# Is Windsurf Safe on Mac? Monitor Its Network Access with FireAI > What the Windsurf AI editor can reach on a Mac, its documented terminal permission levels, and how FireAI learns its connections and flags a new destination or an upload spike. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai Windsurf is an AI-assisted code editor for macOS built around an agent called Cascade. Like any editor with an agent inside it, it can read the files in your project, run commands in a terminal and call services over the network. This article sets out, from the vendor's own pages, what Windsurf is and what it is documented to be able to do, and then shows how to watch its network connections on a Mac with FireAI. ## What Windsurf is and who makes it The Windsurf website now redirects to a product page for Devin Desktop, which states: "Devin Desktop is the new name for Windsurf. We're building on the IDE foundation of Windsurf to introduce the command center for managing all your agents in one place." The page offers a "Download for MacOS" button, refers to Cognition, and notes that Windsurf for JetBrains remains available for download ([devin.ai/desktop](https://devin.ai/desktop)). The documentation moved with it: pages formerly at docs.windsurf.com now redirect to docs.devin.ai. > **Note:** Naming has changed. This article says "Windsurf" because that is the name searchers and FireAI's agent list use. Whether a renamed build is matched by FireAI under the Windsurf profile depends on the app FireAI sees; it was not verified for this article. ## What Cascade can access The documentation describes Cascade as the agentic assistant with Code and Chat modes, tool calling, checkpoints and linter integration. It states that Cascade has access to "Search, Analyze, Web Search, MCP, and the terminal", and that it can detect which packages and tools you use and install them for you ([Cascade documentation](https://docs.devin.ai/desktop/cascade/cascade)). Web search, MCP servers and installed packages all imply outbound network traffic, and a terminal command can open any connection the command itself is able to make. ## The documented permission model for terminal commands Windsurf's documentation defines four auto-execution levels for terminal commands ([terminal documentation](https://docs.devin.ai/desktop/terminal)): - Disabled: all commands require manual approval before execution. - Allowlist Only: only commands that match entries in your allow list are auto-executed; all others require approval. - Auto: the agent uses its judgment to decide whether a command is safe to auto-execute, and commands it deems potentially risky still require approval. - Turbo: all commands are auto-executed immediately, except those in your deny list. An allow-list entry ending in a star matches every command that starts with the same tokens, and a deny list prevents auto-execution; if a command matches both, approval is required. These settings govern which commands run without asking you. They are a statement about commands, not about the network destinations those commands or the editor's own services contact. ## Which domains does Windsurf contact? The pages cited here do not publish a list of domains, and this article does not guess one. That gap is the practical reason to observe the connections on your own machine rather than rely on a list. ## Watching Windsurf with FireAI FireAI is a firewall for macOS that runs on your Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, Windsurf among them, and identifies Windsurf by the app it runs from. FireAI then learns where that app normally connects and watches for departures. For every recognised agent it works the same way, using only metadata (host names and byte counts); FireAI never reads the payload of a connection. 1. For the first 3 days FireAI learns the destinations Windsurf normally contacts, grouped by domain: api.anthropic.com becomes anthropic.com. Nothing is flagged during this learning period. 2. After that, a destination outside the learned baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for "It's fine". 3. An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB. ## Set up monitoring for Windsurf, step by step 1. Install and open FireAI, then use Windsurf as you normally would for a few days so the 3-day learning period has real traffic to learn from. 2. Open Suggestions and look for the AI agents card. Flags from agents also appear in Quick Review, the card stack you swipe through. 3. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of being flagged. Your own allow rules still win, and DNS and your local network are never blocked. 4. When something is blocked, the AI agents card offers Allow and Keep blocked. Allow adds the destination to the baseline; Keep blocked creates a block rule, so the destination stays blocked in every mode. 5. For a precise rule, open Rules and click Add rule: choose the app, then Allow or block, then a website, a domain with its subdomains, an IP address or a range, and how long it lasts. 6. To understand a single connection, open Threats and use Investigate, or choose Investigate from a line on the World map. The page shows a risk score, the reasons behind it and what FireAI saw. > **Note:** The Agent profile mode needs FireAI 1.0.3 or later, and the 19-agent list needs 1.0.4. Version 1.0.2 flags new destinations but does not block them. ## Limits - FireAI cannot see prompts, the contents of tools, file access such as ~/.ssh, or skills. TLS hides the payload, and FireAI is not inside Windsurf. - FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac. - During the 3-day learning period nothing is flagged, and in the Agent profile mode nothing is blocked while an agent is still learning. Upload spikes are flagged, never blocked. - Agents matched by app, path or script name are labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer's signature. - Child processes that exit very quickly may be missed, and they are matched by path, not by signature. - A Windsurf release that runs under a different app name than the one FireAI recognises would not have a Windsurf baseline; it would still be covered by connection prompts and per-app rules. The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile). > Learn where Windsurf normally connects, then get a flag the first time it reaches somewhere new. [Download FireAI for Mac](https://hisnlabs.com/en/download) Other agents in this series: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai). The catch-all guide for every other agent is [Every other AI agent on your Mac](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). ## How FireAI and HisnLabs fit in Windsurf runs commands and talks to the network. FireAI shows where, and lets you block a new destination. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [Devin Desktop (Windsurf): product page](https://devin.ai/desktop) - [Devin Desktop documentation: Cascade](https://docs.devin.ai/desktop/cascade/cascade) - [Devin Desktop documentation: Terminal command auto-execution](https://docs.devin.ai/desktop/terminal) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile) - [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes) - [FireAI docs: Answer your first connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt) - [FireAI docs: Investigate a connection](https://hisnlabs.com/en/docs/investigate-a-connection)