Skip to content

agent-gate v0.2.0

Choose a tag to compare

@github-actions github-actions released this 07 May 06:38
· 51 commits to main since this release
6cea5ab

agent-gate v0.2.0

Single-user audit gate for AI agent HTTPS traffic. See the
README for
what this is and how to get started.

Install

Download the archive for your platform below, extract, and put
agent-gate on your PATH. Then:

agent-gate init

On macOS, you may need to clear the quarantine attribute the first
time:

xattr -d com.apple.quarantine ./agent-gate

Or install from source:

go install agent-gate/cmd/agent-gate@v0.2.0

Changelog

  • 793b006 Address init onboarding feedback
  • 03c85bf Include denied host in allowlist errors
  • 5698e45 Initial commit
  • f694951 Merge main into explore-page (resolve Plan 7 conflicts)
  • f49fc46 Merge remote-tracking branch 'origin/main' into feat/plan5-codex-fixture
  • dae3b55 Merge remote-tracking branch 'origin/main' into fix/dashboard-badge-polish
  • a5a764f Polish init wizard onboarding
  • ff50816 Polish init wizard: Continue button + custom-host copy fixes
  • 2469392 build: gitignore docs/superpowers (local working notes)
  • 00614bd build: inject version/commit/date ldflags from git in Makefile
  • 672e43d build: populate version/commit/date from runtime/debug.ReadBuildInfo
  • f86fefe build: trust ldflags-set commit and skip runtime/debug dirty check
  • 56e363f ca: expose leaf tls config builder
  • 3953d68 ci: bump Go to 1.25, add gofmt gate, fail-fast=false on matrix
  • 714f10e ci: run go vet and go test on linux, macos, windows
  • e2ae93d dashboard: collapse Explore PII chips into the event row
  • b7fe7c6 dashboard: friendlier flag labels + correct severity color in session view
  • 7b93a46 docs(claude): project memory file for AI assistants
  • f1bf192 docs(claude): require worktree for all execution
  • b3d3337 docs(plan7): post-ship doc-rot sweep
  • f70729b docs(plan7): reorder TODOS, add Plan 6+7 to CLAUDE.md, install via release binaries
  • 6a1b417 docs(readme): airtight launcher setup, flags, threat-model boundaries
  • c08edcc docs(readme): build-from-source ldflags incantation; ignore skill state dirs
  • 247e495 docs(readme): document Plan 1 features and getting started
  • 59c13b7 docs(readme): document Plan 3 surface — CLI, host buttons, upstream-CA, stop
  • ad19311 docs(readme): document policy + dashboard
  • aea2188 docs(readme): rewrite First-time setup + add Upgrading section for v0.6.0
  • 5843470 docs(readme): use neutral placeholder hostname in upstream-ca example
  • 624ee7c docs(readme): visual uplift with hero banner, system diagram, and live screenshots
  • 0e1d68e docs(runtime): document SetNow constraints; modernize test context
  • 082fa24 docs(secrets): correct comment on FindAll dedup behavior
  • cefbae1 feat(agentdetect): detect installed agents via PATH + env vars
  • cde4c23 feat(allowlist): add Remove(host) for dashboard untrust
  • 504cb55 feat(allowlist): file-backed host allowlist with atomic add
  • b7029f6 feat(ca): add Installer interface + Smallstep + Mock impls
  • 9951cbf feat(ca): root CA generation, persistence, leaf signing
  • bbec8e5 feat(cert): truststore-backed install/uninstall, drop manual instructions
  • 678702c feat(cli): add agent-gate run subcommand (permissive mode functional)
  • 3df18df feat(cli): agent-gate dashboard subcommand
  • eead390 feat(cli): agent-gate init bootstraps config + CA + windows WFP install
  • 72196c9 feat(cli): agent-gate reindex command
  • 4fa7b3e feat(cli): cert install (macOS) + cert path
  • dcdeab8 feat(cli): cobra skeleton with version, proxy, cert, tail subcommands
  • 6d6778f feat(cli): dashboard auto-reindexes PII on first launch
  • e61a462 feat(cli): dispatch __netns-helper hidden subcommand from main
  • a3995ed feat(cli): polling tail subcommand
  • 82ba6fd feat(cli): run policy on every captured flow before persisting
  • 05157d3 feat(cli): wire agent-gate proxy to proxy+parser+store pipeline
  • 313950b feat(cmd): add 'agent-gate doctor' subcommand
