# Is Qwen Code Safe on Mac? Monitor Its Network with FireAI

> Qwen Code is an open-source terminal coding agent that runs on Node.js. See what it can reach on a Mac, its approval modes and sandbox, and how FireAI watches its connections.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai

Qwen Code is an open-source coding agent that lives in a terminal, reads a project, edits files and runs shell commands on request. Developers search for “is Qwen Code safe” and “Qwen Code network access” for a practical reason: the agent sends your prompts and parts of your code to a model provider, and a shell command it runs can open connections of its own. This article collects what its documentation says about how it runs on macOS, what it can reach and what permission controls it offers, and then shows how FireAI, an on-device firewall for macOS made by HisnLabs, watches the network side.

## What Qwen Code is

Qwen Code is developed by the QwenLM team, part of Alibaba’s Qwen project, and its repository describes it as an open-source AI coding agent for the terminal, editor, desktop, browser and chat. It is released under the Apache-2.0 licence. Its documentation says it works with OpenAI-compatible, Anthropic, Gemini and Qwen APIs, and with any third-party provider or local model such as Ollama or vLLM [[1]](https://github.com/QwenLM/qwen-code). The destination of its traffic therefore depends on the provider you configure.

## How Qwen Code runs on macOS

On a Mac, Qwen Code is a Node.js program. The README gives `npm install -g @qwen-code/qwen-code@latest`, which requires Node.js 22.0.0 or newer, or `brew install qwen-code`, and it also lists install scripts for Linux, macOS and Windows. A headless mode runs a single prompt from a script with `qwen -p "..."`. Because the npm install runs on the Node runtime, the process macOS sees is `node` executing a script, not a program named after the agent.

## What it can access and how it is controlled

Qwen Code documents five approval modes: Plan (read-only analysis), Ask Permissions (formerly Default, manual approval for file edits and shell commands), Auto-Edit (file changes approved automatically, shell commands still asked), Auto (an LLM classifier approves actions it judges safe and blocks risky ones, and blocks when unsure) and YOLO (all actions approved automatically). Shift+Tab cycles through the modes during a session [[2]](https://qwenlm.github.io/qwen-code-docs/en/users/features/approval-mode/).

On macOS the sandbox page describes two methods: Seatbelt, which uses the built-in `sandbox-exec` and needs no extra software, and Docker or Podman for full isolation. Sandboxing is enabled with `qwen -s`, the `QWEN_SANDBOX=true` variable or `"tools": {"sandbox": true}` in `settings.json`. There are six built-in Seatbelt profiles. The default, `permissive-open`, restricts writes but allows network access; the `-closed` profiles block the network and the `-proxied` profiles route it through a proxy [[3]](https://github.com/QwenLM/qwen-code/blob/main/docs/users/features/sandbox.md). Settings live in `~/.qwen/settings.json` and in `.qwen/settings.json` inside a project [[4]](https://github.com/QwenLM/qwen-code/blob/main/docs/users/configuration/settings.md).

## Where it connects

The documentation pages read for this article do not publish a fixed list of domains. Traffic goes to the model provider and endpoints you configure, to anything an MCP server or a shell command contacts, and, if you sign in with a Qwen account, to that service. Telemetry and data handling are described in the project’s Terms of Service and Privacy Notice, linked from the README. With the default Seatbelt profile the network is open, so the sandbox limits file writes but does not decide where the agent may connect.

> **Note:** This article reports what Qwen Code’s own documentation says and what it leaves out. We list no domain, incident or vulnerability that the sources above do not state.

## Watching Qwen Code with FireAI

FireAI is a firewall for macOS that runs on the Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, learns where each normally connects and flags what is new. FireAI’s Agent profile page lists Qwen Code among the agents run by node, bun, deno or python, which FireAI recognises by the script the runtime runs. In FireAI’s activity list the connection is therefore matched to Qwen Code through its script rather than shown as a bare `node`.

- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain, so api.anthropic.com becomes anthropic.com. Nothing is flagged during this period.
- After that, the first-ever destination outside the baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
- FireAI uses metadata only, meaning host names and byte counts. It never reads the payload of a connection.

> Want a firewall that tells you when Qwen Code reaches somewhere new? FireAI learns each agent’s normal destinations on your Mac. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Setting up FireAI for Qwen Code

1. Install FireAI and use the agent as you normally do. The 3-day learning period starts on its own and flags nothing.
2. Open Suggestions and find the AI agents card. After the learning period, a flag for the agent appears there and in Quick Review.
3. Review each flag. Choose Block to create a rule for the process that connected, or “It’s fine” to add the destination to the agent’s baseline.
4. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and a connection to a destination outside the baseline is blocked instead of flagged once the agent has finished learning.
5. A blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent reaches it right away. Keep blocked creates a block rule that holds in every mode.

An allow rule you wrote for a website, domain or address still wins, and DNS and your local network are never blocked. For an agent FireAI does not list, write a rule for its program by hand in [per-app rules](https://hisnlabs.com/en/docs/per-app-rules). The Agent profile mode needs FireAI 1.0.3 or later, and recognition of Qwen Code needs 1.0.4.

## Limits

- The Auto mode’s classifier and the sandbox profiles belong to Qwen Code and are a separate layer from FireAI. A permissive Seatbelt profile still allows network access, which is exactly the part FireAI watches.
- Qwen Code is recognised by the script the runtime runs, which means it is labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, file access or skills. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and they are matched by path, not by signature.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address, so a new address for a service the agent normally uses is blocked until you allow it.

## Other agents

The same approach applies to every agent FireAI recognises. See the other guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent running on python or node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile), published by HisnLabs.

> See every connection your Mac makes — and decide which ones go through. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## How FireAI and HisnLabs fit in

FireAI learns where Qwen Code normally connects on your Mac and flags a first-ever destination or an upload spike, without reading your data.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [Qwen Code: project repository and README (GitHub)](https://github.com/QwenLM/qwen-code)
- [Qwen Code documentation: approval modes](https://qwenlm.github.io/qwen-code-docs/en/users/features/approval-mode/)
- [Qwen Code documentation: sandbox](https://github.com/QwenLM/qwen-code/blob/main/docs/users/features/sandbox.md)
- [Qwen Code documentation: settings](https://github.com/QwenLM/qwen-code/blob/main/docs/users/configuration/settings.md)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
