node9
Access control for agents: rules for what Claude Code, Codex, Cursor and MCP servers may do, review of risky actions before they run, and one audit log
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- It embeds into agent hooks and intercepts tool calls
- It reads configuration, session history and secret paths, and can send a summary to the cloud dashboard
Install
Manual install
npx node9-ai scanChecks the machine without installing, nothing is uploaded. A way to assess risk before adopting.
This is third-party code. Review the repository files before installing.
What it does
node9 sits between the agent and every tool it calls and decides whether to pass an action or hold it. Protection of sensitive paths is on by default: a read of files like ~/.ssh, ~/.aws or .env is stopped, the agent is told why, and the decision comes to you. Commands are parsed as a syntax tree, so wrapping does not bypass a rule. It also scans the machine and repositories for weak spots, shields dangerous database operations, wraps MCP servers, and can run the agent inside an isolated container. Every decision lands in an audit log.
Who it is for. For developers and devops who give agents access to files, databases and services and want to keep it under control.
Good fit when
- You need to limit what an agent may do with files, commands and MCP servers
- You want to see and approve risky actions before they run
- You need one audit log of agent actions for review
Not a fit when
- You do not give agents access to sensitive data and systems
- You are not ready for an extra interception layer in the workflow
- You need the team features with a cloud dashboard but want local-only
Example request
Check this machine for risks if the agent is compromised and enable protection of sensitive pathsLimitations
The base command parsing covers the shell and does not close every leak path; the authors state the limits plainly. Isolated runs need Docker and are aimed first at Claude in the early phase. Team features, the fleet dashboard and audit export belong to the paid node9 Pro and its cloud. Local checks and protection run on your machine.
How to disable. Disconnect the machine with node9 logout, remove the wrappers via node9, and uninstall the node9-ai package if installed via brew or npm.
Security check
- It embeds into agent hooks and intercepts tool calls
- It reads configuration, session history and secret paths, and can send a summary to the cloud dashboard
README in short
The README opens with a real supply-chain compromise where installed agents were run with protections off and drained keys. node9 is offered as a gate between the agent and tools: default protection of sensitive paths, tree-based command parsing, database shields, MCP wrapping and isolated container runs. It shows commands to check the machine and repositories, an interactive monitor dashboard and an audit log of decisions. Install via brew or npm, with a GitHub Action and a Python SDK, and a separate paid node9 Pro. Apache-2.0 licensed.
FAQ
How does node9 stop an action?
It runs in the agent's hook: a held action does not run until you answer, even if the agent was started with permission checks skipped.
Do I need an account?
Local checks and protection work without sign-in. An account and the cloud are for the team dashboard, fleet log and part of node9 Pro.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents