# FireAI recognises 19 AI agents on macOS and limits where their data goes

> FireAI 1.0.4 names 19 AI agents on a Mac, including those run by node or python, and flags or blocks their new destinations. Mapped to the OWASP 2025 and 2026 risk lists.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-03
Canonical: https://hisnlabs.com/en/blog/fireai-recognises-ai-agents-macos-data-exfiltration

Both OWASP lists that describe the security of language-model systems treat data leaving the system as a central outcome: the Top 10 for LLM Applications 2025 lists Sensitive Information Disclosure as LLM02 [[2]](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/), and the Top 10 for Agentic Applications for 2026, published on 9 December 2025, mentions exfiltration in eight of its ten entries [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/). On a Mac, that exfiltration is a network connection. FireAI 1.0.4 extends its Agent profile from three recognised agents to 19, including agents that run inside node or python, and this article sets out which of the OWASP risks that work addresses and which it does not.

![A grid of 19 small clay characters, one for each AI agent FireAI 1.0.4 recognises, from Claude Code and Cursor to OpenClaw, Hermes Agent and Muse.](https://cdn.hisnlabs.com/blog/ai-agents-recognised-by-fireai.png)

*The characters FireAI shows for each recognised agent. They are FireAI illustrations, not the vendors’ logos.*

## Background

An AI agent on a Mac runs with the permissions of the account that starts it. It reads files, runs shell commands and opens network connections, and it decides what to do next from text it reads, including text written by someone else. OWASP defines prompt injection as a vulnerability that “occurs when user prompts alter the LLM’s behavior or output in unintended ways”, and lists “disclosure of sensitive information” among its impacts [[1]](https://genai.owasp.org/llmrisk/llm01-prompt-injection/).

FireAI is a network firewall. It does not run inside an agent and does not read prompts, files or the contents of encrypted connections. What it does see is which program opens each connection, the destination host, and how many bytes are sent [[5]](https://hisnlabs.com/en/docs/agent-profile). Agent profile, introduced in FireAI 1.0.2, uses that metadata to learn where each agent normally connects, and flags a destination it has never contacted or an unusually large upload. The Agent profile security mode, added in 1.0.3, blocks a new destination until the user allows it [[6]](https://hisnlabs.com/en/docs/security-modes).

## What OWASP describes

### Top 10 for LLM Applications 2025

- LLM01:2025 Prompt Injection. Example scenario 2 describes hidden instructions in a web page that make a model “insert an image linking to a URL, leading to exfiltration of the private conversation” [[1]](https://genai.owasp.org/llmrisk/llm01-prompt-injection/).
- LLM02:2025 Sensitive Information Disclosure. The entry names “personal identifiable information (PII), financial details, health records, confidential business data, security credentials, and legal documents” as the information at stake [[2]](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/).
- LLM06:2025 Excessive Agency. The entry traces the risk to excessive functionality, permissions and autonomy, and its example has an incoming email trick an agent into scanning the user’s inbox and forwarding sensitive information to the attacker [[3]](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/).

### Top 10 for Agentic Applications for 2026

- ASI01 Agent Goal Hijack: hidden instructions in web pages or documents “silently redirect an agent to exfiltrate sensitive data or misuse connected tools” [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/).
- ASI02 Tool Misuse and Exploitation: agents misuse legitimate tools, “leading to data exfiltration, tool output manipulation or workflow hijacking”. The examples include an agent chaining legitimate administrative tools, cURL among them, to send out sensitive logs, and an approved ping tool used to leak data through DNS queries [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/).
- ASI04 Agentic Supply Chain Vulnerabilities: among the examples, a compromised npm package installed automatically by coding agents that “exfiltrated SSH keys and API tokens” [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/).
- ASI05 Unexpected Code Execution: shell commands hidden in a prompt that the agent runs, “resulting in unauthorized system access or data exfiltration” [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/).
- ASI10 Rogue Agents: an agent that keeps sending data out after an indirect prompt injection, with the mitigation of a behavioural layer that monitors for deviations, including “unexpected data exfiltration attempts” [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/).

