# Crush Agent Security on Mac: Monitor Its Network with FireAI

> Crush is a Go terminal coding agent from Charm with permission prompts, MCP and provider catalogue updates. See what it can reach on a Mac and how FireAI watches its connections.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai

Crush is a terminal coding agent from Charm, the company behind a well-known family of command-line tools. It asks before it runs a tool, can be told not to, and documents more than one network behaviour in its README. That makes it a good subject for readers who search “crush ai agent security mac”, “crush network access” or “is Crush safe”. This article collects what the README states, then explains how FireAI, an on-device firewall for macOS made by HisnLabs, watches the connections of a single compiled program.

## What Crush is

Crush is developed by Charm (charmbracelet on GitHub) and is written in Go. The README describes it as agentic coding software for the terminal that connects tools, code and workflows to language models. It supports many providers, including OpenAI, Anthropic, Gemini, Ollama and Bedrock, and its model catalogue is kept current from Catwalk, an open-source provider database. It can use MCP servers over stdio, HTTP and SSE, with OAuth for HTTP, and language servers (LSPs) for code context [[1]](https://github.com/charmbracelet/crush).

## How Crush runs on macOS

The README lists `brew install charmbracelet/tap/crush`, `npm install -g @charmland/crush`, `go install github.com/charmbracelet/crush@latest` and pre-built binaries for macOS. Because it is a Go program, the process on the Mac is a single native executable named `crush`, not an interpreter running a script.

## What it can access and how it is controlled

By default Crush asks for permission before executing tool calls. The `--yolo` flag bypasses every prompt, and the README warns: “Be very, very careful with this feature.” Permissions can also be configured: `permissions allow` lets named tools run without prompting, and `permissions deny` hides tools from the agent entirely. Configuration covers providers, LSPs, MCPs, permissions, themes and skills [[2]](https://github.com/charmbracelet/crush/blob/main/README.md).

These controls decide which tool calls proceed. The README does not describe a network allow-list.

## Where it connects

The README documents two behaviours that open connections without a prompt of yours. First, Crush collects pseudonymous usage metadata, and states that prompts and responses are never collected; it is turned off with `CRUSH_DISABLE_METRICS=1` or by honouring `DO_NOT_TRACK`. Second, it fetches the provider catalogue from Catwalk automatically, which can be switched off with `CRUSH_DISABLE_PROVIDER_AUTO_UPDATE=1` and refreshed by hand with `crush update-providers` [[2]](https://github.com/charmbracelet/crush/blob/main/README.md). Other destinations depend on the provider and MCP servers you configure.

> **Note:** This article reports what Crush’s own documentation says and what it leaves out. We list no domain, incident or vulnerability that the sources above do not state.

## Watching Crush with FireAI

FireAI is a firewall for macOS that runs on the Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, learns where each normally connects and flags what is new. FireAI’s Agent profile page lists Crush among the command-line agents recognised by the name of their program. Connections from a program named `crush`, and from its child processes such as a shell, git or curl, are attributed to Crush.

- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain, so api.anthropic.com becomes anthropic.com. Nothing is flagged during this period.
- After that, the first-ever destination outside the baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
- FireAI uses metadata only, meaning host names and byte counts. It never reads the payload of a connection.

> Want a firewall that tells you when Crush reaches somewhere new? FireAI learns each agent’s normal destinations on your Mac. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Setting up FireAI for Crush

1. Install FireAI and use the agent as you normally do. The 3-day learning period starts on its own and flags nothing.
2. Open Suggestions and find the AI agents card. After the learning period, a flag for the agent appears there and in Quick Review.
3. Review each flag. Choose Block to create a rule for the process that connected, or “It’s fine” to add the destination to the agent’s baseline.
4. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and a connection to a destination outside the baseline is blocked instead of flagged once the agent has finished learning.
5. A blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent reaches it right away. Keep blocked creates a block rule that holds in every mode.

An allow rule you wrote for a website, domain or address still wins, and DNS and your local network are never blocked. For an agent FireAI does not list, write a rule for its program by hand in [per-app rules](https://hisnlabs.com/en/docs/per-app-rules). The Agent profile mode needs FireAI 1.0.3 or later, and recognition of Crush needs 1.0.4.

## Limits

- Environment variables such as `CRUSH_DISABLE_METRICS` change what Crush itself sends. FireAI does not read those settings; it only reports which hosts the program contacts and how much it uploads.
- Crush is recognised by the name of its program, which means it is labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, file access or skills. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and they are matched by path, not by signature.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address, so a new address for a service the agent normally uses is blocked until you allow it.

## Other agents

The same approach applies to every agent FireAI recognises. See the other guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent running on python or node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile), published by HisnLabs.

> See every connection your Mac makes — and decide which ones go through. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## How FireAI and HisnLabs fit in

FireAI learns where Crush normally connects on your Mac and flags a first-ever destination or an upload spike, without reading your data.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [Crush: project repository and README (GitHub)](https://github.com/charmbracelet/crush)
- [Crush: README configuration reference (GitHub)](https://github.com/charmbracelet/crush/blob/main/README.md)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
