Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Aegis-releases — Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and tamper-evident audit logs. | Kitploit
Ferramentas/GitHubGitHub/adarsh14734/aegis-releases
Authentication & AuthorizationDefensive ToolsConfiguration AuditingDevSecOpsPrivacySecret DetectionAI SecurityLog Analysis
GitHubadarsh14734/aegis-releases

Aegis-releases

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and tamper-evident audit logs.

Ver Repositório
22há 16 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Aegis

Claude Code's sandbox lets an agent read your SSH keys and AWS credentials by default. Aegis doesn't.

Two layers, both verified on real hardware.

Kernel sandbox — the agent's own shell cannot reach a denied path:

$ ! cat ~/.ssh/id_rsa
cat: /Users/you/.ssh/id_rsa: Operation not permitted

$ ! cat ~/.aws/credentials
cat: /Users/you/.aws/credentials: Operation not permitted

$ tail ~/Library/Application\ Support/Aegis/denials.log
kernel denied file-read-data /Users/you/.ssh/id_rsa to cat(pid 41560)
kernel denied file-read-data /Users/you/.aws/credentials to cat(pid 42180)

MCP proxy — same tool, same file, with and without Aegis in front:

direct to the server:   allowed: TOKEN=proof-env-secret
through aegis proxy:    AEGIS DENIED: read_text_file
                        Reason: path matches deny rule '.env'
                        Rule: deny_paths

What's new in 0.9.0

Each line is backed by a test that ran against this release; where something is not yet tested, it says so.

  • aegis workspace add / remove / list — change which folders the agent may work in without editing policy.json. Adding always needs --confirm-grant; removing never does. add refuses your home directory, anything containing Aegis's own files, a path with .., a folder that does not exist, a symlink sitting inside a workspace, and a workspace inside or around another one. Every change is recorded in the audit log and regenerates the sandbox profile. A session that is already running keeps the workspaces it started with — including one you just removed — measured against a live sandboxed session.
  • Two ways to widen access, closed. In 0.8.1, a symlink planted inside a workspace could be turned into a new workspace with aegis policy set-folder, granting wherever the link pointed; and a workspace created inside another could later be swapped for a symlink and followed at the next launch. Both were reproduced on 0.8.1 and are now permanent regression tests proven to fail there.
  • Relative paths in policy.json are refused. A relative path resolved against the folder Aegis was started from, so aegis run and the launch wrapper could enforce different sandboxes from one policy (measured: different profile digests). Paths must be absolute or start with ~/.
  • Every policy change regenerates the sandbox profile, so aegis doctor no longer reports a mismatch between an edit and the next launch.
  • A way out when Claude Code cannot log in inside the sandbox. aegis run and aegis doctor print the real Claude Code path — read from the wrapper Aegis wrote — and /login, to run outside the sandbox. Not fixed: a revoked or expired token still reads as logged in until the first message fails (Claude Code's status reports no expiry), and login still cannot happen inside the sandbox; that needs a credential broker that does not exist yet.
  • aegis init protects a new user who has not logged in yet. Found by following the walkthrough in a clean environment: in 0.8.1, a Claude Code that had never logged in was left unwrapped by default, behind a question the docs never mentioned, so claude stayed outside the sandbox. Now, once you say yes to sandboxing, it is wrapped, with a loud warning to log in once outside the sandbox (the real Claude Code path, then /login); aegis init's closing steps put that first, and aegis doctor fails until you do. The same run also fixed init's opening and closing text, gave aegis init, aegis run and aegis doctor one login instruction, and stopped a no-op change printing nothing to change (nothing to change).
  • Folder permissions say what they really reach. Ask applies to MCP tool calls only; Claude Code's own file tools and shell are decided by the sandbox, which treats reading and writing separately — measured, in the table in docs/getting-started.md. Deny now blocks reading as well as writing, including for a folder in no workspace, and refuses a folder that contains Aegis's own files.
  • Test harness: the guard that keeps test runs off your real installation no longer fails at random while a sandboxed session is running. It attributes that session's checkpoint rows and still reports anything else. (Test code, not part of the package.)

Not yet tested in 0.9.0: Linux; clients other than Claude Code; the /login flow end to end; a rebuilt desktop app.

What it does

Sits between your AI coding agent and your machine:

  • Deny by default on every tool call
  • Kernel sandbox on subprocesses — cat .env can't bypass it
  • Tamper-evident audit log — hash-chained, integrity checked by aegis doctor, and checkpointed from outside the sandbox under a key the sandbox can't read or write
  • Outbound requests checked before they're made
  • Secrets never reach the MCP server

Install (macOS Apple Silicon)

New here? docs/getting-started.md is the step-by-step path, including the two questions that default to No.

Followed earlier instructions that said aegis-mcp? That package is not Aegis — it is an unrelated project installed under the same import name, aegis. Remove it first:

python3 -m pip uninstall aegis-mcp

If aegis-sandbox is already installed, that uninstall also deletes two of its files, so reinstall it afterwards: python3 -m pip install --force-reinstall aegis-sandbox.

python3 -m pip install aegis-sandbox
aegis init      # detects Claude Code / Cursor, asks a few questions
aegis doctor    # proves the boundary is actually in place

Upgrading? Re-run aegis init. Your policy.json is yours and is never rewritten behind your back, so a new sandbox domain does not appear on its own — and without the OAuth token endpoint a sandboxed client stops working when its token expires. aegis init offers the new hosts; accepting is one keystroke.

What it does NOT do

  • Does not stop prompt injection
  • Kernel escape defeats the sandbox
  • The audit database is still writable from inside the sandbox. Checkpoints make tampering with already-checkpointed history detectable — not impossible, and the newest rows aren't covered yet
  • A sandboxed client can't log in at all. Log in to Claude Code before aegis init; aegis doctor fails if a wrapped client isn't logged in
  • A sandboxed client can't renew an expired login token — run it once outside the sandbox to refresh
  • The sandbox can still read your OAuth token from the Keychain
  • Tool results larger than 16 MiB are refused
  • No external security review, no certifications
  • Not audited by anyone but me — the full source ships as the sdist on PyPI; read it, that's why it's MIT

Full threat model: THREAT-MODEL.md

License

MIT

Baixar ferramenta