Secure Agent — AI skill for Claude Code
🔐 Egress inspection & secret-leak firewall for local AI agents — see what your agents send, catch secrets before they leak, and stop rotating your keys three times a week.
How to install Secure Agent
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open cavi-ai/secure-agent and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Secure Agent does
🔐 Egress inspection & secret-leak firewall for local AI agents — see what your agents send, catch secrets before they leak, and stop rotating your keys three times a week. macOS menu bar app + Go daemon.
Alternatives in AI
- The Pair — Open-source AI pair programming for desktop: a Mentor + Executor agent cross-check each other's code to catch 358 ★
- Debug Skill — Give your AI agent a real debugger — breakpoints, stepping, variable inspection, and stack traces via CLI 218 ★
- Open Claude Code Termux — An automated 1-click installer to run the open-source Claude Code leak natively on Android (Termux) and Window 125 ★
README
secure-agent
[](https://github.com/cavi-ai/secure-agent/actions/workflows/ci.yml) [](https://go.dev/) [](https://swift.org/) [](https://apple.com/macos) [](LICENSE)
**Egress inspection & secret-leak firewall for local AI agents.** See what your agents send, catch secrets before they leak, and stop rotating your keys three times a week.
**`secure-agent`** is a lightweight, always-on AI-agent security monitor and harness guard designed for macOS.
**Platform support.** macOS 14+ is the primary target (Endpoint Security telemetry, menubar app, DMG packaging). The Go daemon also builds and runs on **Linux** (`GOOS=linux go build ./...`), where Endpoint Security (`eslogger`) file telemetry degrades gracefully to the transcript scanner and network sampling runs on `/proc` — the guard hooks, egress firewall, fleet, and console all work identically. CI enforces the Linux build + tests on every push.
As AI coding agents (Claude Code, Cursor, Codex, Antigravity, Pi, Qwen Code, opencode, Copilot, etc.) gain increasing autonomy in local development environments, they gain execution privileges to read local sensitive files, mutate shell configurations, access credential stores, and initiate external network connections. `secure-agent` provides a non-intrusive, multi-layered defense system that enforces zero-trust boundaries around AI agent process trees without disrupting developer velocity.
🌟 Key Features
- 🛡️ In-Harness Secret Guard (
PreToolUseGating)
Related Skills
Agentacl
Access control and sandboxing for AI coding agents on macOS. Stop Claude Code, Codex, Gemini CLI, Copilot CLI
Vibe Gauge
🧠 Native macOS menu-bar dashboard for AI coding: Claude / Codex / Gemini / Grok quotas with sleep-aware usage
VibeGauge
🧠 Native macOS menu-bar dashboard for AI coding: Claude / Codex / Gemini / Grok quotas with sleep-aware usage
Devcontainer Airlock
Secure, layered devcontainers for AI coding agents: the agents work in a workbench with no GitHub token and no
Agent Guard
Real-time secret-leak guardrails for AI coding agents (Claude Code, Codex), Git hooks, and CI.
Agent Firewall
A firewall for AI coding agents — inspects prompts, tool calls, and model output to catch credential leaks, pr
Related Agents
Network Analyst
Deep network analysis agent — packet inspection, protocol dissection, traffic anomaly detection, IDS/IPS rule
macOS UI Designer
Use this agent when you need to plan, design, or evaluate macOS application user interfaces from a UI/UX persp
Conversion Funnel Analyst
Read-only analyst that pulls funnel metrics (signups → first upload → first download → paid) week-over-week an