For ASI02, the document’s third mitigation is titled Execution Sandboxes and Egress Controls and reads: “Enforce outbound allowlists and deny all non-approved network destinations” [[4]](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/). The same entry asks for per-tool least-privilege profiles that include egress allowlists. These two recommendations are the ones a network firewall on the Mac can carry out.

> FireAI, the on-device firewall for macOS developed by HisnLabs, learns where each AI agent on a Mac normally connects and flags or blocks a first-ever destination. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## What FireAI 1.0.4 recognises

Earlier versions recognised Claude Code, the Claude desktop app and Cursor by their code signature, and ChatGPT and Codex by their path. Agents that run inside a script runtime were not recognised: to the firewall, OpenClaw was node and Aider was python [[5]](https://hisnlabs.com/en/docs/agent-profile). FireAI 1.0.4 reads the arguments of node, bun, deno and python processes to find the script they run, and adds 14 agents.

| Agent | How FireAI recognises it |
| --- | --- |
| Claude Code, Claude, Cursor | Code signature with the developer’s team identifier; Claude Code also by its install folder |
| ChatGPT, Windsurf, Kiro, Trae, Goose, OpenClaw | The app bundle the program runs from |
| Muse from Meta | The signing identifier of its Mac App Store app |
| Codex, opencode, Crush, Goose, Cursor’s command-line agent | The name of the native command-line program |
| OpenClaw, Hermes Agent, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, opencode, Aider, Codex, Claude Code | The script run by node, bun, deno or python, or the folder it is installed in |

*Recognition rules in FireAI 1.0.4. Some agents are matched in more than one way.*

OpenAI describes dots as agents that run on their own computer in the cloud [[8]](https://openai.com/index/introducing-dots/). Their traffic on the Mac passes through the ChatGPT app, so FireAI counts it as ChatGPT’s. Meta’s Muse [[9]](https://ai.meta.com/muse/) is recognised by its App Store identifier.

Recognition extends to what an agent starts. When a shell, git, curl or a package installer opens a connection, FireAI walks up the chain of parent processes, up to eight levels, until it reaches a recognised agent, and records the connection under that agent [[5]](https://hisnlabs.com/en/docs/agent-profile). This is the case OWASP describes under ASI02, where legitimate tools such as cURL carry the data out: the tool is trusted, but its parent is an agent.

Agentic web browsers and terminal apps are deliberately left out. All of their traffic would count as the agent’s, and the Agent profile mode would then block ordinary browsing.

## How the controls map to the OWASP entries

| OWASP entry | FireAI control | What remains outside it |
| --- | --- | --- |
| LLM01, ASI01: injected instructions redirect the agent | A request to a host the agent has never contacted is flagged, or blocked in the Agent profile mode | The injection itself; data sent to a destination the agent already uses |
| LLM02: sensitive information disclosed | An upload spike is flagged: an hour with at least 4 times the agent’s busiest hour, and never under 25 MB | Small leaks such as a single key or token; FireAI cannot tell whether data is sensitive |
| LLM06: excessive agency | Per-app rules limit which destinations any program may reach | Messages sent through a service the agent is allowed to use, such as its mail provider |
| ASI02: legitimate tools used to exfiltrate | Child processes are attributed to the agent; the Agent profile mode acts as a learned outbound allowlist | Data encoded in DNS queries: DNS is never blocked by the Agent profile mode |
| ASI04, ASI05: a package or command run by the agent | Connections from code the agent runs are flagged or blocked like the agent’s own | Code that runs later, outside the agent, falls under the ordinary per-app rules instead |
| ASI10: an agent that keeps sending data out | Each agent has a baseline; departures from it are flagged with a plain-language sentence | Behaviour learned during the first 3 days becomes part of the baseline |

*Sources: OWASP [1] to [4] for the entries; the FireAI documentation [5] for the controls.*

The flag describes the facts FireAI measured, for example that an agent has never contacted a server before and sent 40 MB to it. When the on-device AI model is turned on, it rewords those facts into a sentence. It does not judge whether a destination is safe; the decision stays with the user [[5]](https://hisnlabs.com/en/docs/agent-profile).

