Flanner Curb

See what your agents can reach, and cut it to what they need.

Flanner Curb shows what Claude Code and Codex can reach on your machine: the credentials each could read, and every channel that could carry them away.

A command group in the free flanner CLI. It runs on your machine, and its output names no credential and no location.

flanner curbReading…
$ flanner curb map --agent claude
Claude Code High (H1, configured)
CHANNEL STATE
Built-in file tools uncontrolled
Shell commands: files uncontrolled
Shell commands: network uncontrolled
Web fetch and web search uncontrolled
MCP servers uncontrolled
Model provider traffic informational
Credentials: 2 found, 2 readable (2 wide): cloud 1, SSH 1.
No names, no locations

An agent can reach more than its settings suggest

A coding agent runs in your shell, as you. It can usually read your tokens, SSH keys and cloud logins, and a prompt injection or a plain mistake can use them. A setting that looks like protection often covers one path and leaves another open.

A Read deny rule covers one path

In Claude Code, a deny rule on Read covers the built-in file tools and the shell file commands it recognises. It does not cover grep -r, or a script that opens the file. Curb counts the file as readable until the sandbox denies it too.

The network is several channels

A list of allowed domains applies to sandboxed shell commands. Web fetch and search, MCP servers and apps each have their own control, or none. Curb judges each channel on its own.

Settings files are not the session

A launch flag, a Codex profile or another folder changes which settings apply. So each report is for one stated launch, and says what it assumed.

Three commands that only read

Nothing is changed, and nothing leaves the machine.

Reach, channel by channel

Rates each agent launch High, Medium or Low, and names the rule behind the rating. It says whether each channel is controlled, and which setting would close an open one.

flanner curb map

Names, in a window only

Opens the same report with credential names and locations, in a window on your screen. Nothing from it is printed or written to disk, so an agent that runs the command gets only a notice.

flanner curb show

What each agent loads

Settings layers, MCP servers, hooks, skills, and scheduled jobs that run an agent unattended, with who controls each. Credential names appear only as counts.

flanner curb inventory

Each finding is marked configured or assumed, or enforced once a test has proved it. Configured means read from the settings for that launch. Assumed means inferred, and anything Curb could not read counts as the worse case. Expect High the first time: most developer machines rate High today, and the report says which setting changes that. How to read a report

Find the secrets agents left behind

The leak sweep reads where agents leave secrets: transcripts and sessions, CLAUDE.md and AGENTS.md, skills, MCP configs, shell history, your project's .env files, and flanner's own plans and memories. It works offline, and puts each secret in one of three classes.

A. Sent to a model provider

It is in a transcript, so it has already left the machine. Rotate it now.

B. Readable by an agent

Some agent launch here can read the file, through a channel no control covers. Rotate it, or move it where no agent can read it.

C. On disk but blocked

No agent launch here can read it today.

Run flanner curb sweep. Only counts are printed; flanner curb show --sweep opens types and locations in a window. No command prints a secret's value. Detection is Kingfisher, an optional extra: pip install 'flanner[sweep]'.

Close what is open, and test it

From here Curb can change things. Every change needs a yes from your operating system, which an agent cannot give.

Fixes, in the agent's own settings

Deny rules, the sandbox, and network and environment limits, written to each agent's user settings. Curb plans only changes that leave every channel no broader. Each file is backed up for 7 days, and --undo puts it back.

flanner curb fix

A test that asks the agent itself

Curb plants a decoy of fake credentials beside each file a control claims to block. Then it asks the agent to read it four ways: its Read tool, cat, grep -r and a script. It costs tokens on your own plan, and states the cost first.

flanner curb test

Your operating system asks, not Curb

Windows Hello or the account password, Touch ID or the password on macOS, polkit on a Linux desktop. A yes covers one exact change, once, for two minutes. With no approval method, Curb stays read-only.

Scrub a rotated secret from a file

After you rotate a secret, Curb replaces it in the file with a placeholder of the same length. No backup is kept, because a backup would be another copy. It is the one change that cannot be undone.

flanner curb scrub FILE

See what your agents actually use

The action log records each tool call's metadata: the agent, the tool, the channel, a redacted target and the decision. Never the content.

A log you can check

Each record is chained to the one before it and signed with the device key, so --verify catches an edited, removed or reordered record. Records are kept 30 days. If the log cannot be written, the agent carries on.

flanner curb log --enable

Observed use, per channel

Once the log covers 14 days and 20 sessions, Curb says what each agent was seen using. With less it says no evidence. If some sessions ran without the hooks, it says partial evidence.

flanner curb observed

Not seen is not "not needed"

The hooks cannot see everything: child processes, and for Codex web search, MCP servers and apps. So an idea for closing a channel is only a suggestion for you to review.

One policy for a team, on Flanner Mesh

Your organization signs one policy for its coding agents. Each device checks it, and decides for itself what to apply.