  • 8de1231 feat(cmd): add help topics + group commands in --help
  • 3f4a7ad feat(config): TOML config loader with defaults and tilde expansion
  • bf393d7 feat(dashboard): /explore empty state with Reset filters
  • 9f677fe feat(dashboard): /explore free-text body+url+host search
  • f9a587e feat(dashboard): /explore page with all-events table
  • a256372 feat(dashboard): /explore pagination
  • 81e8f98 feat(dashboard): POST /api/dismiss + /api/trust actions
  • 3c85bdb feat(dashboard): Passthrough button + denylist > passthrough priority fix
  • 6cd2c6c feat(dashboard): SSE /api/live emits new event ids on a poll
  • f22b8f8 feat(dashboard): add POST /api/untrust to remove hosts from allowlist
  • 8906967 feat(dashboard): add Untrust button on trusted-host event detail
  • 39a9420 feat(dashboard): clear-all-events button (wipes data, keeps config)
  • 7e8d47f feat(dashboard): clickable risk feed + mobile-stacked sessions table
  • f57c391 feat(dashboard): collapsible SSE event blocks
  • bd8c7db feat(dashboard): event detail with redacted/raw toggle (raw is audit-logged)
  • 2b46224 feat(dashboard): filter chips for host + time range on sessions list
  • 9143a14 feat(dashboard): flag PII in payload bodies
  • 88d4e16 feat(dashboard): host filter chips on /explore
  • 97da8b2 feat(dashboard): kind filter chips on /explore
  • 525c2fb feat(dashboard): payload inspection polish
  • c27f284 feat(dashboard): per-row PII chip strip on /explore
  • 2872a86 feat(dashboard): port to Investigator's Desk visual system
  • 3faf658 feat(dashboard): pretty-print JSON + SSE bodies in event detail
  • 034c6bd feat(dashboard): redesign SOC overview
  • aebdd22 feat(dashboard): redesign event inspection
  • 5efa611 feat(dashboard): redesign session timeline
  • d0cc950 feat(dashboard): restore Trust host + Dismiss flag buttons on event detail
  • b7d702e feat(dashboard): server skeleton with embedded assets + base layout
  • 58904fe feat(dashboard): session detail view listing events oldest-first
  • 0c27844 feat(dashboard): sessions list view grouping events by session id
  • 87b4fca feat(dashboard): syntax-color JSON + SSE bodies in event detail
  • a949a97 feat(dashboard): time preset filter on /explore
  • 60b8345 feat(dashboard): top-bar Operations/Explore nav
  • 69e06f2 feat(dashboard): two-tier PII coloring (sensitive vs identifying)
  • b37bb83 feat(denylist): add Remove(host) mirroring allowlist
  • 40dfbb6 feat(denylist): hard-block button + denylist file (always wins, no enforce needed)
  • 7d96e60 feat(dismissals): JSON-backed audit log with three scopes
  • 9d6292e feat(doctor): add Check primitives + 5 checks (CA, ports, data-dir, lockfile, host-list)
  • bc7578b feat(doctor): add Repair (safe/aggressive) and human/JSON output
  • 14d6381 feat(doctor): add config-valid, agents-detected, ca-trusted checks
  • 849795b feat(idgen): goroutine-safe monotonic ULID generator
  • 3fa1534 feat(init): rewrite as initwizard-driven onboarding command
  • f33729e feat(init): write inline-commented config.toml on bootstrap
  • f7f289b feat(initwizard): add huh-backed HuhPrompter (interactive)
  • 4fe88a7 feat(initwizard): orchestrator with Prompter interface
  • 148565f feat(launcher): --upstream-ca / --upstream-insecure-skip-verify on run
  • a32600f feat(launcher): CA-in-trust-store check (warn-and-continue per platform)
  • 6b25676 feat(launcher): __netns-helper subcommand body (lo + bind + FD-pass + exec)
  • e0a7716 feat(launcher): add package skeleton (Options, Mode, Run, build-tag stubs)
  • edd04c6 feat(launcher): add testhelper binary for sandbox isolation tests
  • d7eeb32 feat(launcher): linux airtight via netns helper + SCM_RIGHTS FD-passing
  • b698491 feat(launcher): macOS sandbox-exec airtight spawn; carry resolved addrs back to Options
  • f4406d3 feat(launcher): stale lockfile auto-reclaim + agent-gate stop subcommand
  • 87f5030 feat(launcher): supervisor with permissive mode, lockfile, CA trust stub
  • 8874169 feat(launcher): windows WFP wrapper (uses tailscale/wf for struct layout)
