# Agent profile: OpenClaw, Hermes Agent & Claude Code security on Mac

> FireAI recognises 19 AI agents, from Claude Code and Cursor to OpenClaw, Hermes Agent and Gemini CLI, learns where each normally connects, and flags a first-ever destination or an upload spike for your review, without reading your data. The Agent profile mode goes further and blocks a new destination until you allow it.

FireAI Docs (HisnLabs) · Función · Disponible desde FireAI 1.0.2
Canonical: https://hisnlabs.com/fireai/en/docs/agent-profile

**Dónde en FireAI:** Suggestions › AI agents, and Quick Review

Know when an AI agent on your Mac reaches somewhere new or sends an unusual amount of data, and block it in one swipe.

AI agents such as Claude Code and Cursor run commands, read files and open network connections on your Mac. Agent profile watches the connections. It learns where each agent normally connects, and when one reaches a destination it has never contacted, or sends far more data than usual, FireAI flags it for you to review.

## What FireAI recognises

FireAI 1.0.4 recognises 19 AI agents: Claude Code, Claude, Cursor, ChatGPT (including OpenAI’s dots, which reach the Mac through it), Codex, GitHub Copilot CLI, Gemini CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, OpenClaw, Hermes Agent and Muse from Meta. Each has its own character in the AI agents card.

- Claude Code, the Claude desktop app and Cursor are recognised by their code signature.
- Apps such as ChatGPT, Windsurf, Kiro, Trae, Goose and OpenClaw are recognised by the app they run from; Muse from Meta by its App Store identifier.
- Command-line agents such as Codex, opencode and Crush are recognised by the name of their program.
- Agents run by node, bun, deno or python, such as OpenClaw, Hermes Agent, Gemini CLI, Copilot CLI, Amp, Qwen Code and Aider, are recognised by the script the runtime runs.
- The agent’s child processes, such as a shell, git or curl that the agent runs, are recognised by walking up the process’s parents until FireAI reaches the agent.
- AI web browsers and terminal apps are left out on purpose: all of their traffic would count as the agent’s.

> **Note:** Before FireAI 1.0.4, only Claude Code, Claude, Cursor, ChatGPT and Codex were recognised.

## How it works

1. For the first 3 days, FireAI learns the destinations each agent normally contacts. Destinations are grouped by domain: api.anthropic.com becomes anthropic.com. Nothing is flagged during this learning period.
2. After that, a destination outside the baseline is flagged for review in Suggestions, in the AI agents card, and in [Quick Review](https://hisnlabs.com/fireai/en/docs/quick-review-suggestions). Swipe left to block, or right for “It’s fine”.
3. A flag is also raised for an upload spike: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.

Agent profile uses only metadata: host names and byte counts. FireAI never reads the payload of a connection.

## Block new destinations: the Agent profile mode

By default FireAI only flags. If you want an agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and once an agent has finished learning, a connection to a destination outside its baseline is blocked by FireAI’s network filter instead of being flagged.

- The blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the agent’s baseline, and the agent can reach it right away.
- Keep blocked creates a block rule, so the destination stays blocked in every mode.
- An allow rule you wrote for that website, domain or address still wins. DNS and your local network are never blocked.
- While an agent is still learning, nothing is blocked. Upload spikes are flagged, not blocked.

> **Note:** The Agent profile mode arrived in FireAI 1.0.3. Version 1.0.2 flags new destinations but does not block them.

## A plain-words explanation, from facts FireAI measured

Each flag comes with a sentence such as “Claude Code has never contacted this server before, and sent 40 MB.” When the [on-device AI model](https://hisnlabs.com/fireai/en/docs/on-device-ai-model) is on, Gemma 4 E2B, running on your Mac, rewords the facts FireAI measured into that sentence. When the AI is off, FireAI shows a plain, fixed sentence instead. Nothing leaves your Mac either way.

> **Note:** The model is not a safety judge. It never says a destination is safe or dangerous. A small on-device model is good at rewording facts, and red-team testing showed that judging safety is not something to ask of it.

## Your choices

- Block creates a rule for the process that connected to that destination.
- “It’s fine” adds the destination to the agent’s baseline, so it is not flagged again.

## Where to find it

Open Suggestions and look for the AI agents card. Flags from agents also appear in Quick Review, the card stack you swipe through.

## Honest limits

- FireAI cannot see prompts, the contents of MCP tools, file access such as ~/.ssh, or skills. TLS hides the payload, and FireAI is not inside the agent.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- Child processes that exit very quickly may be missed. Child processes are matched by path, not by signature.
- FireAI recognises the 19 agents listed above. Any other agent is still covered by your connection prompts and per-app rules, but has no baseline and raises no agent flags.
- Agents matched by path or script name are labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- During the 3-day learning period nothing is flagged.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, that connection is blocked until you allow it.

## Questions

### Does FireAI read what my agent sends?

No. It uses host names and byte counts only, and it cannot read inside an encrypted connection.

### Does Agent profile stop prompt injection?

No. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag a first-ever destination or an upload spike and let you block it.

### Does the AI decide whether a connection is safe?

No. The model only rewords facts FireAI measured. The decision is yours.

### Does the Agent profile mode block my agent from working?

Only when it reaches somewhere it has never been. The destinations it used during its first 3 days keep working, grouped by domain, so a new server under a domain it already uses is fine. When something is blocked, one click on Allow lets it through from then on.

### Why was nothing flagged in the first days?

FireAI spends the first 3 days learning what each agent normally does, and flags nothing in that time.

### My agent runs through node or python. Is it covered?

Yes, from FireAI 1.0.4, for the agents listed above: FireAI reads which script the runtime runs. For any other agent, write a rule for the program by hand in [per-app rules](https://hisnlabs.com/fireai/en/docs/per-app-rules).

## Sigue leyendo

- [Review your suggestions in seconds with Quick Review](https://hisnlabs.com/fireai/es-mx/docs/quick-review-suggestions.md)
- [Requests by country and upload spikes: spot possible data exfiltration](https://hisnlabs.com/fireai/es-mx/docs/requests-by-country-and-upload-spikes.md)
- [The on-device AI model, opt-in](https://hisnlabs.com/fireai/es-mx/docs/on-device-ai-model.md)
- [Mac firewall rules: by app, website, domain, IP or range](https://hisnlabs.com/fireai/es-mx/docs/per-app-rules.md)
- [Block an app’s internet access on Mac, or just one company or domain](https://hisnlabs.com/fireai/es-mx/docs/block-an-app-or-a-company.md)

---

Prueba todas las funciones gratis durante 17 días, sin tarjeta. Garantía de reembolso de 30 días. [Descargar para Mac](https://hisnlabs.com/fireai/es-mx/download)
