AgentWall v0.4.0-beta.3
AgentWall v0.4.0-beta.3 Release Notes
Status: Public Beta for Apple Silicon macOS (aarch64) on macOS 13.0 or newer. Intel and universal binaries are not available. Ubuntu remains on its own release line and is unchanged by this release.
AgentWall places a local policy and human-approval layer at configured Codex and Claude Code tool-call boundaries. The local core is Apache-2.0 licensed. This release hub contains compiled artifacts and verification metadata only; AgentWall source remains private.
What is in this release
- A notarized, Developer ID-signed Apple Silicon DMG with per-user, app-supervised
hook protection. There is no App Sandbox, no automatic updater, and no
whole-machine enforcement claim; updates are manual through the Releases page. - Fixes since v0.4.0-beta.2 for native approval nonce/session handling and for
macOS protection-status reporting. - A human Minisign-signed checksum manifest (
SHA256SUMS+SHA256SUMS.minisig),
SPDX SBOM, dependency inventory, and provenance record for release verification.
Tested integration boundary
Codex and Claude Code integrations remain ask-block-prototype with unverified
support-label status. Other agent versions and tools are unverified. The product does
not claim support for Qwen, Cursor, generic MCP governance, Windows, Intel macOS,
enterprise services, or auto-update.
Important limitations
This is tool-call interception, not whole-machine syscall enforcement. Direct
commands, unexposed agent action paths, unsupported versions, and child-process
activity after an allowed command are outside the boundary. Administrators can
bypass the per-user model. Local audit records are not tamper-proof. Agent activity
is not uploaded, and AgentWall runs no automatic analytics.
Install and verification
Download only from this repository's Releases page. Before opening the DMG, verify
the signed manifest with the AgentWall macOS release public key:
minisign -Vm SHA256SUMS -P RWQ0EMfVhrqMZpayEP/VxCwXsSeVxdoCT6FIOmNkqGihxk599o1bFkdM
shasum -a 256 -c SHA256SUMSBoth commands must succeed for every downloaded file before installation. The DMG is
notarized and stapled; macOS Gatekeeper must accept it without override.
Support
- Product issues and questions: use the issue forms at
https://github.com/omnet-systems/agentwall/issues/new/choose - Private security reports: https://github.com/omnet-systems/agentwall/security/advisories/new
- Email: support@omnetsystems.com