Repository navigation
Releases: jozu-ai/agent-guard
Release list
v0.9.5
What's new
- macOS installer and desktop gateway:
AgentGuard.pkginstalls AgentGuard, the gateway engine, a status-bar dashboard and a Network Extension that routes AI app traffic through the gateway, so desktop AI apps are covered by policy too. The same package includes the microVM path, soagentguard runworks from it. It is signed and notarized. Open it, or runsudo installer -pkg AgentGuard.pkg -target /. - Codex and Antigravity are installed from the host: the host now downloads and verifies the Codex and Antigravity binaries and sends them into the VM, as it already did for Claude Code. The guest no longer runs npm for Codex or fetches Antigravity itself. Codex picks its version the way Claude Code does:
--version, else the version of thecodexon your host, else the pinned version. Antigravity serves one version, so--versionis refused for it. When a release manifest cannot be read, the newest cached binary is used, so a warm cache boots offline. - Custom runtime images:
spec.frameworkin an agent definition can now name a container image instead of a built-in agent. AgentGuard resolves, validates and fetches the image on the host, carries it into the VM, and starts your application with its own skills, state and cache directories. A custom runtime session is refused if it would have no gateway, so it cannot run outside policy enforcement. - Local MCP servers go through the gateway: local MCP servers are now routed through the gateway like remote ones, so their tool calls are covered by the same policy enforcement and show up in the session audit stream. Local MCP bundles are installed sealed and run as their own unprivileged user.
- Per-server MCP tool allow-lists: an MCP module can declare which tools it allows. The gateway narrows the server to that list and logs when it does.
- Policy modules named by an agent definition are enforced: the policies an agent definition lists are pinned to one digest and staged with your configured policies.
agentguard policy pullnow checks every layer against its digest, and the policies reported for a session are the ones that were actually loaded. - Reference guardrails: a reference policy bundle is now published under the
jozunamespace, and the default guardrails block only AWS access keys. - Per-registry
--plain-http:--plain-httpnow applies only to the registry of the ref you pass it with. Plain HTTP for one registry no longer affects any other. If you have the old global setting, it is migrated to your policy sources and you get a notice listing the refs it was applied to. - Exit status:
agentguard runnow exits with the status of the agent that ran in the VM.
Improved
- The gateway's configuration is kept on tmpfs inside the guest, so MCP secrets never reach the environment's disk.
- The guest now finishes its shutdown before the host stops the VM.
- A runtime image is stored where only root can write, and is left runnable by the user that runs it.
agentguard policy syncpicks up a tag that has moved (for example:v2) instead of keeping the old files.- A plain-HTTP registry that redirects to HTTPS now produces an explanation instead of a bare failure.
- MCP servers are identified by their declared module name, and module names are validated in one place.
- Updated the gateway engine to gerty v0.1.7. Redaction now applies the verdict as edits at the matched locations on every path (chat, uploads, OOXML archives), image and PDF uploads are refused on the native route, bodies the gateway cannot inspect are denied in the LLM plugin hooks, and the redaction placeholder is branded as Jozu.
- The audit trail now records the request's host and path and links a block to the decision that caused it. The audit outcome for an engine block is now
blocked, where it wasdenied. If you have a collector that matchesgerty.policy.outcome="denied", matchblockedinstead. - The guest image now includes
bubblewrapandripgrep, and its base packages are upgraded on each build. - Agent binary downloads time out when the server stops responding (30 seconds for the response headers, one minute with no data), so
agentguard runno longer hangs on a stalled download. - Release builds pin the Claude Code and Codex versions and checksums.
Fixed
- Silent exit when the guest runs out of memory: when the guest kernel killed the agent for lack of memory,
agentguard runexited 137 and printed nothing. It now says why the agent died. - ChatGPT desktop app stuck on its loading screen behind the gateway: the app waits on a very large startup response, and the reference policy scanned it on every attempt, which took longer than the app's 10 second limit. The reference guardrails now check what you send, not responses, so that traffic passes untouched. An undashed nine-digit number is no longer treated as an ITIN unless it follows a keyword such as
ITINortaxpayer ID, which removes false matches on numeric IDs in app traffic. Dashed ITINs are still caught. - Antigravity tool calls blocked by the hook: Antigravity rejects hook output that contains fields outside its schema, which blocked every tool call. AgentGuard now sends Antigravity only the fields it accepts (
decisionandreason). Other agents are unchanged. - The host read Codex's version from the program name instead of the version number, so the version it reported was wrong. It now reads the first word that starts with a digit.
