Repository navigation
v0.7.3: any agent, not only local coding tools
Squidbrake now reaches agents beyond local coding tools.
Agents that connect to MCP by URL (ChatGPT and claude.ai connectors, Devin, n8n, cloud agents)
squidbrake proxy --app github --serve 0.0.0.0:9000 --token "$PROXY_TOKEN" -- npx -y @modelcontextprotocol/server-github- The agent adds
https://your-host:9000/mcpand sends the token (Bearer,X-Squidbrake-Tokenor?token=). Without it, nothing gets in. - Each conversation is checked on its own, so chains never mix. A caller can name its conversation with
X-Squidbrake-Session.
Remote MCP servers that need their own auth
squidbrake proxy --url ... --header 'Authorization: Bearer ${TOKEN}'.connect guardnow guards these servers too, instead of skipping them.
Cursor and Codex
- Cursor: file edits and deletes (
preToolUse, recent Cursor) and MCP tools (beforeMCPExecution) are now checked, on top of terminal commands and reads. - Codex: MCP tools are now checked.
- Run
squidbrake connect allagain to pick these up.
Agent frameworks
gw.guard_tools([...])puts all of an agent's tools behind Squidbrake in one line: OpenAI Agents SDK, LangChain / LangGraph, CrewAI, PydanticAI, smolagents and Google ADK.- A call Squidbrake stops doesn't run, and the model reads a "NOT RUN: ..." message instead of the run crashing.
- Tested against langchain-core 1.6.7 and openai-agents 0.23.1.
Fix
- The Python client works when an app runs more than one event loop (several
asyncio.runcalls).
Install this version (0.7.3)
Windows (PowerShell):
$env:SQUIDBRAKE_VERSION="0.7.3"; irm https://pilots.squidbrake.com/install.ps1 | iexmacOS / Linux:
curl -fsSL https://pilots.squidbrake.com/install.sh | SQUIDBRAKE_VERSION=0.7.3 shWith pip: pip install squidbrake==0.7.3. Docker: docker pull ghcr.io/batrapulkit/squidbrake:0.7.3
Running the line again without SQUIDBRAKE_VERSION goes back to the newest. Every version:
https://github.com/batrapulkit/squidbrake/releases