  • 2f0d7d1 feat(launcher): windows airtight scaffold + agent-gate uninstall (full impl deferred to Plan 4)
  • a58a58e feat(parser): Anthropic Messages decoder + generic fallback (non-streaming)
  • 5de7324 feat(passthrough): add Remove(host) mirroring allowlist/denylist
  • c8e9ccf feat(pii): JSON token walker for key/value detection
  • fcb8006 feat(pii): SSE kind splits on data: lines and recurses as JSON
  • 304b1d6 feat(pii): SSN detection via JSON key (canonical or 9-digit)
  • 228a43e feat(pii): add Luhn mod-10 helper
  • e509835 feat(pii): add sensitive-keys map for JSON key-context detection
  • 511636e feat(pii): credit_card detection via JSON key still requires Luhn
  • e0174c3 feat(pii): date-of-birth detection requires date-shaped value
  • 2931b54 feat(pii): detect SSN in free text (dashed canonical form)
  • e302c83 feat(pii): detect credit cards with Luhn validation
  • 039b43b feat(pii): detect phone numbers in free text (separator-required)
  • ad0cee8 feat(pii): name + address detection via JSON key context
  • c566777 feat(pii): phone detection via JSON key (≥7 digits)
  • 83069d4 feat(pii): tier-aware overlap dedup (sensitive wins same-position ties)
  • 6b90c0c feat(policy): host_not_allowlisted + permissive_capture rules
  • dadc2e4 feat(policy): oversized_request/response, unknown_mcp_endpoint, parse_error rules
  • a50d3ec feat(policy): rule interface, engine with dismissals + panic recovery
  • fae66ee feat(policy): secret_in_request + env_in_tool_result rules
  • f9b88be feat(proxy): --upstream-insecure-skip-verify flag for self-hosted endpoints
  • c70807f feat(proxy): TLS-MITM proxy emitting RawFlow per request
  • 9e9715f feat(proxy): allowlist enforcement — return 403 for non-allowlisted hosts
  • 007863e feat(proxy): passthrough.txt — skip TLS MITM for cert-pinned hosts
  • cc45bfd feat(redactor): mask secrets in body text + sensitive HTTP headers
  • 391aee0 feat(release): GitHub Releases automation via goreleaser
  • 24846f2 feat(runtime): add XDG-aware path resolution helpers
  • 8d36210 feat(secrets): canonical regex set for known credential patterns
  • 2d66147 feat(store): MaybeReindexPII auto-fires when behind
  • e66d6e2 feat(store): ReindexPII rebuilds event_pii from JSONL
  • 0bb7410 feat(store): SQLite event index with filterable queries
  • fd872f0 feat(store): add event_pii table to schema
  • b8dcada feat(store): daily-rotated JSONL writer with offset tracking
  • 3097669 feat(store): index PII counts on every Append
  • f2ca67a feat(store): per-event PII count writer
  • 593bb30 feat(store): unified Append + Body API over JSONL+SQLite
  • a773cfb feat(types): define RawFlow, ParsedEvent, StoredEvent, Flag
  • e2ddd64 feat: ldflag-injectable version, commit, and build date
  • 1627b4e fix(agentdetect): reject non-ASCII hostnames outright (IDN homograph defense)
  • 595c0d2 fix(allowlist): check trailing-newline write err; document single-process scope
  • df37a15 fix(ca): reject symlinks when validating key.pem permissions
  • ef06a77 fix(ci): Linux apparmor-aware feasibility probe + Windows-safe TOML test paths
  • 6e21ce8 fix(cli): broaden help framing, populate Help topics group, drop doubled --install-cert default
  • 2f98708 fix(cli): close listener on signal for graceful shutdown
  • 5406970 fix(cli): release signal handler on tail exit
  • 1ad4318 fix(dashboard): SSE message triggers a tbody re-fetch (was overwriting rows with bare event id)
  • 8c6433a fix(dashboard): group empty-session events by host; strip port from stored host
  • 3ecbd17 fix(dashboard): paginate session detail, custom 404, omit empty form params, suppress htmx SSE-source noise
  • aaa4cbe fix(dashboard): wrap Explore table for narrow screens
  • 27d5035 fix(doctor): no false-positive port fail when own agent-gate is running; skip Firefox profiles without cert9.db
  • 20c29e8 fix(init): always offer custom-host prompt during interactive init
  • 75fd461 fix(launcher): TestMain dispatches __netns-helper so probe + spawn work in tests