- Gateway policy refresh failing in the background: the gateway service started without a home directory, so every background refresh of the policy failed with "$HOME is not defined" and the gateway kept whatever policy it started with. The service now has a home directory and can reach the registry. Installed gateways pick up the updated reference policy through this refresh.
- MCP bundle extraction is now bounded by total size, not only by the number of entries.
- macOS AppleDouble files no longer end up in the rootfs image.
- Artifact admission now populates the Kitfile in the artifact context.
- The gateway's wildcard can no longer be declared as a tool name.
- The NOTICE archive that ships with each release was silently coming out empty. It now contains the notices from Go modules that require them.
Security
- Updated gRPC (past CVE-2026-84445), and gRPC and
x/cryptopast three earlier advisories. - Updated the Node.js, kubectl, helm and kind versions in the image, and the release image is now scanned for vulnerabilities in CI.
Also in this release
The reference policy now requires card context, bounds credential tokens and adds payment processor keys. The third-party notices now list the runtimes AgentGuard downloads for you (Claude Code, Codex, Antigravity and the OpenClaw CLI). AgentGuard.pkg is attached to releases on this repository, so the installer can be downloaded here. There is also a lot of new end-to-end test coverage for MCP routing, telemetry and policy enforcement, documentation updates for the gateway, MCP routing and the reference bundle, and the build now resolves Go modules from go.sum instead of a vendored copy.
These notes cover everything since v0.8.0.
v0.9.4
What's new
- macOS installer and desktop gateway:
AgentGuard.pkginstalls AgentGuard, the gateway engine, a status-bar dashboard and a Network Extension that routes AI app traffic through the gateway, so desktop AI apps are covered by policy too. The same package includes the microVM path, soagentguard runworks from it. It is signed and notarized. Open it, or runsudo installer -pkg AgentGuard.pkg -target /. - Custom runtime images:
spec.frameworkin an agent definition can now name a container image instead of a built-in agent. AgentGuard resolves, validates and fetches the image on the host, carries it into the VM, and starts your application with its own skills, state and cache directories. A custom runtime session is refused if it would have no gateway, so it cannot run outside policy enforcement. - Local MCP servers go through the gateway: local MCP servers are now routed through the gateway like remote ones, so their tool calls are covered by the same policy enforcement and show up in the session audit stream. Local MCP bundles are installed sealed and run as their own unprivileged user.
- Per-server MCP tool allow-lists: an MCP module can declare which tools it allows. The gateway narrows the server to that list and logs when it does.
- Policy modules named by an agent definition are enforced: the policies an agent definition lists are pinned to one digest and staged with your configured policies.
agentguard policy pullnow checks every layer against its digest, and the policies reported for a session are the ones that were actually loaded. - Reference guardrails: a reference policy bundle is now published under the
jozunamespace, and the default guardrails block only AWS access keys. - Per-registry
--plain-http:--plain-httpnow applies only to the registry of the ref you pass it with. Plain HTTP for one registry no longer affects any other. If you have the old global setting, it is migrated to your policy sources and you get a notice listing the refs it was applied to. - Exit status:
agentguard runnow exits with the status of the agent that ran in the VM.
Improved
- The gateway's configuration is kept on tmpfs inside the guest, so MCP secrets never reach the environment's disk.
- The guest now finishes its shutdown before the host stops the VM.
- A runtime image is stored where only root can write, and is left runnable by the user that runs it.
agentguard policy syncpicks up a tag that has moved (for example:v2) instead of keeping the old files.- A plain-HTTP registry that redirects to HTTPS now produces an explanation instead of a bare failure.
- MCP servers are identified by their declared module name, and module names are validated in one place.
- Updated the gateway engine to gerty v0.1.6.
