# Every Other AI Agent on Your Mac: Python, npm, Bun, Native

> AI agents outside FireAI's list of 19 still get connection prompts and per-app rules. How node and python agents appear, and how to cover them with rules and security modes.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai

New AI agents appear faster than any list can follow. Many are installed with `npm`, `pip`, `bun` or `deno`, or run as a script someone wrote last week, and they connect to whatever their code says. FireAI recognises 19 named agents and gives them a learned baseline. This article explains what protection every other agent still gets, how a node or python agent appears in FireAI, and what to set up, using only what the [FireAI documentation](https://hisnlabs.com/en/docs/agent-profile) states.

## What FireAI does for the 19 recognised agents

FireAI 1.0.4 recognises Claude Code, Claude, Cursor, ChatGPT, Codex, GitHub Copilot CLI, Gemini CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, OpenClaw, Hermes Agent and Muse from Meta. For each, it learns for 3 days where the agent normally connects, then flags a destination it has never contacted and an upload spike of at least 4 times the busiest hour so far and at least 25 MB. Each has its own article:

- [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai)
- [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai)
- [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai)
- [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai)
- [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai)
- [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai)
- [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai)
- [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai)
- [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai)
- [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai)
- [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai)
- [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai)
- [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai)
- [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai)
- [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai)
- [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai)
- [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai)
- [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai)
- [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai)

## What an unlisted agent still gets

The documentation is direct about this limit: "Any other agent is still covered by your connection prompts and per-app rules, but has no baseline and raises no agent flags." In practice:

- Connection prompts: in Alert mode, the first time an app reaches a destination with no matching rule, FireAI pauses that connection and asks. The prompt shows the app, the destination and, when FireAI can tell, its country and company.
- Per-app rules: you can allow or block a specific app and destination by hand, as precisely as one IP address or as broadly as a whole domain.
- Security modes: Paranoid and Under attack apply to every app, listed or not. In Under attack, only apps with an explicit Allow rule may connect.
- No baseline and no agent flags: FireAI will not tell you that an unlisted agent has just reached a destination it has never used, or that it has uploaded an unusual amount. You see the prompt, or the rule decides.

## How a node or python agent appears

Agents written in JavaScript or Python run inside a general-purpose runtime. FireAI documents that agents run by node, bun, deno or python, such as OpenClaw, Hermes Agent, Gemini CLI, Copilot CLI, Amp, Qwen Code and Aider, are recognised by the script the runtime runs. That is how the listed ones are recognised. For an agent that is not on the list, FireAI has no profile for the script, so the connection belongs to the runtime. A rule written for the program applies to that program, which means a rule for `node` or `python3` affects every script running under it, not only the agent.

> **Warning:** Before you write a broad rule for a runtime, look at what else on your Mac uses it. A rule that blocks `python3` for one agent also blocks every other Python tool.

## Cover an unlisted agent, step by step

1. Run the agent once with FireAI open in the default mode and watch the connection prompts. Click Details on a prompt to see the exact address, port and the app's code-signing status.
2. Click Options before answering to choose how long the answer lasts (Just this once, Until the app quits, Until I restart, or Always) and how wide it is (Only this address, The whole website, This server (IP) only, or Anywhere). Note that without a licence, every answer applies just this once.
3. Open Rules and click Add rule to write the rule yourself: choose the app, Allow or block, a website, a domain with its subdomains, an IP address or a range, and Always or Until I restart my Mac. Under Advanced you can set direction, protocol and port.
4. For a strict setup, allow only the destinations the agent genuinely needs (for example the model provider's host) and let the prompt ask about the rest.
5. When you are running something you do not fully trust, switch the security mode to Paranoid, or to Under attack so only apps with an explicit Allow rule connect. Your own rules and an explicit Allow rule for an app always win over a mode.
6. To look closer at one connection, open Threats and use Investigate, or choose Investigate from a line on the World map. You get a risk score out of 100, the reasons and what FireAI saw. A single sign rarely means much, and the decision stays with you.

The Agent profile security mode is a separate option for the 19 recognised agents: it blocks a destination outside an agent's baseline once learning is complete. For an unlisted agent there is no baseline, so it has nothing to compare against.

## Limits

- An unlisted agent has no baseline and raises no agent flags.
- FireAI cannot see prompts, the contents of tools, or file access, and it does not stop prompt injection. TLS hides the payload.
- FireAI uses host names and byte counts only. It cannot tell you what an agent sent, only where and how much.
- Rules written for a runtime apply to everything the runtime runs.

If an agent you use should be on the list, the recognised ones are described in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile).

> Run an agent FireAI does not list? Prompts and per-app rules still decide where it may connect. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## How FireAI and HisnLabs fit in

Any agent can be covered by rules. The 19 recognised ones also get a learned baseline and flags.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
- [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes)
- [FireAI docs: Answer your first connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt)
- [FireAI docs: Investigate a connection](https://hisnlabs.com/en/docs/investigate-a-connection)