  • ad6337e fix(launcher): address airtight review findings
  • e9c0176 fix(launcher): bound post-kill wait so a stuck child can't hang teardown
  • 1e07e09 fix(launcher): give child process the controlling TTY (no more SIGTTIN on read)
  • a0d3f44 fix(launcher): plug pipeline-goroutine leak on supervisor error paths
  • 8f2a17d fix(parser): read message_delta usage from top level (real Anthropic format)
  • 2f9723e fix(pii): broad name/address key match no longer hides nested sensitive
  • 20d6b1b fix(pii): regex-sweep the unparsed remainder of malformed JSON
  • aec3d64 fix(pii): reject Luhn inputs shorter than 13 digits
  • 8ed96ec fix(plan6): pre-landing review fixes
  • f148db3 fix(policy): pass parsed hostname (not full URL) to dismissal lookup
  • b99475f fix(proxy): add truncation flag, block-on-full Out, log cert failures
  • 99aeff4 fix(proxy): clone response headers to avoid race with goproxy header mutation
  • c797869 fix(proxy): stop closing flowCh on shutdown to avoid send-on-closed panic
  • 9f44b45 fix(qa): post-merge polish — LIKE-escape, missing 404, flag-filter form roundtrip
  • e65dffe fix(runtime): error on missing APPDATA/LOCALAPPDATA on Windows
  • 2f3ccd4 fix(runtime): stop auto-seeding api.anthropic.com on load
  • a0397f6 fix(store): Clear must also wipe event_pii
  • c577a95 fix(store): defensive short-write check; document fsync caveat
  • ce2238b fix(store): re-open jsonl when file was unlinked externally (e.g., by dashboard Clear)
  • 2d07277 fix(store): wrap schema-creation error with context
  • 98fbece fix(test): append .exe to binPath on Windows
  • 350f18a fix(test): use TOML literal strings for Windows paths
  • 10ac9b3 fix: Windows CI fixes (pre-existing CA bug + e2e TOML escape)
  • 87e6bdf fix: address explore review findings
  • 6f51a25 parser: add shape registry dispatch
  • ed2a92b parser: decode OpenAI Chat Completions SSE streams
  • 6f24952 parser: decode OpenAI Responses API SSE streams
  • a11c9da parser: decode chatgpt backend fixtures
  • 048f750 parser: scope streamed tool buckets by (choice, index) + skip negative indices
  • 237e9b0 proxy: add websocket frame codec
  • 0de7d75 refactor(config): drop unused AllowlistConfig.File field
  • 49576ba refactor(dashboard): consume pre-computed PII matches
  • 38c6a83 refactor(dashboard): drop redundant web/ mirror; keep embed source under internal/dashboard
  • b5c9cd4 refactor(pii): add Tier, Source, ContentKind types
  • 7240528 refactor(pii): run free-text regex inside walker, not body-wide
  • abfe50d refactor(runtime): extract shared proxy/launcher startup into internal/runtime
  • 5cf61ad refactor(runtime): move lockfile from launcher to runtime package
  • 67099c5 release: ship binary + LICENSE only in archives
  • 477b050 store: add websocket event schema foundation
  • f669e0c store: reindex websocket metadata from jsonl
  • de576a2 style(dashboard): apply SOC visual system
  • 4901a5c style(types): apply gofmt
  • 3db1f3d test(ca): skip TestEnsureRejectsBadKeyPerms on Windows
  • 56e5d79 test(dashboard): cover flagLabelFor mapping + unknown-code passthrough
  • 32a8fa7 test(dashboard): strengthen session timeline coverage
  • af1c59d test(e2e): airtight direct-dial-denied assertion (load-bearing)
  • eb07835 test(e2e): cover init non-interactive happy path + force + doctor
  • 0f2b867 test(e2e): proxy → parser → store integration test
  • 90f16d2 test(e2e): proxy → policy → store → dashboard end-to-end
  • fc61f5f test(e2e): replace fixed sleep with Eventually + close flowCh
  • 49d8290 test(launcher): cross-platform supervisor lifecycle tests
  • 210378c test(launcher): linux airtight isolation + descendant inheritance + fail-mode
  • 8ad17c5 test(launcher): macOS sandbox isolation + descendant inheritance
  • d0593c3 test(parser): SSE re-assembly fixture + assertions
  • aaa469f test(parser): capture codex (OAuth) backend traffic for Plan 5
  • a02bedf test(parser): document codex+API-key follow-up — eureka resolved
  • 8ead6bb testdata: scrub vendor names from streaming fixtures

Full Changelog: ...v0.2.0