Fixed
- ChatGPT desktop app stuck on its loading screen behind the gateway: the app waits on a very large startup response, and the reference policy scanned it on every attempt, which took longer than the app's 10 second limit. The reference guardrails now check what you send, not responses, so that traffic passes untouched. An undashed nine-digit number is no longer treated as an ITIN unless it follows a keyword such as
ITINortaxpayer ID, which removes false matches on numeric IDs in app traffic. Dashed ITINs are still caught. - Antigravity tool calls blocked by the hook: Antigravity rejects hook output that contains fields outside its schema, which blocked every tool call. AgentGuard now sends Antigravity only the fields it accepts (
decisionandreason). Other agents are unchanged. - Gateway policy refresh failing in the background: the gateway service started without a home directory, so every background refresh of the policy failed with "$HOME is not defined" and the gateway kept whatever policy it started with. The service now has a home directory and can reach the registry. Installed gateways pick up the updated reference policy through this refresh.
- MCP bundle extraction is now bounded by total size, not only by the number of entries.
- macOS AppleDouble files no longer end up in the rootfs image.
- Artifact admission now populates the Kitfile in the artifact context.
- The gateway's wildcard can no longer be declared as a tool name.
- The NOTICE archive that ships with each release was silently coming out empty. It now contains the notices from Go modules that require them.
Security
- Updated gRPC (past CVE-2026-84445), and gRPC and
x/cryptopast three earlier advisories. - Updated the Node.js, kubectl, helm and kind versions in the image, and the release image is now scanned for vulnerabilities in CI.
Also in this release
The reference policy now requires card context, bounds credential tokens and adds payment processor keys. AgentGuard.pkg is attached to releases on this repository, so the installer can be downloaded here. There is also a lot of new end-to-end test coverage for MCP routing, telemetry and policy enforcement, documentation updates for the gateway, MCP routing and the reference bundle, and the build now resolves Go modules from go.sum instead of a vendored copy.
These notes cover everything since v0.8.0.
v0.9.3
What's new
- macOS installer and desktop gateway:
AgentGuard.pkginstalls AgentGuard, the gateway engine, a status-bar dashboard and a Network Extension that routes AI app traffic through the gateway, so desktop AI apps are covered by policy too. The same package includes the microVM path, soagentguard runworks from it. It is signed and notarized. Open it, or runsudo installer -pkg AgentGuard.pkg -target /. - Custom runtime images:
spec.frameworkin an agent definition can now name a container image instead of a built-in agent. AgentGuard resolves, validates and fetches the image on the host, carries it into the VM, and starts your application with its own skills, state and cache directories. A custom runtime session is refused if it would have no gateway, so it cannot run outside policy enforcement. - Local MCP servers go through the gateway: local MCP servers are now routed through the gateway like remote ones, so their tool calls are covered by the same policy enforcement and show up in the session audit stream. Local MCP bundles are installed sealed and run as their own unprivileged user.
- Per-server MCP tool allow-lists: an MCP module can declare which tools it allows. The gateway narrows the server to that list and logs when it does.
- Policy modules named by an agent definition are enforced: the policies an agent definition lists are pinned to one digest and staged with your configured policies.
agentguard policy pullnow checks every layer against its digest, and the policies reported for a session are the ones that were actually loaded. - Reference guardrails: a reference policy bundle is now published under the
jozunamespace, and the default guardrails block only AWS access keys. - Per-registry
--plain-http:--plain-httpnow applies only to the registry of the ref you pass it with. Plain HTTP for one registry no longer affects any other. If you have the old global setting, it is migrated to your policy sources and you get a notice listing the refs it was applied to. - Exit status:
agentguard runnow exits with the status of the agent that ran in the VM.
Improved
- The gateway's configuration is kept on tmpfs inside the guest, so MCP secrets never reach the environment's disk.
- The guest now finishes its shutdown before the host stops the VM.
- A runtime image is stored where only root can write, and is left runnable by the user that runs it.
agentguard policy syncpicks up a tag that has moved (for example:v2) instead of keeping the old files.- A plain-HTTP registry that redirects to HTTPS now produces an explanation instead of a bare failure.
- MCP servers are identified by their declared module name, and module names are validated in one place.
