Flight recorder for coding agents

See what your AI agent did. Stop it before it leaks.

Every prompt, tool call and result goes into a hash-chained, Ed25519-signed ledger written by a separate process. A small policy engine stops the lethal trifecta (private data, untrusted content and an outbound call) before the call runs.

Claude Code first. Codex CLI, Cursor and Gemini CLI have experimental adapters.

  • no account
  • no cloud
  • no telemetry
  • zero dependencies
  • Node 18+
  • Apache-2.0
Demo

Watch it stop an attack

A planted instruction tries to send a secret out. The call is denied before it runs. Recorded from a real blackbox demo run.
Editing one record breaks the chain, and blackbox verify names it. Same run, --tamper.
Works with

Claude Code, Codex CLI, Cursor and Gemini CLI

One ledger and one policy for every coding agent on your machine. Claude Code is covered end to end, including native OpenTelemetry. Codex CLI, Cursor and Gemini CLI are supported through hooks as experimental adapters: they are built from public documentation and tested with simulated agent payloads, not yet validated on the real agents. Each adapter lists what it cannot gate yet in supported agents.

It also audits the rest of the attack surface: blackbox mcp checks MCP servers and their configuration for prompt-injection and supply-chain risks, and blackbox skills audits installed skills. The log is an open format (spec) you can verify with a standalone script and export to any OpenTelemetry backend (GenAI export).

Audit

What did your agent do last month?

Replay your existing Claude Code history through the policy without installing anything. Transcripts run in parallel on worker threads; --jobs N sets the count.

npx agent-blackbox scan
npx agent-blackbox scan --html      # local report
npx agent-blackbox skills           # audit installed skills
npx agent-blackbox mcp              # MCP servers and config audit
Install

Record and gate every session

# inside Claude Code
/plugin marketplace add developerfred/agent-blackbox
/plugin install agent-blackbox@agent-blackbox

# or the CLI
brew install developerfred/tap/agent-blackbox
blackbox install

blackbox timeline --last    # what the agent did
blackbox verify             # prove nothing was changed
Features

What you get

Tamper-evident ledger
Hash chain plus signatures. blackbox anchor exports a head you can publish elsewhere.
Policy before execution
Decisions in the PreToolUse hook, in milliseconds. Denials stay quiet toward the agent.
Secrets never stored
Replaced by HMAC fingerprints before anything is written.
Real erasure
Per-session keys: purge or retainDays makes old sessions unreadable, backups included.
Web3 aware
Seed phrases, keystores and transaction signing count as sensitive.
Open format and OTel export
The ledger format is specified with test vectors. blackbox export writes OpenTelemetry GenAI traces, metadata only.
Measured
blackbox eval: 62 of 62 known attacks caught, 0 of 20 false alarms.
Policy

Rules

RuleTriggerDecision
secret-egressA secret read earlier appears in an outbound calldeny
sensitive-egressOne command reads a sensitive file and sends data outdeny
lethal-trifectaPrivate data and untrusted content, then a call to an unnamed host or opaque codeask
web3-transactionSigning or broadcasting a transactionask
post-denialSomething was denied earlier and a call goes outask
self-protectionThe agent touches ~/.blackboxdeny
hook-tamperThe agent edits Claude Code settings or plugin filesask alert

The recorder never returns "allow". It only adds friction and never skips Claude Code's own permission checks.

Privacy

Nothing leaves your machine

  • The recorder listens on 127.0.0.1 only, and this project makes no outbound connection.
  • Payloads and per-record summaries are encrypted per session (AES-256-GCM). Prompt and response text through telemetry is opt-in with install --prompts.
  • install prints the key and fail-open posture. --fail-closed denies when the recorder is down.
  • Details: docs/PRIVACY.md.
Limits

What it does not do

  • Until you run blackbox harden (recorder as a dedicated OS user), a process running as you can read the master key.
  • The firewall catches known patterns, not every attack. Treat it as friction and evidence, not a guarantee.
  • The chain proves nothing recorded was altered. It cannot prove everything was recorded.

Full list in the README. Plans in the ROADMAP.

Useful? Give it a star.

A star helps other developers find it. A fork lets you add your own rules and attacks to the eval corpus.