Skip to main content

Security harness for AI coding agents (Claude Code, Codex CLI, etc.) — mitmproxy payload inspection + TOML policy control.

Project description

Agent Zoo

Agent Zoo

日本語 | English

CI

A security harness that isolates AI coding agents (Claude Code / Codex CLI / Gemini CLI) inside Docker containers and forces all outbound traffic through mitmproxy. Payload inspection plus TOML policy control physically prevent data exfiltration and dangerous command execution, without relying on the agent's own trustworthiness.

Quickstart

uv tool install agent-zoo                      # install from PyPI
mkdir my-zoo && cd my-zoo
zoo init                                       # secure by default: empty allow list (Inbox approval required)
# or: zoo init --policy claude                 # allow Anthropic/Claude only
# or: zoo init --policy {codex,gemini,all}     # see `zoo init --help`
zoo build                                      # build the claude image (5-10 min)
zoo run                                        # interactive mode (first run prompts /login)

zoo init now defaults to --policy minimal (empty domains.allow.list) so that the first outbound request is rejected and surfaced to the Inbox for per-request approval. Pick another profile (claude / codex / gemini / all) to preseed the allow-list, or edit .zoo/policy.toml directly. Live audit is available through the dashboard (zoo up --dashboard-only, http://localhost:8080).

Features

  • Docker isolation: agent containers run on an internal: true network, cut off from the host OS and other containers; the only egress is the mitmproxy sidecar
  • Domain allow-list: outbound destinations are explicitly enumerated in policy.toml, with hot reload support
  • Payload inspection: request and response bodies are inspected (Base64 decoding, secret patterns, URL-embedded secrets)
  • tool_use detection: SSE streams are parsed and dangerous tool invocations are blocked at the request hook
  • Dashboard auditing: requests / tool_uses / blocks shown live, with whitelist nurturing and Inbox (agent-to-human approval requests)
  • Agent-agnostic: same harness covers Claude Code / Codex CLI / Gemini CLI; the unified image enables cross-agent invocation

Documentation

Doc Contents
Install & Setup Detailed uv tool installzoo initzoo run flow, full command reference, unified profile
Inbox guide (JP) Approving agent-issued allow-list requests through the dashboard
Security model Defense in depth, known limitations, operating principles
Policy reference Every setting in policy.toml

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_zoo-0.1.5.tar.gz (1.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agent_zoo-0.1.5-py3-none-any.whl (98.7 kB view details)

Uploaded Python 3

File details

Details for the file agent_zoo-0.1.5.tar.gz.

File metadata

  • Download URL: agent_zoo-0.1.5.tar.gz
  • Upload date:
  • Size: 1.4 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent_zoo-0.1.5.tar.gz
Algorithm Hash digest
SHA256 51eb4f84f77a4192810d959c04590cf1c9747eb6a1c1ba3ee2e7e702f7c595fa
MD5 de14befcf1ab3be99b79252a745120e9
BLAKE2b-256 a3c98b22bf23c1e220d7403172e1eeee22fe399940b97c1bbf6684183aa8e615

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_zoo-0.1.5.tar.gz:

Publisher: release.yml on ymdarake/agent-zoo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent_zoo-0.1.5-py3-none-any.whl.

File metadata

  • Download URL: agent_zoo-0.1.5-py3-none-any.whl
  • Upload date:
  • Size: 98.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent_zoo-0.1.5-py3-none-any.whl
Algorithm Hash digest
SHA256 2c9e8276c0f984769c4dd3424c0006b28810d2ab5ef557129b329879cc15be5e
MD5 abfa6062a32be9a24d544f54749b4227
BLAKE2b-256 139c790d00180ddb7ebbd1a5eee991dff8c0a2db76e58d4efaaa16334a563c75

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_zoo-0.1.5-py3-none-any.whl:

Publisher: release.yml on ymdarake/agent-zoo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page