v2.8.1
A follow-up to the v2.8.0 agent-API-egress default: an explicit --allow-host
list no longer cuts off the agent's own API.
Backward compatible: every pre-2.8.1 .ai-jail keeps working.
Fixed
-
The default agent API host is unioned with
--allow-host, not suppressed
by it (#156). In v2.8.0 the automatic API-host default only applied when
--allow-hostwas empty, soai-jail --allow-host github.com claudereached
github.combut silently droppedapi.anthropic.comand left Claude unable
to talk to its API — surprising, and inconsistent with the toolchain-registry
default, which already unions onto an explicit--allow-hostlist. The agent
default now behaves the same: adding a host extends what the agent can reach
instead of cutting off its own API, soai-jail --allow-host github.com claudereachesgithub.comandapi.anthropic.com. Neither automatic
default (agent API host or registry hosts) is gated on--allow-hostbeing
empty any more — only on the asserted network posture.The verbatim "only this list, nothing automatic" mode is unchanged and
explicit:ai-jail --no-network --allow-host github.com claudecomposes to
filtered egress withgithub.comonly.--no-networksets the posture,
which disables both automatic defaults, while a non-empty allow-list keeps
egress filtered rather than fully offline.--networkand--lockdownkeep
their existing behavior; the sandbox stays deny-by-default throughout.
Checksums (SHA256)
9c5e41b59be8fd65f239252f8d2e03f16a806d76c090bd256948b452b350710b ai-jail-linux-x86_64.tar.gz
ff1f076b2ed8cedffaa78d02c3c5014ed9e3424f70a5f06145475424ce79cedb ai-jail-macos-aarch64.tar.gz
Install
brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail