Cybersécurité95

AgentACL

I didn't want Claude Code's security boundary to be Claude Code, so I put one underneath it

r/ClaudeCodeu/Straight_Condition3930 septembre 2026

Capture du projet

Résumé

Le projet AgentACL vise à améliorer la sécurité des agents de codage en créant une couche de sécurité supplémentaire avec un sandbox macOS. Il permet de restreindre les accès aux ressources sensibles et de contrôler les actions des agents. Le projet est open-source et écrit en Rust.

Pourquoi c’est intéressant

Le projet AgentACL est intéressant car il aborde un problème de sécurité important lié aux agents de codage. La solution proposée est originale et pourrait avoir un impact significatif sur la sécurité des systèmes d'information. De plus, le projet est open-source et invite la communauté à contribuer et à tester le système.

Comment Claude est utilisé

Le projet utilise Claude Code pour lancer des agents, mais ajoute une couche de sécurité supplémentaire avec un sandbox macOS pour restreindre les accès aux ressources sensibles. L'auteur cherche à améliorer la sécurité des agents en leur attribuant une identité propre et en contrôlant leurs accès aux ressources.

Idées dérivées

  1. 01

    Système d'authentification pour agents

    Développer un système d'authentification pour les agents basé sur une chaîne de délégation de confiance entre l'utilisateur, l'agent et les ressources. Cela permettrait de contrôler finement les accès et les actions des agents.

  2. 02

    Framework d'évaluation de la sécurité des agents

    Créer un framework pour évaluer et comparer la sécurité de différents agents et systèmes de sandboxing. Cela aiderait les développeurs à choisir les solutions les plus sûres pour leurs projets.

  3. 03

    Système de gestion des identités des agents

    Concevoir un système de gestion des identités des agents qui puisse être intégré à des systèmes d'information existants. Cela faciliterait la mise en œuvre de la délégation de confiance et la gestion des accès.

Afficher le post original
I've been using coding agents heavily, and something kept bothering me. Claude Code, Codex, Gemini CLI, etc. ultimately run commands as me. If my user account can read: • ~/.ssh • ~/.aws/credentials • .env • kubeconfig • Terraform state • browser credentials then an agent or anything it launches potentially can too. And telling the agent: "don't read this" isn't really the security model I want. So I started building AgentACL, an open-source macOS security layer for coding agents. The idea is pretty simple: Human identity: John Machine identity: my Mac Agent identity: Claude Code ↓ bash / python ↓ resource Instead of trusting the agent to enforce its own permissions, AgentACL runs it inside a macOS kernel sandbox. For example: $ agentacl run -- claude > cat .env cat: .env: Operation not permitted The important part is that this isn't a Claude prompt, hook, MCP rule or skill. The file operation is denied outside Claude by macOS. If Claude does: Claude → bash → python → read .env the child processes inherit the same sandbox. Right now it can: • protect .env, SSH keys, AWS/GCP/Azure credentials, kubeconfig, Terraform state, browser credentials, etc. • restrict network egress by hostname • prevent agents from modifying things like git hooks and shell startup files • discover Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode • show protected vs unprotected agents • record what was blocked and which process chain attempted it • manage rules through YAML or a local web UI • stay completely local One thing I'm deliberately trying to avoid is pretending the security is stronger than it is. Today, agents launched through agentacl run get the kernel boundary. Agents launched outside AgentACL can currently be discovered and flagged, but aren't blocked yet. The next major step is macOS Endpoint Security so the control can become system-wide and identify agents regardless of how they were started. Long term, what interests me even more than sandboxing is agent identity. We already have: Human IAM Machine / workload IAM Now we're running autonomous processes on our machines that act on behalf of humans. I think we're going to need: Human ↓ delegates to Agent ↓ launches Process ↓ accesses Resource with authorization attached to that delegation chain. The project is Apache-2.0 and written in Rust. GitHub: https://github.com/chaitanya-sistla/agentacl I'd genuinely like people here to try to break the threat model. What am I missing?