Agentacl — AI skill for Claude Code
Access control and sandboxing for AI coding agents on macOS.
How to install Agentacl
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open chaitanya-sistla/agentacl and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Agentacl does
Access control and sandboxing for AI coding agents on macOS. Stop Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode from reading your secrets, with a kernel sandbox, an egress firewall, live approvals and an audit log.
Alternatives in AI
- Codex Skill — by klaudworks - Enables users to prompt codex from claude code 914 ★
- System — You are YouClaw, a helpful AI assistant 684 ★
- TokenEater — 179 Native macOS menu bar app for monitoring Claude AI usage limits and watching coding sessions live 196 ★
README
AgentACL: access control and sandboxing for AI coding agents on macOS
**Stop Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode from reading your secrets. AgentACL enforces it in the macOS kernel, not in the prompt.**
[](https://github.com/chaitanya-sistla/agentacl/actions/workflows/ci.yml) [](https://github.com/chaitanya-sistla/agentacl/releases/latest) [](LICENSE) 
AI coding agents run shell commands **as you**. Anything you can read, they can read: SSH keys, `.env` files, AWS and GCP credentials, Terraform state, browser cookies. They can also send it anywhere on the internet.
AgentACL is an open-source **security layer for AI coding agents**. It runs each agent inside a macOS kernel sandbox (Seatbelt), with a network egress firewall and an audit log. The agent keeps full access to your project and loses access to everything it shouldn't touch. You decide what that is, in a local web console or a YAML policy.

Why AgentACL
| Without AgentACL | With AgentACL | |
|---|---|---|
Agent reads ~/.ssh, ~/.aws, .env, browser cookies |
✅ succeeds | ⛔ Operation not permitted (kernel) |
| Agent uploads data to an unknown site | ✅ succeeds | ⛔ refused by the egress proxy, or held until you approve |
Agent plants a git hook or edits ~/.zshrc |
✅ succeeds | ⛔ blocked |
Subprocesses (sh, python, curl) |
inherit everything | inherit the same sandbox |
| You know what the agent tried | no record | every attempt logged: agent, process chain, rule |
| An agent runs unprotected | invisible | flagged in the console |
Ins
Related Skills
AI Agent Sandbox
A secure bubblewrap-based sandboxing solution for running Claude Code with strict filesystem isolation.
Apohara Agentguard
Anti-bypass command-safety hook, local seccomp+Landlock sandbox, and deterministic prompt-injection firewall f
Hub Cc
Local control plane for Claude Code on Windows and macOS: switch LLM gateways in one click behind a fixed endp
Cplt
Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a
Brood Box
10+ Run AI coding agents (Claude Code, Codex, OpenCode) inside hardware-isolated microVMs with snapshot isolat
Vibe Gauge
🧠 Native macOS menu-bar dashboard for AI coding: Claude / Codex / Gemini / Grok quotas with sleep-aware usage
Related Agents
Developer Overview
code-container (container) creates isolated Docker environments for AI coding harnesses (Claude Code, OpenCode
Consult Agent
Execute cross-tool AI consultations via Task spawning. Use when agents or workflows need a second opinion from
Qp Security Reviewer
Read-only reviewer for the quality-pass security & data-integrity dimension — authz gaps, tenant/owner scoping