- Updated the gateway engine to gerty v0.1.6.
Fixed
- ChatGPT desktop app stuck on its loading screen behind the gateway: the app waits on a very large startup response, and the reference policy scanned it on every attempt, which took longer than the app's 10 second limit. The reference guardrails now check what you send, not responses, so that traffic passes untouched. An undashed nine-digit number is no longer treated as an ITIN unless it follows a keyword such as
ITINortaxpayer ID, which removes false matches on numeric IDs in app traffic. Dashed ITINs are still caught. - Gateway policy refresh failing in the background: the gateway service started without a home directory, so every background refresh of the policy failed with "$HOME is not defined" and the gateway kept whatever policy it started with. The service now has a home directory and can reach the registry. Installed gateways pick up the updated reference policy through this refresh.
- MCP bundle extraction is now bounded by total size, not only by the number of entries.
- macOS AppleDouble files no longer end up in the rootfs image.
- Artifact admission now populates the Kitfile in the artifact context.
- The gateway's wildcard can no longer be declared as a tool name.
- The NOTICE archive that ships with each release was silently coming out empty. It now contains the notices from Go modules that require them.
Security
- Updated gRPC (past CVE-2026-84445), and gRPC and
x/cryptopast three earlier advisories. - Updated the Node.js, kubectl, helm and kind versions in the image, and the release image is now scanned for vulnerabilities in CI.
Also in this release
The reference policy now requires card context, bounds credential tokens and adds payment processor keys. AgentGuard.pkg is attached to releases on this repository, so the installer can be downloaded here. There is also a lot of new end-to-end test coverage for MCP routing, telemetry and policy enforcement, documentation updates for the gateway, MCP routing and the reference bundle, and the build now resolves Go modules from go.sum instead of a vendored copy.
These notes cover everything since v0.8.0.
v0.9.2
What's new
- macOS installer and desktop gateway:
AgentGuard.pkginstalls AgentGuard, the gateway engine, a status-bar dashboard and a Network Extension that routes AI app traffic through the gateway, so desktop AI apps are covered by policy too. The same package includes the microVM path, soagentguard runworks from it. It is signed and notarized. Open it, or runsudo installer -pkg AgentGuard.pkg -target /. - Custom runtime images:
spec.frameworkin an agent definition can now name a container image instead of a built-in agent. AgentGuard resolves, validates and fetches the image on the host, carries it into the VM, and starts your application with its own skills, state and cache directories. A custom runtime session is refused if it would have no gateway, so it cannot run outside policy enforcement. - Local MCP servers go through the gateway: local MCP servers are now routed through the gateway like remote ones, so their tool calls are covered by the same policy enforcement and show up in the session audit stream. Local MCP bundles are installed sealed and run as their own unprivileged user.
- Per-server MCP tool allow-lists: an MCP module can declare which tools it allows. The gateway narrows the server to that list and logs when it does.
- Policy modules named by an agent definition are enforced: the policies an agent definition lists are pinned to one digest and staged with your configured policies.
agentguard policy pullnow checks every layer against its digest, and the policies reported for a session are the ones that were actually loaded. - Reference guardrails: a reference policy bundle is now published under the
jozunamespace, and the default guardrails block only AWS access keys. - Per-registry
--plain-http:--plain-httpnow applies only to the registry of the ref you pass it with. Plain HTTP for one registry no longer affects any other. If you have the old global setting, it is migrated to your policy sources and you get a notice listing the refs it was applied to. - Exit status:
agentguard runnow exits with the status of the agent that ran in the VM.
Improved
- The gateway's configuration is kept on tmpfs inside the guest, so MCP secrets never reach the environment's disk.
- The guest now finishes its shutdown before the host stops the VM.
- A runtime image is stored where only root can write, and is left runnable by the user that runs it.
agentguard policy syncpicks up a tag that has moved (for example:v2) instead of keeping the old files.- A plain-HTTP registry that redirects to HTTPS now produces an explanation instead of a bare failure.
- MCP servers are identified by their declared module name, and module names are validated in one place.
- Updated the gateway engine to gerty v0.1.6.
