New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more β†’
Get Started

@node9/proxy

Package Overview
Dependencies
Maintainers
1
Versions
241
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@node9/proxy

The Sudo Command for AI Agents. Execution Security for Claude Code & MCP.

Source
npmnpm
Version
1.0.0
Version published
Weekly downloads
1.4K
-33.22%
Maintainers
1
Weekly downloads
Β 
Created
Source

πŸ›‘οΈ Node9 Proxy

The "Sudo" Command for AI Agents.

NPM Version License: MIT

Node9 is the execution security layer for the Agentic Era. It encases autonomous AI Agents (Claude Code, Gemini CLI, Cursor, MCP Servers) in a deterministic security wrapper, intercepting dangerous shell commands and tool calls before they execute.

While others try to guess if a prompt is malicious (Semantic Security), Node9 governs the actual action (Execution Security).

⚑ Key Architectural Upgrades

🏁 The Multi-Channel Race Engine

Node9 initiates a Concurrent Race across all enabled channels. The first channel to receive a human signature wins and instantly cancels the others:

  • Native Popup: OS-level dialog (Mac/Win/Linux) for sub-second keyboard dismissal.
  • Browser Dashboard: Local web UI for deep inspection of large payloads (SQL/Code).
  • Cloud (Slack): Remote asynchronous approval for team governance.
  • Terminal: Classic [Y/n] prompt for manual proxy usage and SSH sessions.

🧠 AI Negotiation Loop

Node9 doesn't just "cut the wire." When a command is blocked, it injects a Structured Negotiation Prompt back into the AI’s context window. This teaches the AI why it was stopped and instructs it to pivot to a safer alternative or apologize to the human.

🌊 The Resolution Waterfall

Security posture is resolved using a strict 5-tier waterfall:

  • Env Vars: Session-level overrides (e.g., NODE9_PAUSED=1).
  • Cloud (SaaS): Global organization "Locks" that cannot be bypassed locally.
  • Project Config: Repository-specific rules (node9.config.json).
  • Global Config: Personal UI preferences (~/.node9/config.json).
  • Defaults: The built-in safety net.

πŸš€ Quick Start

npm install -g @node9/proxy

# 1. Setup protection for your favorite agent
node9 addto claude
node9 addto gemini

# 2. (Optional) Connect to Slack for remote approvals
node9 login <your_api_key>

# 3. Check your status
node9 status

πŸ›  Protection Modes

ModeTargetHow it works
Hook ModeClaude, Gemini, Cursornode9 addto <agent> wires native pre-execution hooks.
Proxy ModeMCP Servers, Shellnode9 "npx <server>" intercepts JSON-RPC traffic.
Manual ModeYounode9 rm -rf / protects you from your own typos.

βš™οΈ Configuration (node9.config.json)

Rules are merged additiveβ€”you cannot "un-danger" a word locally if it was defined as dangerous by a higher authority (like the Cloud).

{
  "settings": {
    "mode": "standard",
    "enableUndo": true,
    "approvers": {
      "native": true,
      "browser": true,
      "cloud": true,
      "terminal": true
    }
  },
  "policy": {
    "sandboxPaths": ["/tmp/**", "**/test-results/**"],
    "dangerousWords": ["drop", "destroy", "purge", "push --force"],
    "ignoredTools": ["list_*", "get_*", "read_*"],
    "toolInspection": {
      "bash": "command",
      "postgres:query": "sql"
    }
  }
}

βͺ Phase 2: The "Undo" Engine (Coming Soon)

Node9 is currently building Shadow Git Snapshots. When enabled, Node9 takes a silent, lightweight Git snapshot right before an AI agent is allowed to edit or delete files. If the AI hallucinates, you can revert the entire session with one click: node9 undo.

πŸ”§ Troubleshooting

node9 check exits immediately / Claude is never blocked Node9 fails open by design to prevent breaking your agent. Check debug logs: NODE9_DEBUG=1 claude.

Terminal prompt never appears during Claude/Gemini sessions Interactive agents run hooks in a "Headless" subprocess. You must enable native: true or browser: true in your config to see approval prompts.

"Blocked by Organization (SaaS)" A corporate policy has locked this action. You must click the "Approve" button in your company's Slack channel to proceed.

πŸ—ΊοΈ Roadmap

  • Multi-Channel Race Engine (Simultaneous Native/Browser/Cloud/Terminal)
  • AI Negotiation Loop (Instructional feedback loop to guide LLM behavior)
  • Resolution Waterfall (Cascading configuration: Env > Cloud > Project > Global)
  • Native OS Dialogs (Sub-second approval via Mac/Win/Linux system windows)
  • One-command Agent Setup (node9 addto claude | gemini | cursor)
  • Identity-Aware Execution (Differentiates between Human vs. AI risk levels)
  • Shadow Git Snapshots (1-click Undo for AI hallucinations)
  • Execution Sandboxing (Simulate dangerous commands in a virtual FS before applying)
  • Multi-Admin Quorum (Require 2+ human signatures for high-stakes production actions)
  • SOC2 Tamper-proof Audit Trail (Cryptographically signed, cloud-managed logs)

🏒 Enterprise & Compliance

Node9 Pro provides Governance Locking, SAML/SSO, and VPC Deployment. Visit [node9.ai](https://node9.ai

Keywords

ai-security

FAQs

Package last updated on 10 Mar 2026

Related posts