Skip to main content

Security harness for AI coding agents (Claude Code, Codex CLI, etc.) — mitmproxy payload inspection + TOML policy control.

Project description

Agent Zoo

Agent Zoo

日本語 | English

CI

A security harness that isolates AI coding agents (Claude Code / Codex CLI / Gemini CLI) inside Docker containers and forces all outbound traffic through mitmproxy. Payload inspection plus TOML policy control physically prevent data exfiltration and dangerous command execution, without relying on the agent's own trustworthiness.

Quickstart

uv tool install agent-zoo                      # install from PyPI
mkdir my-zoo && cd my-zoo
zoo init                                       # secure by default: empty allow list (Inbox approval required)
# or: zoo init --policy claude                 # allow Anthropic/Claude only
# or: zoo init --policy {codex,gemini,all}     # see `zoo init --help`
zoo build                                      # build the claude image (5-10 min)
zoo run                                        # interactive mode (first run prompts /login)

zoo init now defaults to --policy minimal (empty domains.allow.list) so that the first outbound request is rejected and surfaced to the Inbox for per-request approval. Pick another profile (claude / codex / gemini / all) to preseed the allow-list, or edit .zoo/policy.toml directly. Live audit is available through the dashboard (zoo up --dashboard-only, http://localhost:8080).

Features

  • Docker isolation: agent containers run on an internal: true network, cut off from the host OS and other containers; the only egress is the mitmproxy sidecar
  • Domain allow-list: outbound destinations are explicitly enumerated in policy.toml, with hot reload support
  • Payload inspection: request and response bodies are inspected (Base64 decoding, secret patterns, URL-embedded secrets)
  • tool_use detection: SSE streams are parsed and dangerous tool invocations are blocked at the request hook
  • Dashboard auditing: requests / tool_uses / blocks shown live, with whitelist nurturing and Inbox (agent-to-human approval requests)
  • Agent-agnostic: same harness covers Claude Code / Codex CLI / Gemini CLI; the unified image enables cross-agent invocation

Documentation

Doc Contents
Install & Setup Detailed uv tool installzoo initzoo run flow, full command reference, unified profile
Inbox guide (JP) Approving agent-issued allow-list requests through the dashboard
Security model Defense in depth, known limitations, operating principles
Policy reference Every setting in policy.toml

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_zoo-0.1.3.tar.gz (1.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agent_zoo-0.1.3-py3-none-any.whl (97.7 kB view details)

Uploaded Python 3

File details

Details for the file agent_zoo-0.1.3.tar.gz.

File metadata

  • Download URL: agent_zoo-0.1.3.tar.gz
  • Upload date:
  • Size: 1.4 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent_zoo-0.1.3.tar.gz
Algorithm Hash digest
SHA256 d56ae9bd90159f878382fa29048e8ce7a8e9796856b6856bc033ad47e39186f4
MD5 d27cf31a2f6278a61749ff0fcc06ecab
BLAKE2b-256 bf5e680b187868e061f8e861884b90eac6aa0fbe9a9d467f589a39b2b8d02a19

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_zoo-0.1.3.tar.gz:

Publisher: release.yml on ymdarake/agent-zoo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent_zoo-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: agent_zoo-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 97.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent_zoo-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 fad36eecbb0004dd12b5ccd600f7044b5b740e0fca5ee77f2ae5f44b55f792cc
MD5 be8142cbb8700d4b9a5bf93d48df7f99
BLAKE2b-256 ee972d3026c106c28fe7ee437b25cb7cd69b3517dd34233b792367384c77744a

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_zoo-0.1.3-py3-none-any.whl:

Publisher: release.yml on ymdarake/agent-zoo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page