Fixed
- MCP bundle extraction is now bounded by total size, not only by the number of entries.
- macOS AppleDouble files no longer end up in the rootfs image.
- Artifact admission now populates the Kitfile in the artifact context.
- The gateway's wildcard can no longer be declared as a tool name.
- The NOTICE archive that ships with each release was silently coming out empty. It now contains the notices from Go modules that require them.
Security
- Updated gRPC (past CVE-2026-84445), and gRPC and
x/cryptopast three earlier advisories. - Updated the Node.js, kubectl, helm and kind versions in the image, and the release image is now scanned for vulnerabilities in CI.
Also in this release
The reference policy now requires card context, bounds credential tokens and adds payment processor keys; a lot of new end-to-end test coverage for MCP routing, telemetry and policy enforcement, and documentation updates for the gateway, MCP routing and the reference bundle. This release skips v0.9.0 and v0.9.1, which were not published here, so the notes above cover everything since v0.8.0.
v0.8.0
What's new
- OTLP telemetry relay: AgentGuard can now forward telemetry from the sandbox to your own OpenTelemetry collector, so you can see what's happening inside a running session from your existing observability stack.
- Remote MCP routing (phase 1): remote MCP servers are now routed through the gateway, bringing them under the same policy enforcement as everything else the agent talks to.
Improved
agentguard runstarts about 50% faster, and now shows progress during longer waits instead of leaving you looking at a blank terminal.- VM boot is faster too: the embedded guest binary is no longer re-read from disk on every boot.
- Clearer error when a sandbox collision is refused: you'll now see the environment name and who's holding it, instead of a generic failure.
- AgentGuard now refuses to start a second microVM on an environment that's already running one, and environment commands can no longer delete an environment out from under an active VM.
Fixed
- Clipboard writes from inside the guest now land on the host pasteboard correctly.
- Antigravity's OAuth session now round-trips into and out of the VM properly.
- Codex now correctly picks up
OPENAI_API_KEYand writes it into the guest'sauth.json. - Stale cached agent binaries are cleaned up after a new download instead of accumulating.
Removed
- Gemini CLI agent runtime support has been removed. If you were running Gemini through AgentGuard, this is no longer available in this release.
Also in this release
A good amount of work went into CI reliability behind the scenes (the nightly build and the release pipeline itself are both more trustworthy now), along with dependency updates and test coverage improvements. Nothing user-facing there, but worth knowing if you watch the build status.
Full changelog: jozu-ai/agentguard@v0.7.1...v0.8.0
v0.7.1
This release adds a self-update command, keeps agent sessions across runs, ships audit logs on its own, and patches seven dependency advisories. It also carries everything from v0.7.0, which was not published here.
Highlights
-
agentguard update. Moving to a newer release no longer means re-running the install script.agentguard updatechecks for one, asks, and installs it in place.--dry-runreports what would happen without doing it,--version Xinstalls an exact release in either direction (reinstalling a corrupted binary, or stepping back while a regression is fixed), and--yesskips the prompt for scripts. Every download is verified against Jozu's Developer ID signature and, starting with this release, the published SHA-256. If the install directory belongs to root, it re-runs itself under sudo and asks for your password like any other elevated install. Agent Guard also mentions a newer version at most once a day; setAGENTGUARD_NO_UPDATE_CHECK=1to turn that off. -
Sessions survive the VM. Conversation transcripts and prompt history now persist between runs, so resuming a session and
--continuebehave the way they do outside the sandbox. Each named environment keeps its own history. Add--no-persist-sessionsfor a run that leaves nothing behind, or clear one environment withagentguard env clear-state <name>. -
Audit logs upload by themselves. Policy decisions and tool calls from
agentguard runare shipped as they happen, with no background service to install or keep running. Uploaded bundles now record which agent produced them, so a fleet's activity reads per agent instead of as one undifferentiated stream. -
Environment cloning is faithful. A cloned environment now reproduces the original exactly, and cloning one that is currently running is refused rather than quietly producing a copy that differs from what you asked for.
Fixes
- A VM whose standard input closed, which happens whenever you pipe a command into an agent, would spin a CPU core at 100 percent instead of finishing.
