
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@node9/proxy
Advanced tools
Node9 is the execution security layer for the Agentic Era. It encases autonomous AI Agents (Claude Code, Gemini CLI, Cursor, MCP Servers) in a deterministic security wrapper, intercepting dangerous shell commands and tool calls before they execute.
While others try to guess if a prompt is malicious (Semantic Security), Node9 governs the actual action (Execution Security).
Node9 initiates a Concurrent Race across all enabled channels. The first channel to receive a human signature wins and instantly cancels the others:
[Y/n] prompt for manual proxy usage and SSH sessions.Node9 doesn't just "cut the wire." When a command is blocked, it injects a Structured Negotiation Prompt back into the AIβs context window. This teaches the AI why it was stopped and instructs it to pivot to a safer alternative or apologize to the human.
Security posture is resolved using a strict 5-tier waterfall:
NODE9_PAUSED=1).node9.config.json).~/.node9/config.json).npm install -g @node9/proxy
# 1. Setup protection for your favorite agent
node9 addto claude
node9 addto gemini
# 2. (Optional) Connect to Slack for remote approvals
node9 login <your_api_key>
# 3. Check your status
node9 status
| Mode | Target | How it works |
|---|---|---|
| Hook Mode | Claude, Gemini, Cursor | node9 addto <agent> wires native pre-execution hooks. |
| Proxy Mode | MCP Servers, Shell | node9 "npx <server>" intercepts JSON-RPC traffic. |
| Manual Mode | You | node9 rm -rf / protects you from your own typos. |
node9.config.json)Rules are merged additiveβyou cannot "un-danger" a word locally if it was defined as dangerous by a higher authority (like the Cloud).
{
"settings": {
"mode": "standard",
"enableUndo": true,
"approvers": {
"native": true,
"browser": true,
"cloud": true,
"terminal": true
}
},
"policy": {
"sandboxPaths": ["/tmp/**", "**/test-results/**"],
"dangerousWords": ["drop", "destroy", "purge", "push --force"],
"ignoredTools": ["list_*", "get_*", "read_*"],
"toolInspection": {
"bash": "command",
"postgres:query": "sql"
}
}
}
Node9 is currently building Shadow Git Snapshots. When enabled, Node9 takes a silent, lightweight Git snapshot right before an AI agent is allowed to edit or delete files. If the AI hallucinates, you can revert the entire session with one click: node9 undo.
node9 check exits immediately / Claude is never blocked
Node9 fails open by design to prevent breaking your agent. Check debug logs: NODE9_DEBUG=1 claude.
Terminal prompt never appears during Claude/Gemini sessions
Interactive agents run hooks in a "Headless" subprocess. You must enable native: true or browser: true in your config to see approval prompts.
"Blocked by Organization (SaaS)" A corporate policy has locked this action. You must click the "Approve" button in your company's Slack channel to proceed.
node9 addto claude | gemini | cursor)Node9 Pro provides Governance Locking, SAML/SSO, and VPC Deployment. Visit [node9.ai](https://node9.ai
FAQs
Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and keep every action on the record.
The npm package @node9/proxy receives a total of 965 weekly downloads. As such, @node9/proxy popularity was classified as not popular.
We found that @node9/proxy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.Β It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.