Recurso · Disponível desde o FireAI 1.0.2
Agent profile: an AI firewall for your AI agents
Know when an AI agent on your Mac reaches somewhere new or sends an unusual amount of data, and block it in one swipe.
Onde no FireAI: Suggestions › AI agents, and Quick Review
Por enquanto esta página está em inglês.
AI agents such as Claude Code and Cursor run commands, read files and open network connections on your Mac. Agent profile watches the connections. It learns where each agent normally connects, and when one reaches a destination it has never contacted, or sends far more data than usual, FireAI flags it for you to review.
What FireAI recognises
- Claude Code, the Claude desktop app and Cursor are recognised by their code signature.
- ChatGPT and Codex are recognised by their path on disk.
- The agent’s child processes, such as a shell, git or curl that the agent runs, are recognised by walking up the process’s parents until FireAI reaches the agent.
How it works
- For the first 3 days, FireAI learns the destinations each agent normally contacts. Destinations are grouped by domain: api.anthropic.com becomes anthropic.com. Nothing is flagged during this learning period.
- After that, a destination outside the baseline is flagged for review in Suggestions, in the AI agents card, and in Quick Review. Swipe left to block, or right for “It’s fine”.
- A flag is also raised for an upload spike: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
Agent profile uses only metadata: host names and byte counts. FireAI never reads the payload of a connection.
A plain-words explanation, from facts FireAI measured
Each flag comes with a sentence such as “Claude Code has never contacted this server before, and sent 40 MB.” When the on-device AI model is on, Gemma 4 E2B, running on your Mac, rewords the facts FireAI measured into that sentence. When the AI is off, FireAI shows a plain, fixed sentence instead. Nothing leaves your Mac either way.
Your choices
- Block creates a rule for the process that connected to that destination.
- “It’s fine” adds the destination to the agent’s baseline, so it is not flagged again.
Where to find it
Open Suggestions and look for the AI agents card. Flags from agents also appear in Quick Review, the card stack you swipe through.
Honest limits
- FireAI cannot see prompts, the contents of MCP tools, file access such as ~/.ssh, or skills. TLS hides the payload, and FireAI is not inside the agent.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- Child processes that exit very quickly may be missed. Child processes are matched by path, not by signature.
- Agents run by an interpreter, such as OpenClaw, Hermes Agent, or Gemini CLI running as node or python, are not recognised automatically yet. Agent-aware identity is planned.
- During the 3-day learning period nothing is flagged.
Questions
Does FireAI read what my agent sends?
No. It uses host names and byte counts only, and it cannot read inside an encrypted connection.
Does Agent profile stop prompt injection?
No. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag a first-ever destination or an upload spike and let you block it.
Does the AI decide whether a connection is safe?
No. The model only rewords facts FireAI measured. The decision is yours.
Why was nothing flagged in the first days?
FireAI spends the first 3 days learning what each agent normally does, and flags nothing in that time.
My agent runs through node or python. Is it covered?
Not yet. Agents run by an interpreter are not recognised automatically, and agent-aware identity is planned. You can still write a rule for any app by hand in per-app rules.
Leia em seguida
Experimente no seu Mac
Teste todos os recursos grátis por 17 dias, sem cartão.
Garantia de reembolso de 30 dias.