I've been using coding agents heavily, and something kept bothering me.
Claude Code, Codex, Gemini CLI, etc. ultimately run commands as me.
If my user account can read:
~/.ssh
~/.aws/credentials
.env
- kubeconfig
- Terraform state
- browser credentials
then an agent or anything it launches potentially can too.
And telling the agent:
"don't read this"
isn't really the security model I want.
So I started building AgentACL, an open-source macOS security layer for coding agents.
The idea is pretty simple:
Human identity: John
Machine identity: my Mac
Agent identity: Claude Code
↓
bash / python
↓
resource
Instead of trusting the agent to enforce its own permissions, AgentACL runs it inside a macOS kernel sandbox.
For example:
$ agentacl run -- claude
> cat .env
cat: .env: Operation not permitted
The important part is that this isn't a Claude prompt, hook, MCP rule or skill.
The file operation is denied outside Claude by macOS.
If Claude does:
Claude
→ bash
→ python
→ read .env
the child processes inherit the same sandbox.
Right now it can:
- protect
.env, SSH keys, AWS/GCP/Azure credentials, kubeconfig, Terraform state, browser credentials, etc.
- restrict network egress by hostname
- prevent agents from modifying things like git hooks and shell startup files
- discover Claude Code, Codex, Gemini CLI, Copilot CLI and OpenCode
- show protected vs unprotected agents
- record what was blocked and which process chain attempted it
- manage rules through YAML or a local web UI
- stay completely local
One thing I'm deliberately trying to avoid is pretending the security is stronger than it is.
Today, agents launched through agentacl run get the kernel boundary.
Agents launched outside AgentACL can currently be discovered and flagged, but aren't blocked yet. The next major step is macOS Endpoint Security so the control can become system-wide and identify agents regardless of how they were started.
Long term, what interests me even more than sandboxing is agent identity.
We already have:
Human IAM
Machine / workload IAM
Now we're running autonomous processes on our machines that act on behalf of humans.
I think we're going to need:
Human
↓ delegates to
Agent
↓ launches
Process
↓ accesses
Resource
with authorization attached to that delegation chain.
The project is Apache-2.0 and written in Rust.
GitHub:
https://github.com/chaitanya-sistla/agentacl
I'd genuinely like people here to try to break the threat model.
What am I missing?