chaitanya-sistla

Agentacl — AI skill for Claude Code

AI community

Access control and sandboxing for AI coding agents on macOS.

How to install Agentacl

This entry records only its repository, not the path inside it, so there is no exact command to give. Open chaitanya-sistla/agentacl and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agentacl does

Access control and sandboxing for AI coding agents on macOS. Stop Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode from reading your secrets, with a kernel sandbox, an egress firewall, live approvals and an audit log.

Alternatives in AI

  • Codex Skill — by klaudworks - Enables users to prompt codex from claude code 914 ★
  • System — You are YouClaw, a helpful AI assistant 684 ★
  • TokenEater — 179 Native macOS menu bar app for monitoring Claude AI usage limits and watching coding sessions live 196 ★

README

AgentACL: access control and sandboxing for AI coding agents on macOS

**Stop Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode from reading your secrets. AgentACL enforces it in the macOS kernel, not in the prompt.**

[![CI](https://github.com/chaitanya-sistla/agentacl/actions/workflows/ci.yml/badge.svg)](https://github.com/chaitanya-sistla/agentacl/actions/workflows/ci.yml) [![Release](https://img.shields.io/github/v/release/chaitanya-sistla/agentacl)](https://github.com/chaitanya-sistla/agentacl/releases/latest) [![License](https://img.shields.io/badge/license-Apache--2.0-blue)](LICENSE) ![macOS](https://img.shields.io/badge/macOS-13%2B-black)

AI coding agents run shell commands **as you**. Anything you can read, they can read: SSH keys, `.env` files, AWS and GCP credentials, Terraform state, browser cookies. They can also send it anywhere on the internet.

AgentACL is an open-source **security layer for AI coding agents**. It runs each agent inside a macOS kernel sandbox (Seatbelt), with a network egress firewall and an audit log. The agent keeps full access to your project and loses access to everything it shouldn't touch. You decide what that is, in a local web console or a YAML policy.

![AgentACL access graph showing what an AI coding agent can read and change: the project is open, secrets are blocked](docs/images/access-graph.png)

Why AgentACL

Without AgentACL With AgentACL
Agent reads ~/.ssh, ~/.aws, .env, browser cookies ✅ succeeds ⛔ Operation not permitted (kernel)
Agent uploads data to an unknown site ✅ succeeds ⛔ refused by the egress proxy, or held until you approve
Agent plants a git hook or edits ~/.zshrc ✅ succeeds ⛔ blocked
Subprocesses (sh, python, curl) inherit everything inherit the same sandbox
You know what the agent tried no record every attempt logged: agent, process chain, rule
An agent runs unprotected invisible flagged in the console

Ins