Skip to content

Releases: batrapulkit/squidbrake

v0.7.9: one line, and the computer is set up

Choose a tag to compare

@batrapulkit batrapulkit released this 08 Oct 13:51

One line, and the computer is set up

squidbrake setup does everything a person needs on this computer, in one go. The installers now end with it, so the line on the start page is the whole setup:

  • Squidbrake keeps running in the background and starts at every login.
  • Every AI agent on the computer is connected: Claude Code, Cursor, Codex, Gemini CLI, VS Code Copilot, Antigravity, and the MCP servers they use.
  • Each hook is checked end to end. Anything that still needs a person, such as trusting the hook in Codex, is printed with the fix.
  • The keys are shown once.
  • The dashboard opens already signed in. The key goes in the part of the address after #, which never leaves the computer.

If the port is taken, setup stops before any key is made. Running it a second time doesn't restart anything; it reconnects the agents and checks them again. To install without setting up, use SQUIDBRAKE_SETUP=0.

Also in this release:

  • When an install fails, the installer asks before sending the lines it printed (home folder shown as ~) to the pilots dashboard.
  • Re-running the installer right after a release now gets that release. pip and uv used to reuse PyPI's version list for a few minutes.

Upgrade: run the install line again, or pipx upgrade squidbrake and then squidbrake setup.

v0.7.8: installs that work on the laptops people really have

Choose a tag to compare

@batrapulkit batrapulkit released this 08 Oct 12:28

Installs that work on the laptops people really have

Every way we found a founder's install going wrong, fixed, each with a test.

Windows

  • Cursor on a profile with a space (C:\Users\Rahul Kumar) no longer blocks every action. Cursor runs hooks through PowerShell, where a quoted path isn't run. The hook line is now one word per path in cmd, PowerShell and bash, and squidbrake doctor checks it in PowerShell too.
  • Company proxies: the hooks reach the gateway on this computer directly and never through the system proxy. If something that isn't Squidbrake answers (a proxy's sign-in page), the call is blocked instead of run unchecked.
  • About 2 seconds faster per tool call: hooks use 127.0.0.1, not localhost. Windows tries IPv6 first and waits before falling back.
  • User folders in other scripts (Devanagari, Cyrillic, ...) no longer stop a command or the background service.
  • Windows on ARM installs: httptools has no wheel for it, so it's skipped there.
  • The background service waits longer each time the gateway fails to start (up to 5 minutes) instead of every 2 seconds. When stopped, it only ends a process that is Python.

First run, everywhere

  • If the port is taken, it says so before any key is printed or browser opened (the dashboard key used to land in the other app).
  • No browser over SSH or on Linux without a desktop.
  • squidbrake pilot join no longer asks the usage-stats question. With opposite defaults, pressing Enter on both put founders in the community pilot instead of theirs.
  • Saying no to the background service now explains that agents' actions wait while Squidbrake is off.

Antigravity

  • Its own housekeeping (checking background tasks and commands, notifying, reading pages and MCP resources) runs without asking. Typing into a running command and the browser agent still ask.

Installers (served from the pilots server, so already live)

  • Re-running upgrades in place. A failed download keeps the working install, and the background service is stopped and started again around the upgrade.
  • They show why pip or uv failed, and work behind HTTPS-inspecting proxies.
  • macOS: no developer-tools pop-up. Debian/Ubuntu: python3-venv is named. PATH goes in the file each shell reads. Home folders with spaces work. WSL is named.
  • If an install fails, it asks before sending the lines it printed, with your home folder shown as ~.

