# Amp Coding Agent Security on Mac: Monitor Its Connections

> Amp is a coding agent with a CLI and a Mac app that syncs threads to ampcode.com. See what its docs say about data flow and settings, and how FireAI flags new destinations.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai

Amp is a coding agent from Ampcode that you can use on the web, from a command-line tool or in native apps. Unlike a purely local tool, it keeps conversations as threads on ampcode.com, so network traffic is part of how it works. Searches such as "amp coding agent security" and "is Amp safe" therefore call for a plain account of what is documented. This article gives it, then shows how FireAI, a network firewall for macOS developed by HisnLabs, watches Amp’s connections on your Mac.

## What Amp is and how it runs on a Mac

The [manual](https://ampcode.com/manual) calls Amp a coding agent and development environment, available on the web, as a CLI, and as macOS and iOS apps, with threads that continue across them. It supports MCP for customisation. The [CLI documentation](https://ampcode.com/docs/cli) gives an install script (`curl -fsSL https://ampcode.com/install.sh | bash`), supports macOS, Linux and Windows through WSL, and says the CLI can run the agent on your machine, in a cloud environment the docs call an orb, or on a connected runner. Accounts are managed with `amp login`, `amp account list` and `amp logout`, and the `AMP_API_KEY` environment variable takes precedence over saved accounts.

## What it can access and where data goes

The [security page](https://ampcode.com/security) says Amp collects code snippets and conversation threads, including user messages, model responses, code context and tool results, and that it does not see, store, clone or index the entire codebase. It states that secrets are automatically redacted before they enter threads or reach external services. Code snippets are sent to several model providers, Google Cloud hosts the primary infrastructure, and the company says all infrastructure operates on US-based servers. Deleted threads are removed within 30 days. These are the vendor’s statements, which we could not test independently.

## Settings that shape its behaviour

The [settings documentation](https://ampcode.com/docs/cli/settings) lists user settings in `~/.config/amp/settings.json` and workspace settings in `.amp/settings.json`. Relevant keys include `amp.tools.disable` to block specific tools, `amp.mcpServers` to configure MCP servers, `amp.defaultVisibility` for thread privacy by repository, and `amp.remoteThreadCreation.enabled`, which controls whether ampcode.com may create threads remotely. Workspace administrators can apply managed settings that override local ones. The pages reviewed did not describe a permission-prompt system in detail, so check the current manual for what Amp asks before it runs a command.

> Amp is built to talk to a service. FireAI helps you notice when it talks to a service it never used before. Try it free. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Watching Amp with FireAI

FireAI is an on-device firewall for macOS developed by HisnLabs. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature lists Amp among the 19 AI agents it recognises, and it identifies Amp by the script the runtime runs, the method Agent profile uses for agents started through node, bun, deno or python. The agent’s child processes, such as a shell, git or curl it launches, are attributed to it by walking up the parent processes. FireAI then learns, for the first 3 days, which destinations Amp normally contacts, grouped by domain, and flags nothing during that period. After that, a first-ever destination is flagged in Suggestions, in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.

FireAI uses metadata only, host names and byte counts, and never reads the payload of a connection. By default it flags and leaves the decision to you. In the Agent profile security mode it goes further: once learning has finished, a connection to a destination outside the baseline is blocked until you press Allow, and Keep blocked turns that block into a rule that holds in every mode.

### Setup, step by step

1. Install FireAI and finish its first-run setup, following [Install and finish setup](https://hisnlabs.com/en/docs/install-and-finish-setup).
2. Use Amp as you normally do for 3 days. FireAI learns its destinations in the background and flags nothing yet.
3. Open Suggestions and find the AI agents card. When a flag appears, read the plain-words sentence, then swipe left in Quick Review to block or right for "It’s fine".
4. If you want the agent kept to places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack.
5. When something is blocked, open the AI agents card and choose Allow to add it to the baseline, or Keep blocked to create a block rule.

## Limits

- FireAI does not prevent prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see Amp’s prompts, the contents of MCP tools, skills, or which files it reads, because TLS hides the payload and FireAI is not inside the agent.
- Amp is matched by script name, so FireAI labels it rather than verifying it: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- Because Amp is designed to send code context to its service and model providers, a large upload to its usual domain is expected; the spike flag only fires on an hour at least 4 times your busiest so far and above 25 MB.
- Work Amp does in a cloud orb or on a remote runner happens off your Mac, where FireAI cannot see it.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- A new server under a domain the agent already uses is treated as known, because destinations are grouped by domain.

The feature is described in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile).

Other agents FireAI recognises have their own guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai).

## How FireAI and HisnLabs fit in

Amp sends code context to model providers by design. FireAI shows, and can block, any new destination it reaches.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [Amp manual](https://ampcode.com/manual)
- [Amp documentation: CLI](https://ampcode.com/docs/cli)
- [Amp documentation: CLI settings](https://ampcode.com/docs/cli/settings)
- [Amp security page](https://ampcode.com/security)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
