Résumé
Le projet AgentACL vise à améliorer la sécurité des agents de codage en créant une couche de sécurité supplémentaire avec un sandbox macOS. Il permet de restreindre les accès aux ressources sensibles et de contrôler les actions des agents. Le projet est open-source et écrit en Rust.
Pourquoi c’est intéressant
Le projet AgentACL est intéressant car il aborde un problème de sécurité important lié aux agents de codage. La solution proposée est originale et pourrait avoir un impact significatif sur la sécurité des systèmes d'information. De plus, le projet est open-source et invite la communauté à contribuer et à tester le système.
Comment Claude est utilisé
Le projet utilise Claude Code pour lancer des agents, mais ajoute une couche de sécurité supplémentaire avec un sandbox macOS pour restreindre les accès aux ressources sensibles. L'auteur cherche à améliorer la sécurité des agents en leur attribuant une identité propre et en contrôlant leurs accès aux ressources.
Idées dérivées
- 01
Système d'authentification pour agents
Développer un système d'authentification pour les agents basé sur une chaîne de délégation de confiance entre l'utilisateur, l'agent et les ressources. Cela permettrait de contrôler finement les accès et les actions des agents.
- 02
Framework d'évaluation de la sécurité des agents
Créer un framework pour évaluer et comparer la sécurité de différents agents et systèmes de sandboxing. Cela aiderait les développeurs à choisir les solutions les plus sûres pour leurs projets.
- 03
Système de gestion des identités des agents
Concevoir un système de gestion des identités des agents qui puisse être intégré à des systèmes d'information existants. Cela faciliterait la mise en œuvre de la délégation de confiance et la gestion des accès.
Afficher le post originalMasquer le post original
I've been using coding agents heavily, and something kept bothering me.
Claude Code, Codex, Gemini CLI, etc. ultimately run commands as me.
If my user account can read:
• ~/.ssh
• ~/.aws/credentials
• .env
• kubeconfig
• Terraform state
• browser credentials
then an agent or anything it launches potentially can too.
And telling the agent:
"don't read this"
isn't really the security model I want.
So I started building AgentACL, an open-source macOS security layer for coding agents.
The idea is pretty simple:
Human identity: John Machine identity: my Mac Agent identity: Claude Code ↓ bash / python ↓ resource
Instead of trusting the agent to enforce its own permissions, AgentACL runs it inside a macOS kernel sandbox.
For example:
$ agentacl run -- claude > cat .env cat: .env: Operation not permitted
The important part is that this isn't a Claude prompt, hook, MCP rule or skill.
The file operation is denied outside Claude by macOS.
If Claude does:
Claude → bash → python → read .env
the child processes inherit the same sandbox.
Right now it can:
• protect .env, SSH keys, AWS/GCP/Azure credentials, kubeconfig, Terraform state, browser credentials, etc.
• restrict network egress by hostname
• prevent agents from modifying things like git hooks and shell startup files
• discover Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode
• show protected vs unprotected agents
• record what was blocked and which process chain attempted it
• manage rules through YAML or a local web UI
• stay completely local
One thing I'm deliberately trying to avoid is pretending the security is stronger than it is.
Today, agents launched through agentacl run get the kernel boundary.
Agents launched outside AgentACL can currently be discovered and flagged, but aren't blocked yet. The next major step is macOS Endpoint Security so the control can become system-wide and identify agents regardless of how they were started.
Long term, what interests me even more than sandboxing is agent identity.
We already have:
Human IAM Machine / workload IAM
Now we're running autonomous processes on our machines that act on behalf of humans.
I think we're going to need:
Human ↓ delegates to Agent ↓ launches Process ↓ accesses Resource
with authorization attached to that delegation chain.
The project is Apache-2.0 and written in Rust.
GitHub:
https://github.com/chaitanya-sistla/agentacl
I'd genuinely like people here to try to break the threat model.
What am I missing?