The remaining entries of the 2026 list, Identity and Privilege Abuse (ASI03), Memory and Context Poisoning (ASI06), Insecure Inter-Agent Communication (ASI07), Cascading Failures (ASI08) and Human-Agent Trust Exploitation (ASI09), concern what happens inside agents and between them. A network firewall on the Mac sees their consequences only when they end in a connection.

## Recommendations

1. Let each agent run normally for its first 3 days, so that its baseline reflects ordinary work rather than an experiment with a new tool.
2. Read the AI agents card in Suggestions regularly. A first-ever destination right after the agent read a web page, an email or an unfamiliar repository is the pattern OWASP describes under ASI01.
3. For an agent that works on sensitive code or documents, switch to the Agent profile security mode, so that new destinations are blocked until allowed [[6]](https://hisnlabs.com/en/docs/security-modes).
4. Keep secrets out of the agent’s reach. FireAI sees where data goes, not what it is, and it cannot recall data already sent to an allowed destination.
5. For an agent FireAI does not name, write a rule for the program it runs as [[7]](https://hisnlabs.com/en/docs/per-app-rules).

## Relevance to FireAI

FireAI applies the egress side of the OWASP guidance on the Mac itself: an allowlist per agent, learned rather than written by hand, with a flag or a block when it is breached. It works from connection metadata only, and nothing about the user’s activity leaves the Mac. It does not prevent prompt injection, does not inspect what an agent sends, and does not replace sandboxing, least-privilege credentials or human approval of high-impact actions, which the OWASP documents also recommend.

> FireAI recognises Claude Code, Cursor, Gemini CLI, OpenClaw, Hermes Agent and 14 other agents on macOS, and lets the user decide where each may send data. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

- FireAI recognises the 19 agents listed above, not every agent. Any other program, agent or not, is covered by FireAI’s ordinary connection prompts and per-app rules, but has no baseline and raises no agent flags.
- Recognition by path or by script name is a label for the baseline, not a proof of identity. A program can copy another agent’s folder name. Only Claude Code, Claude and Cursor are checked against their developer’s team identifier; Muse’s team identifier has not yet been checked on an installed copy.
- A child process that exits within roughly a tenth of a second may be gone before FireAI walks up its parents, and its connection is then not attributed to the agent.
- During the first 3 days nothing is flagged, and anything the agent does in that period becomes normal for it.
- Destinations are grouped by domain. Data sent to a new server under a domain the agent already uses, or to a shared service such as a code host, is not flagged.
- FireAI cannot read prompts, MCP tool contents, skills or encrypted traffic, and does not see which files an agent opens.
- The mapping above is HisnLabs’ reading of the OWASP documents. OWASP has not reviewed or endorsed FireAI.

## How FireAI and HisnLabs fit in

An agent on your Mac can be steered by a hidden instruction. FireAI shows, and can block, where its data goes next.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [OWASP Gen AI Security Project: LLM01:2025 Prompt Injection](https://genai.owasp.org/llmrisk/llm01-prompt-injection/)
- [OWASP Gen AI Security Project: LLM02:2025 Sensitive Information Disclosure](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/)
- [OWASP Gen AI Security Project: LLM06:2025 Excessive Agency](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/)
- [OWASP Gen AI Security Project: OWASP Top 10 for Agentic Applications for 2026 (9 December 2025)](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
- [OpenAI: Introducing dots](https://openai.com/index/introducing-dots/)
- [Meta AI: Muse](https://ai.meta.com/muse/)