Upgrade: run the install line again, or pipx upgrade squidbrake

v0.7.7: Windows install keeps its window open

Choose a tag to compare

@batrapulkit batrapulkit released this 07 Oct 18:30
  • Windows: on a computer without Python 3.10+, the one-line installer no longer closes the PowerShell window. uv's installer now runs in its own PowerShell, so its exit on the default Restricted execution policy can't end yours.
  • squidbrake pilot join with no keyboard to answer (piped, CI) now says how to join instead of showing a traceback.

v0.7.6: what it caught, and teams past week one

Choose a tag to compare

@batrapulkit batrapulkit released this 07 Oct 18:12

For teams running agents past week one

  • What it caught, every week. The Monday report now lists what was blocked, what people rejected (by whom, with their note) and what shadow mode would have stopped, each with what it would have done. It goes to Slack, Discord, Microsoft Teams or email, and the dashboard has it under Reports → What it caught with a Copy weekly report button. (The digest to a Discord webhook used to fail quietly; it now uses Discord's format.)
  • Rules suggested from what you keep approving. Settings → Rules shows "approved 5 times, never rejected: Allow it?" and adds the rule in the right place, with a backup. Money, the agent's own settings and anything a command check held are never suggested.
  • Starter packs for support, finance and ops agents, one click each (small refunds run, deleting customers never does; large transfers refused, payee changes wait for finance; flags, pins, scaling and restarts wait for a person).
  • Approvals in Teams and by email. Teams gets a card; email links only to the review page (mail scanners open links, so no one-tap approve in email). "Send a test notification" checks both.
  • Every decision to your SIEM. Splunk HEC, Datadog logs or any HTTP endpoint, batched in the background, with a "Send a test record" button.
  • Slack buttons. Approve and Reject right in the Slack message, from Squidbrake's Slack app (manifest in Settings). Clicks are verified with the app's signing secret, and the message then says who decided.
  • OAuth apps by URL. Connect in Settings signs in once to Slack, HubSpot, Notion, Asana, ClickUp, Grafana Cloud or any OAuth MCP server; the gateway keeps and refreshes the session, and every call is checked like any other.
  • Data checks. Text an agent puts where others read it (a PR, issue, comment or post) that names a customer on your list, or carries card numbers, SSNs, IBANs or lists of people's contacts, waits for a person.

Upgrade: pipx upgrade squidbrake

v0.7.5: change control, record first

Choose a tag to compare

@batrapulkit batrapulkit released this 07 Oct 15:51

Change control for AI agents: the record comes first

  • The README, demo GIF, Claude Code plugin, plugin marketplace and MCP registry listing now say what Squidbrake is: a record of every change your agents make (which agent, what changed, who signed off, what led to it), sign-off by a second person for risky changes, and an undo for destructive ones.
  • The weekly Slack summary now opens with what people signed off on, then what the agents did.
  • New example policy for agents that run with nobody watching (nightly loops, cron jobs, Routines): examples/rules/unattended-agent.yaml. Every action goes on the record; the agent stays in its own lane (reads plus a short list of writes); it can't redo work or repeat something a person rejected; deletes, money out and irreversible commands are refused because nobody is awake to sign off; and a stuck loop stops after 200 steps. It ships in shadow mode.

Upgrade: pipx upgrade squidbrake

v0.7.4: MCP by URL from your dashboard

Choose a tag to compare

@batrapulkit batrapulkit released this 07 Oct 10:07

Any agent that connects to MCP by URL, straight from your dashboard

For ChatGPT and claude.ai connectors, Devin, n8n and other cloud agents:

  1. In the dashboard, open Settings → Agents that connect by URL. Add the app's MCP server: its URL, plus the header its auth needs.
  2. Give the agent https://<your gateway>/mcp/<name>. It signs in with one of its agent keys: Authorization: Bearer gw_..., or ?key=gw_... for apps that take only a URL.

What happens:

  • Every call is checked like any other (rules, chains, approvals) and recorded as the agent that made it.
  • The app's own token stays on the gateway and is never shown again.
  • Hosted dashboards take servers by URL. Servers started by a command need a self-hosted gateway with SQUIDBRAKE_MCP_COMMANDS=1.
  • If the gateway stops, even by crashing, the proxies behind these URLs stop with it.

v0.7.3: any agent, not only local coding tools

Choose a tag to compare

@batrapulkit batrapulkit released this 07 Oct 09:45

Squidbrake now reaches agents beyond local coding tools.

