection |
| Inspect session memory/CPU and configure resource budgets | Resources |
| Find worktrees, review cleanup and track reclaimed disk space | Worktrees and cleanup |
| Chat with local Ollama and confirm proposed commands | Local chat and commands |
| Collect signed events and posture from several nodes | Fleet |
File guarding, system observation and payload inspection are separate capabilities. Claude Code and Cursor have supported guard hooks; other harnesses have varying process and transcript coverage. See the harness coverage table.
Named guard rules and the firewall default to monitoring. Some hook safety checks always deny credential-printing and guard/harness mutations. Guard prompts, firewall blocking and automatic resource interventions require separate configuration. Unrouted or tunneled traffic is not payload-inspected, and a manual hook check does not prove a live session invokes it. Read the protection guide and limits before relying on enforcement.
macOS is the primary platform for the app, Endpoint Security telemetry and DMG distribution. The daemon, CLI and collector also build on Linux with CGO_ENABLED=0, using /proc for process/network sampling. See Linux and headless setup.
The documentation index links every guide and reference, including Configuration, API, Architecture and the threat models.
For development and pull requests, read Contributing. Report vulnerabilities through the security policy.
Distributed under the MIT License.
