Watch it stop an attack
blackbox demo run.blackbox verify names it. Same run, --tamper.Flight recorder for coding agents
Every prompt, tool call and result goes into a hash-chained, Ed25519-signed ledger written by a separate process. A small policy engine stops the lethal trifecta (private data, untrusted content and an outbound call) before the call runs.
Claude Code first. Codex CLI, Cursor and Gemini CLI have experimental adapters.
blackbox demo run.blackbox verify names it. Same run, --tamper.One ledger and one policy for every coding agent on your machine. Claude Code is covered end to end, including native OpenTelemetry. Codex CLI, Cursor and Gemini CLI are supported through hooks as experimental adapters: they are built from public documentation and tested with simulated agent payloads, not yet validated on the real agents. Each adapter lists what it cannot gate yet in supported agents.
It also audits the rest of the attack surface: blackbox mcp checks MCP servers and their configuration for prompt-injection and supply-chain risks, and blackbox skills audits installed skills. The log is an open format (spec) you can verify with a standalone script and export to any OpenTelemetry backend (GenAI export).
Replay your existing Claude Code history through the policy without installing anything. Transcripts run in parallel on worker threads; --jobs N sets the count.
npx agent-blackbox scan
npx agent-blackbox scan --html # local report
npx agent-blackbox skills # audit installed skills
npx agent-blackbox mcp # MCP servers and config audit
# inside Claude Code
/plugin marketplace add developerfred/agent-blackbox
/plugin install agent-blackbox@agent-blackbox
# or the CLI
brew install developerfred/tap/agent-blackbox
blackbox install
blackbox timeline --last # what the agent did
blackbox verify # prove nothing was changed
blackbox anchor exports a head you can publish elsewhere.PreToolUse hook, in milliseconds. Denials stay quiet toward the agent.purge or retainDays makes old sessions unreadable, backups included.blackbox export writes OpenTelemetry GenAI traces, metadata only.blackbox eval: 62 of 62 known attacks caught, 0 of 20 false alarms.| Rule | Trigger | Decision |
|---|---|---|
secret-egress | A secret read earlier appears in an outbound call | deny |
sensitive-egress | One command reads a sensitive file and sends data out | deny |
lethal-trifecta | Private data and untrusted content, then a call to an unnamed host or opaque code | ask |
web3-transaction | Signing or broadcasting a transaction | ask |
post-denial | Something was denied earlier and a call goes out | ask |
self-protection | The agent touches ~/.blackbox | deny |
hook-tamper | The agent edits Claude Code settings or plugin files | ask alert |
The recorder never returns "allow". It only adds friction and never skips Claude Code's own permission checks.
127.0.0.1 only, and this project makes no outbound connection.install --prompts.install prints the key and fail-open posture. --fail-closed denies when the recorder is down.blackbox harden (recorder as a dedicated OS user), a process running as you can read the master key.A star helps other developers find it. A fork lets you add your own rules and attacks to the eval corpus.