node9-proxy
View on GitHubThe Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.
Node9 is a security proxy that sits between AI coding agents and their tools: it scans past sessions for leaks, blocks risky commands before execution, gates MCP servers, and produces audit reports. Works with Claude Code, Codex, Cursor and any MCP server.
Use Cases
Block risky agent commands like rm -rf, DROP TABLE, git push --force before executionAudit and review every action an autonomous AI agent took over a time windowScan past AI sessions for credential leaks and agent loopsDetect secrets on disk that an AI agent could reachGate GitHub Actions agent workflows against injection and hijackingEnforce human approval (HITL) for high-risk tool callsPin and gate MCP servers/tools to prevent supply-chain attacksDLP for AWS/GitHub/Stripe keys exfiltrated by agentsRun agents in a sandbox with kernel egress controls and scoped mountsTrack cost per agent and top tools usedProtect against prompt injection and SSRF in agent toolchainsCI security scanning of CLAUDE.md/AGENTS.md/.cursorrules instructions
Built With
- Language
- TypeScript
- Frameworks
- MCP · Claude Code · Codex CLI · Gemini CLI · GitHub Copilot CLI · Cursor · Windsurf · VS Code · Claude Desktop · Opencode · Pi · Hermes Agent · GitHub Actions · Node.js
Tags
agent-security · mcp-security · prompt-injection · dlp · audit-logs · llm-security · guardrails · human-in-the-loop · devsecops · claude-code · github-actions · ssrf · governance · sandboxing · cli · security-proxy