- Long sessions no longer fill with libmalloc warnings from the guest.
- Fleet heartbeats default to every five minutes instead of every two, which cuts idle traffic from a large fleet without making status noticeably staler.
- Per-agent behavior now lives in a single registry, so all five supported agents pick up install, credential, and policy changes together instead of drifting apart.
Security and dependencies
- Go 1.26.6, closing five standard library advisories.
- oras-go and grpc bumped for two more.
Verifying this release
The macOS binary is built in FIPS 140-3 mode, codesigned with Jozu's Developer ID, and notarized.
| File | Description |
|---|---|
agentguard |
Notarized macOS ARM64 binary |
agentguard.zip |
Notarized archive |
checksums.txt |
SHA-256 for the binary and the archive |
agentguard.cdx.json |
CycloneDX SBOM |
THIRD_PARTY_NOTICES.md |
Third-party license notices and GPL/LGPL source offer |
checksums.txt is new in this release. To check the binary before you run it, download both files into the same directory and run:
grep ' agentguard$' checksums.txt | shasum -a 256 -c -You can also confirm the signature, which is what agentguard update checks on your behalf:
codesign --verify --strict -R '=anchor apple generic and certificate leaf[subject.OU] = PMHBCVV9C2' agentguardv0.6.5
This release adds Antigravity as a supported agent, fixes a scroll regression from v0.6.3, and patches two dependency vulnerabilities.
Highlights
- Antigravity CLI (
agy) support. Google is retiring the standalone Gemini CLI in favor of Antigravity CLI, so Jozu Agent Guard now supports it as a fifth agent alongside Claude Code, Gemini CLI, Codex CLI, and OpenClaw, with the same integration surface: install, credential staging, hook-based policy enforcement, MCP servers, skills, and fleet heartbeat reporting. Try it:agentguard run agy.
Fixes
- Fixed scroll-wheel input being mistranslated into arrow keys inside the microVM terminal, a regression introduced in v0.6.3. That release changed how terminal output was relayed to make plain click-drag text selection work, but the side effect was that the host terminal never entered its normal scroll-handling mode, so scrolling fell back to arrow keys, which some agents surfaced as a confusing warning. This release restores standard terminal behavior: scroll works out of the box, and text selection is a shift or option drag, the same as running the agent directly outside Jozu Agent Guard. The login URL auto-copy behavior from v0.6.3 is untouched and still works.
Security and dependencies
- Bumped two dependencies to patch known vulnerabilities: an infinite-loop issue reachable via the Hub client, and a transparency-log verification bypass reachable via image signature checks.
Verifying this release
The macOS binary is built in FIPS 140-3 mode, codesigned, and notarized.
| File | Description |
|---|---|
agentguard |
Notarized macOS ARM64 binary |
agentguard.zip |
Notarized archive |
agentguard.cdx.json |
CycloneDX SBOM |
THIRD_PARTY_NOTICES.md |
Third-party license notices and GPL/LGPL source offer |
To verify the binary signature:
spctl --assess --type execute --verbose agentguard
Full documentation: https://jozu.com/docs/agent-guard/getting-started/ag-overview.html
See the v0.6.4 release notes on this page for a summary of everything shipped before this release.
v0.6.4
This release adds live activity state for running agents and fixes a clock-drift bug that could break auth inside long-running VMs.
Highlights
- Agent activity state detection. The Jozu Hub Fleet View and
agentguard topnow show what an agent is actually doing right now: working, idle, blocked (waiting on a human, e.g. a plan approval or a question), starting, or stalled. This is derived from LLM traffic seen by the gateway inside the microVM, so it works with zero changes to agent frameworks or policies. A blocked transition reaches the Hub within seconds rather than waiting for the next periodic heartbeat. Try it:agentguard topwhile a run is active, or check the Fleet View on the Hub.
Fixes
- Fixed guest VM clocks drifting over long sessions with no way to recover. Once the clock drifted (for example, the host going to sleep mid-session), nothing corrected it, and one user hit this directly: a JWT minted by their identity provider looked "not yet valid" against the guest's drifted clock, failing authentication. Jozu Agent Guard now periodically checks and corrects the guest clock during a run, and a failure in that mechanism only disables it for that session rather than failing VM boot.
