# Gemini CLI Security on Mac: Monitor Its Network Connections

> Gemini CLI by Google runs shell commands, reads files and fetches web pages from your terminal. See its documented sandbox and trusted folders, and how FireAI flags new destinations.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai

Gemini CLI is Google’s open-source command-line agent. It reads and edits files, runs shell commands and fetches web pages, so people searching for "gemini cli security mac" or "is Gemini CLI safe" want to know what limits exist and where its traffic goes. This article summarises Google’s own documentation and then shows how FireAI, a network firewall for macOS developed by HisnLabs, watches it.

## What Gemini CLI is and how it runs on a Mac

The [repository](https://github.com/google-gemini/gemini-cli) describes Gemini CLI as an open-source AI agent that brings Gemini into your terminal. It is developed by Google under the Apache License 2.0. It installs with npm (`npm install -g @google/gemini-cli`) or Homebrew (`brew install gemini-cli`), or runs without installation through `npx @google/gemini-cli`. It is therefore a Node.js program, and it signs in with a Google account (OAuth), a Gemini API key or Vertex AI.

## What it can access

Its built-in tools cover file system operations, shell command execution, web fetching with Google Search grounding, and MCP servers for custom integrations. The README mentions usage tracking, described in its telemetry documentation, which is where to check what the tool reports.

## The documented permission and sandbox model

Google documents two controls that matter on a Mac.

- Sandboxing: on macOS the lightweight option uses Seatbelt (`sandbox-exec`) profiles. The default profile, `permissive-open`, confines writes to the project directory while allowing broad file reads and network access. Stricter profiles, including proxied variants, are chosen with the `SEATBELT_PROFILE` environment variable, and Docker or Podman containers are the alternative. It is enabled with `-s` or `--sandbox`, `GEMINI_SANDBOX`, or settings.json.
- Trusted Folders: disabled by default. When enabled, an untrusted folder puts the CLI in safe mode, which turns off workspace settings, MCP server connections, custom commands and tool auto-acceptance.

The sandbox page itself states that sandboxing reduces but does not eliminate all risks. Note that the default Seatbelt profile still allows network access, so it does not limit where data can be sent.

The documentation reviewed does not publish a complete list of domains Gemini CLI contacts. Google sign-in, the Gemini API and any page it fetches are the obvious candidates, but only your own observation can confirm them.

> The default sandbox allows network access. FireAI watches that gap: it shows each new destination and lets you block it. Try it free. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Watching Gemini CLI with FireAI

FireAI is an on-device firewall for macOS developed by HisnLabs. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature lists Gemini CLI among the 19 AI agents it recognises, and because Gemini CLI runs through node, it identifies it by the script the runtime runs, as Agent profile does for node, bun, deno and python agents. The agent’s child processes, such as a shell, git or curl it launches, are attributed to it by walking up the parent processes. FireAI then learns, for the first 3 days, which destinations Gemini CLI normally contacts, grouped by domain, and flags nothing during that period. After that, a first-ever destination is flagged in Suggestions, in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.

FireAI uses metadata only, host names and byte counts, and never reads the payload of a connection. By default it flags and leaves the decision to you. In the Agent profile security mode it goes further: once learning has finished, a connection to a destination outside the baseline is blocked until you press Allow, and Keep blocked turns that block into a rule that holds in every mode.

### Setup, step by step

1. Install FireAI and finish its first-run setup, following [Install and finish setup](https://hisnlabs.com/en/docs/install-and-finish-setup).
2. Use Gemini CLI as you normally do for 3 days. FireAI learns its destinations in the background and flags nothing yet.
3. Open Suggestions and find the AI agents card. When a flag appears, read the plain-words sentence, then swipe left in Quick Review to block or right for "It’s fine".
4. If you want the agent kept to places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack.
5. When something is blocked, open the AI agents card and choose Allow to add it to the baseline, or Keep blocked to create a block rule.

## Limits

- FireAI does not prevent prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see Gemini CLI’s prompts, the contents of MCP tools, skills, or which files it reads, because TLS hides the payload and FireAI is not inside the agent.
- Gemini CLI is matched by script name, so FireAI labels it rather than verifying it: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- A web page the agent fetches is a legitimate destination for the agent but may be new to its baseline, so expect flags when you ask it to research.
- FireAI works alongside Gemini CLI’s sandbox and Trusted Folders, it does not replace them.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- A new server under a domain the agent already uses is treated as known, because destinations are grouped by domain.

Prompt injection, where text in a fetched page steers an agent, is catalogued by [OWASP](https://genai.owasp.org/llmrisk/llm01-prompt-injection/). FireAI does not stop it. The feature is described in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile).

Other agents FireAI recognises have their own guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai).

## How FireAI and HisnLabs fit in

Gemini CLI can run commands and fetch the web from your terminal. FireAI shows, and can block, where it connects next.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [Gemini CLI repository (README)](https://github.com/google-gemini/gemini-cli)
- [Gemini CLI documentation: Sandboxing](https://github.com/google-gemini/gemini-cli/blob/main/docs/cli/sandbox.md)
- [Gemini CLI documentation: Trusted Folders](https://github.com/google-gemini/gemini-cli/blob/main/docs/cli/trusted-folders.md)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [OWASP Gen AI Security Project: LLM01:2025 Prompt Injection](https://genai.owasp.org/llmrisk/llm01-prompt-injection/)