Agents that connect to MCP by URL (ChatGPT and claude.ai connectors, Devin, n8n, cloud agents)

squidbrake proxy --app github --serve 0.0.0.0:9000 --token "$PROXY_TOKEN" -- npx -y @modelcontextprotocol/server-github
  • The agent adds https://your-host:9000/mcp and sends the token (Bearer, X-Squidbrake-Token or ?token=). Without it, nothing gets in.
  • Each conversation is checked on its own, so chains never mix. A caller can name its conversation with X-Squidbrake-Session.

Remote MCP servers that need their own auth

  • squidbrake proxy --url ... --header 'Authorization: Bearer ${TOKEN}'.
  • connect guard now guards these servers too, instead of skipping them.

Cursor and Codex

  • Cursor: file edits and deletes (preToolUse, recent Cursor) and MCP tools (beforeMCPExecution) are now checked, on top of terminal commands and reads.
  • Codex: MCP tools are now checked.
  • Run squidbrake connect all again to pick these up.

Agent frameworks

  • gw.guard_tools([...]) puts all of an agent's tools behind Squidbrake in one line: OpenAI Agents SDK, LangChain / LangGraph, CrewAI, PydanticAI, smolagents and Google ADK.
  • A call Squidbrake stops doesn't run, and the model reads a "NOT RUN: ..." message instead of the run crashing.
  • Tested against langchain-core 1.6.7 and openai-agents 0.23.1.

Fix

  • The Python client works when an app runs more than one event loop (several asyncio.run calls).

v0.7.2: background service (opt-in) and squidbrake explain

Choose a tag to compare

@batrapulkit batrapulkit released this 06 Oct 17:04

Keep it running in the background, if you want to (thanks @bishboi, #63)

  • The first time you run squidbrake in a terminal, it asks once whether to keep it running in the background and at every login. Enter means no.
    • macOS uses launchd, Linux a systemd user service, Windows a login entry.
    • squidbrake start --background turns it on without asking. squidbrake service status | stop checks it or takes it out.
    • Agents fail closed, so a closed terminal no longer locks them out.
  • Dashboard:
    • Each agent has its own color and initials.
    • Activity opens on Chains: one card per session, with its steps in order. "Show chain" in the approval queue jumps to that session.

squidbrake explain "<command>" (thanks @SaiThihan, #64)

  • Shows how Squidbrake reads a shell command, and what the gateway would do with it, without running anything. Exit code 1 when it's more than "other".
$ squidbrake explain "git push origin main"
other
  git push origin main other
  gateway: waits for a person (approve-git-push)

Fixes

  • squidbrake service --help shows the service's own help.
  • The test suite passes on Windows.

v0.7.1: usage stats switched on (only after a yes)

Choose a tag to compare

@batrapulkit batrapulkit released this 06 Oct 10:50

Anonymous usage stats from the first-run question (v0.7.0) now reach the Squidbrake team. Nothing changes for anyone who said no, or who turns it off: squidbrake telemetry off, SQUIDBRAKE_TELEMETRY=0 or DO_NOT_TRACK=1. What is sent: squidbrake telemetry status.

v0.7.0: one question on first run, so we can see what Squidbrake catches

Choose a tag to compare

@batrapulkit batrapulkit released this 06 Oct 10:41

The first time you run squidbrake in a terminal, it asks one question (Enter means yes):

Squidbrake can send anonymous usage stats to its team:
  - which squidbrake commands run, the version, OS and country
  - counts of what it checked, held and blocked: the program only (e.g. "rm"), the rule, and sizes
Never your commands, files, prompts, rules or keys. It shows one small team what to fix next.
Send anonymous usage stats? [Y/n]
  • Asked once. Never asked in the agent hooks, scripts, CI or with --yes, and nothing is sent from them until someone has said yes.
  • squidbrake telemetry status shows exactly what is sent; squidbrake telemetry off (or SQUIDBRAKE_TELEMETRY=0, or DO_NOT_TRACK=1) stops it.
  • squidbrake register you@company.com tells the team who you are, if you'd like help rolling it out (asks first).
  • An install already in a pilot keeps its pilot.

Details: telemetry.py and pilot.py.