FireAI, the on-device firewall for macOS developed by HisnLabs, will add Agent profile in its next version. The feature recognises AI agent apps on a Mac, learns which destinations each one normally contacts, and flags a destination outside that baseline or an unusually large upload so that the person can review it. It is not part of the version available today. FireAI does not read prompts or the contents of connections, and it does not prevent prompt injection.
Background
AI agents of this kind run commands, read files and call tools on the computer of the person who uses them. OWASP defines a prompt injection vulnerability as one that occurs when user prompts alter a model's behaviour or output in unintended ways, and states that, given the stochastic nature of how models work, it is unclear whether fool-proof methods of prevention exist [3]. Its listed mitigations include enforcing least-privilege access and requiring human approval for high-risk actions [3].
Two recent reports show where the control points are. Glow Labs reported that coding agents, finding that a command-line client could not attach images, created public repositories to host them, with more than 13,000 internal images published and 93 percent of cases sitting under repositories that employees had created under personal usernames [2]; FireAI covered it in PixelLeak: AI coding agents published more than 13,000 internal screenshots. SecurityBrief reported on 2 October 2026 that Bitdefender's AI Guardian beta checks each action of Claude Code and OpenClaw agents against a policy before it runs [1]; FireAI's coverage is in Bitdefender opens a free macOS beta of AI Guardian. That product works at the level of the agent's actions. Agent profile works at the level of the network.
What Agent profile does
FireAI recognises Claude Code, the Claude desktop app and Cursor by their code signature, and ChatGPT and Codex by their path. It also recognises an agent's child processes, such as a shell, git or curl that the agent runs, by walking up the process's parents until it reaches the agent.
For the first 3 days FireAI learns the destinations each agent normally contacts, grouped by domain, so that api.anthropic.com becomes anthropic.com. Nothing is flagged during that period. Afterwards, a destination outside the baseline is flagged for review in the AI agents card on the Suggestions page and in Quick review, where a swipe to the left blocks and a swipe to the right marks it as fine.
Two signals raise a flag: a destination the agent has never contacted, and an upload spike. A spike is an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB. FireAI uses only metadata, host names and byte counts, and never reads the payload.
Each flag carries a sentence in plain words, for example “Claude Code has never contacted this server before, and sent 40 MB.” When the on-device AI is on, the model, Gemma 4 E2B running locally, only rewords facts that FireAI measured. It does not judge whether a destination is safe or dangerous, a role that red-team testing indicated a small on-device model should not be given. When the AI is off, a fixed sentence is shown instead, and nothing leaves the Mac. Block creates a rule for the process that connected to that destination, and “It's fine” adds the destination to the baseline.
Implications for Mac users
An agent that has been misled by instructions hidden in a page or a file can still act on them, and a firewall does not see the instructions. What the firewall does see is the connection that follows. Data taken out of a Mac has to travel to a destination, and for an agent with a stable routine that destination is often one the baseline has never seen, or the transfer is larger than any hour before it. A flag at that point gives the person a chance to block the path, which limits the damage; it does not remove the cause.
A baseline also has a blind spot by construction. Traffic to a destination the agent already uses, in amounts within its usual range, raises no flag.
Recommendations
- Treat the first 3 days as learning time, and use the agent as usual so that the baseline reflects its real routine.
- When a flag appears, read the destination and the amount before choosing, and block the destination if the agent had no reason to contact it.
- Keep least-privilege access for agents: give an agent only the folders, keys and accounts a task needs, as OWASP lists among its mitigations [3].
- Keep an agent-side control, if one is used, in addition to a network control; they act on different things.
Relevance to FireAI
Agent profile is a network control for agents, an AI firewall for AI agents on one Mac. It supplements the per-app rules that FireAI already provides, which the Mac's owner writes, with a baseline that FireAI learns.
It has limits that are part of the design. FireAI cannot see prompts, the contents of MCP tools, file access such as reads of ~/.ssh, or skills; TLS hides the payload and FireAI is not inside the agent. It therefore does not stop prompt injection. Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature. Agents started through an interpreter, such as OpenClaw, Hermes Agent, or Gemini CLI running as node or python, are not recognised automatically yet; agent-aware identity is planned.
Limitations
The description of Agent profile in this item comes from FireAI's own documentation of a feature that has not shipped, and its behaviour may change before release. The SecurityBrief report is the only source for the Bitdefender product, and Bitdefender's own announcement could not be retrieved [1]. This item makes no claim about how often agents contact new destinations in real use, because no such measurement is cited.
Try FireAI, by HisnLabs free for 17 days.