Verifying this release
The macOS binary is built in FIPS 140-3 mode, codesigned, and notarized.
| File | Description |
|---|---|
agentguard |
Notarized macOS ARM64 binary |
agentguard.zip |
Notarized archive |
agentguard.cdx.json |
CycloneDX SBOM |
THIRD_PARTY_NOTICES.md |
Third-party license notices and GPL/LGPL source offer |
To verify the binary signature:
spctl --assess --type execute --verbose agentguard
Full documentation: https://jozu.com/docs/agent-guard/getting-started/ag-overview.html
See the v0.6.3 release notes on this page for a summary of everything shipped before this release.
v0.6.3
This is the first release published to this repository. These notes cover everything shipped across the v0.6.x series so far (v0.6.0 through v0.6.3).
Highlights
- Guardrail enforcement on LLM traffic. Every request an agent makes to an LLM provider now routes through a TLS-terminating gateway inside the microVM, where policy rules can inspect and enforce on it. With no policy loaded, the gateway defaults to deny-all rather than passing traffic through uninspected. Watch decisions live with
agentguard logs --guardrails. - Fleet visibility. Running agents show up live in the Jozu Hub Fleet View. Jozu Agent Guard sends a heartbeat at startup, one periodically during the run, and a final "stopped" heartbeat on exit, including which agent framework is running and real resource usage.
- Live audit log streaming. Policy and guardrail events stream from the VM to the host as they happen, viewable locally with
agentguard logswhile a run is active. Optionally schedule upload to the Hub withagentguard audit schedule install. - Container and Kubernetes tooling in the sandbox. Rootless Podman, KIND, and Helm now ship in the microVM out of the box, isolated per principal with no host Docker socket involved. Try
agentguard run claude-code --shelland use them directly. - Login at run start. The first
agentguard runon a machine opens a browser sign-in and registers the instance before the VM boots, so fleet visibility and policy distribution work from the very first run. Headless environments can useagentguard registerahead of time, or setAGENTGUARD_NO_LOGIN=1.
Fixes and stability
- Jozu Agent Guard now detects and repairs mismatched or truncated kernel, initrd, and rootfs files on first launch after an upgrade, instead of failing with a cryptic error.
agentguard env deletenow handles overlay directories containing read-only files written by the guest, which previously caused deletion to fail partway through.- Re-registering against a different hub now validates the new URL and cleanly tears down the old session, instead of leaving stale session state behind.
- Fleet status now reports the actual installed version of Codex, Gemini, and OpenClaw, instead of a placeholder.
- Fixed
agentguard run codexgetting stuck on Codex's own "Do you trust this folder?" prompt. The VM is already the sandbox boundary and policy enforcement runs independently of Codex's own approval gate, so that prompt is now skipped. - Fixed text selection and copy inside the microVM terminal. Some agent TUIs enable mouse-tracking on startup, which used to hijack click-drag away from native text selection; copying a file path, an error message, or a login URL now works normally.
- Fixed a race that could hang a run indefinitely right after boot, and removed a guest-to-host file transfer path that had a path-escape bug and a fail-open case where a failed transfer could silently disable policy enforcement.
- Every release now ships a software bill of materials and a human-readable third-party notices file covering all embedded and linked components, including a written source offer for GPL/LGPL components.
Breaking changes (introduced in v0.6.0)
agentguard register --tokenand--token-stdinwere removed. Use the interactive device flow (agentguard register) instead.- Unauthenticated runs now fail with guidance instead of starting silently and skipping fleet reporting.
Verifying this release
The macOS binary is built in FIPS 140-3 mode, codesigned, and notarized.
| File | Description |
|---|---|
agentguard |
Notarized macOS ARM64 binary |
agentguard.zip |
Notarized archive |
agentguard.cdx.json |
CycloneDX SBOM |
THIRD_PARTY_NOTICES.md |
Third-party license notices and GPL/LGPL source offer |
To verify the binary signature:
spctl --assess --type execute --verbose agentguard
Full documentation: https://jozu.com/docs/agent-guard/getting-started/ag-overview.html