github akitaonrails/ai-jail v2.8.1

5 hours ago

v2.8.1

A follow-up to the v2.8.0 agent-API-egress default: an explicit --allow-host
list no longer cuts off the agent's own API.

Backward compatible: every pre-2.8.1 .ai-jail keeps working.

Fixed

  • The default agent API host is unioned with --allow-host, not suppressed
    by it (#156).
    In v2.8.0 the automatic API-host default only applied when
    --allow-host was empty, so ai-jail --allow-host github.com claude reached
    github.com but silently dropped api.anthropic.com and left Claude unable
    to talk to its API — surprising, and inconsistent with the toolchain-registry
    default, which already unions onto an explicit --allow-host list. The agent
    default now behaves the same: adding a host extends what the agent can reach
    instead of cutting off its own API, so ai-jail --allow-host github.com claude reaches github.com and api.anthropic.com. Neither automatic
    default (agent API host or registry hosts) is gated on --allow-host being
    empty any more — only on the asserted network posture.

    The verbatim "only this list, nothing automatic" mode is unchanged and
    explicit: ai-jail --no-network --allow-host github.com claude composes to
    filtered egress with github.com only. --no-network sets the posture,
    which disables both automatic defaults, while a non-empty allow-list keeps
    egress filtered rather than fully offline. --network and --lockdown keep
    their existing behavior; the sandbox stays deny-by-default throughout.

Checksums (SHA256)

9c5e41b59be8fd65f239252f8d2e03f16a806d76c090bd256948b452b350710b  ai-jail-linux-x86_64.tar.gz
ff1f076b2ed8cedffaa78d02c3c5014ed9e3424f70a5f06145475424ce79cedb  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.