github akitaonrails/ai-jail v2.6.0

latest releases: v2.6.2, v2.6.1
3 hours ago

v2.6.0

A developer-friendliness release: AI harnesses now start pre-authenticated
by default, so a plain ai-jail <harness> no longer makes the agent log in
again inside the jail. This leans into ai-jail's purpose — an accident-guard for
a trusted-but-fallible agent, not a hard-security boundary (use a disposable VM
for hostile code) — and the docs now say so clearly, with the full list of what
is on by default and how to tighten it down to full --lockdown.

Backward compatible: every pre-2.6.0 .ai-jail keeps working. The one behavior
change is the new default below, which is additive (more works out of the box)
and monotonic (an untrusted project .ai-jail can only disable it).

Changed

  • Agent/harness auth is ON by default (agent_state, previously opt-in).
    A plain ai-jail <harness> now mounts that harness's own credential/state dir
    read-write so it starts pre-authenticated — OAuth tokens persist and refresh,
    and the harness does not re-login each session. Covers claude (~/.claude +
    ~/.claude.json), codex (~/.codex), opencode, crush, kimi (~/.kimi-code),
    gemini (~/.gemini), grok, pi, and others. --no-agent-state restores the
    isolated, logged-out run; --lockdown always disables it (the lockdown gate is
    folded into the capability so every mount, the Landlock wrapper, and the audit
    record stay isolated); browser profiles disable it. Still monotonic — an
    untrusted project .ai-jail may only disable it.

    This reverses the former opt-in #84 stance in favor of the "YOLO mode that
    won't wreck anything outside the project" goal. Read-only still does not stop a
    compromised agent from reading its own token, so this is a deliberate
    convenience default, not a security boundary.

Added

  • Pre-authenticate API-key harnesses too: when agent state is on, the invoked
    harness's well-known API-key env var is copied from the host when set —
    ANTHROPIC_API_KEY (claude), OPENAI_API_KEY (codex),
    GEMINI_API_KEY/GOOGLE_API_KEY (gemini/antigravity), XAI_API_KEY (grok),
    MOONSHOT_API_KEY (kimi). Never persisted to a saved .ai-jail; an explicit
    --env for the same name wins.

Fixed

  • macOS launch regression (#148). v2.5.0 emitted the toolchain cache maps
    (which use SOURCE:DESTINATION) on macOS, where seatbelt cannot express
    alternate destinations — so every default macOS launch failed with "alternate
    map destinations are not supported." The toolchain cache and its default
    registry egress are now correctly Linux-only; macOS returns to its pre-2.5.0
    behavior. (--no-toolchains was the workaround.)
  • A global read-only --map of the project directory no longer forces the
    project read-only (#149).
    A map whose destination is the project dir itself
    is now emitted before the project's own read-write bind, so the working
    directory stays writable; maps of paths inside the project (e.g. --map .git)
    still take precedence as before.
  • --env / --env-from-file now document that their values land on the
    launcher's argv (/proc/<pid>/cmdline, readable by same-user processes, #147);
    use --secret KEY=host for a secret that must stay off argv. A
    descriptor-based fix to keep all such values off argv is tracked as a
    follow-up.
  • crush agent-state now includes ~/.config/crush and
    ~/.local/share/crush (its real config and provider data); ~/.crush alone
    was empty, so crush still re-authenticated.
  • antigravity is now recognized and mapped to ~/.gemini (its OAuth lives
    under ~/.gemini/antigravity-cli and it shares ~/.gemini's Google OAuth).

Docs

  • Reframed the purpose across README, docs/SECURITY.md, and CLAUDE.md:
    ai-jail prevents accidents by a trusted agent (a mistyped rm that would hit
    files outside the project), it is not a defense against a motivated attacker or
    a substitute for a VM. Added a clear "on by default" list and a "turn it down /
    lockdown levels" progression from the friendly default to full --lockdown.

Checksums (SHA256)

edb3aa4e036887186382da181055a5ee1a613d61473ab7dceb95757dca06237b  ai-jail-linux-x86_64.tar.gz
6b760233bf3b3303bd86f109cc10e841cbe844d02dbc9cf8a48ead993cf43b91  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.