Org policy

Paths no agent may read, the sandbox, allowed domains, web access and allowed MCP servers. A device applies a change on its own only when the change tightens. Anything else waits for your approval on that device.

flanner curb policy

The fleet view

Admins see each device's policy state, drift and counts by severity. Each device signs its own reports, and the command checks every signature itself. Reports carry no paths, names or fingerprints.

flanner curb fleet

Alerts when reach grows

A new MCP server, a removed deny rule, the sandbox turned off, or a secret sent to a model provider. You are told on your own machine. Admins can have alerts sent to a webhook or Slack.

These three need a Flanner Mesh account, and stay free when its trial ends. How it works on Mesh, and what is free.

In your pipelines, and in your own code

The same questions, asked away from the laptop.

A check for CI workflows

Each GitHub Actions step that runs Claude Code, Codex or Gemini CLI is judged like an agent launch: whether issue or pull request text reaches it, who can start it, and the secrets and tools it holds. It writes SARIF for code scanning, and also runs as a GitHub Action.

flanner curb ci

An audit of your app's LLM calls

Finds the LLM calls in an application's Python code and labels each a single call, tool-using or a loop. It flags untrusted input beside tool-using calls. Every result is marked assumed: it is pattern matching, a start for a deeper review.

flanner curb app

A skill for your agent

flanner init installs the agent-blast-radius skill. Your agent runs the redacted commands and gets severities and counts. For names it asks you to open the window, and nothing from the window reaches it.

Know which agent key signed a commit

A signature shows which key signed, not who wrote the code. So Curb calls this attribution, not identity.

A key for each agent

Each agent on each device gets its own Ed25519 key, kept only in the OS credential store. Curb reminds you to rotate a key after 90 days, and a retired key can sign nothing new.

flanner curb attribution --setup

Signed only inside a session

git signs an agent's commits through a flanner program. It signs only while an agent session the hooks recorded is running a command, and logs each commit. A commit outside a session is refused.

Five answers per commit

Attributed, attributed with a retired key, untrusted because its key was revoked, key status unknown, or unattributed. A revocation is never undone, and an expired key list never counts as current.

flanner curb verify

What stays on your machine

No prompt, code, transcript or secret value is ever uploaded to Flanner.

Stays here

  • Every report. Curb reads agent settings and credential locations on this machine, and runs nothing from the repository.
  • Credential names and locations. They appear only on your screen, never in terminal output, JSON or a file.
  • Secret values. One is held only long enough to fingerprint it, with a key that never leaves this device.
  • A redacted copy of the last sweep, for 30 days: counts, classes and fingerprints. flanner curb forget deletes it.
  • Backups of the settings files a fix changed, for 7 days.
  • The action log, for 30 days. It holds metadata, never content.

Leaves only when you say so

  • A found secret, to its own issuer, when you run a sweep with --validate and answer yes. It asks every run.
  • A test prompt and the decoys' fake contents, to your model provider through your own agent, when you run a test.
  • Policy state, device reports and alerts, to Flanner's servers for your organization, once you enrol the device or check in. No paths, usernames or repository names.
  • The redacted report, to your agent's model provider, when you ask the agent to use the skill.
  • Each agent's public signing key: to GitHub through your own gh sign-in if you ask, and to your organization's key registry on Flanner's servers.

What it does not do

It is not a sandbox

Curb is not an OS sandbox, a network proxy or a secret vault. It reports whether the agent's own sandbox is on. Its fixes can turn that sandbox on, and its tests check it.

It reads settings, not running sessions

A session started with other flags may reach more than the report shows. Every report names the launch it assessed, and assumes no other flags, profiles or settings files.

It does not stop malware running as you

Anything that runs as your user can read, edit and sign what you can. Curb points to the agent's sandbox for that. It does not replace one.

Two agents, at tested versions

Claude Code and Codex. On another version of either, the report still runs and marks every result assumed. Other agents are not analysed.

An approval is not a cage

Approvals stop an agent using Curb to change your settings. They do not stop an agent that scans the disk itself. Only its sandbox and deny rules do, and installing those is what the fixes are for.

A passed test is narrow

It covers that exact file, those four methods, that launch and that moment. An attempt the agent declined, or a prompt stopped, counts as inconclusive, never as blocked.

It cannot say what an agent needs

Curb reports what was seen. Not seen is never treated as not needed, and nothing is restricted for you.

A developer can undo user settings

Without device management, Curb cannot stop someone removing a rule on their own machine. It reports the drift, and can export the policy for device management to deliver.

A signature is not authorship

You, or anything running as you, can still use the signing program inside an agent session. It labels agent commits. It cannot tell who drove the session.

The tested versions, and what is not checked

Curb is free, in the open-source client

No account for anything on your own machine. The team features need a Flanner Mesh account, and stay free when its trial ends.

flanner curb map

New to flanner? Install it first with uv tool install flanner. Read the docs