New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more β†’
Get Started

@node9/proxy

Package Overview
Dependencies
Maintainers
1
Versions
241
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@node9/proxy

The Sudo Command for AI Agents. Execution Security for Claude Code & MCP.

Source
npmnpm
Version
1.0.4
Version published
Weekly downloads
1.4K
-33.22%
Maintainers
1
Weekly downloads
Β 
Created
Source

πŸ›‘οΈ Node9 Proxy

The "Sudo" Command for AI Agents.

NPM Version License: MIT

Node9 is the execution security layer for the Agentic Era. It encases autonomous AI Agents (Claude Code, Gemini CLI, Cursor, MCP Servers) in a deterministic security wrapper, intercepting dangerous shell commands and tool calls before they execute.

While others try to guess if a prompt is malicious (Semantic Security), Node9 governs the actual action (Execution Security).

πŸ’Ž The "Aha!" Moment

AIs are literal. When you ask an agent to "Fix my disk space," it might decide to run docker system prune -af.

<<<<<<< dev ======= >>>>>>> main

With Node9, the interaction looks like this:

  • πŸ€– AI attempts a "Nuke": Bash("docker system prune -af --volumes")
  • πŸ›‘οΈ Node9 Intercepts: An OS-native popup appears immediately.
  • πŸ›‘ User Blocks: You click "Block" in the popup.
  • 🧠 AI Negotiates: Node9 explains the block to the AI. The AI responds: "I understand. I will pivot to a safer cleanup, like removing only large log files instead."

⚑ Key Architectural Upgrades

🏁 The Multi-Channel Race Engine

Node9 initiates a Concurrent Race across all enabled channels. The first channel to receive a human signature wins and instantly cancels the others:

  • Native Popup: OS-level dialog (Mac/Win/Linux) for sub-second keyboard dismissal.
  • Browser Dashboard: Local web UI for deep inspection of large payloads (SQL/Code).
  • Cloud (Slack): Remote asynchronous approval for team governance.
  • Terminal: Classic [Y/n] prompt for manual proxy usage and SSH sessions.

🧠 AI Negotiation Loop

Node9 doesn't just "cut the wire." When a command is blocked, it injects a Structured Negotiation Prompt back into the AI’s context window. This teaches the AI why it was stopped and instructs it to pivot to a safer alternative or apologize to the human.

βͺ Shadow Git Snapshots (Auto-Undo)

Node9 takes a silent, lightweight Git snapshot before every AI file edit. If the AI hallucinates and breaks your code, run node9 undo to instantly revert β€” with a full diff preview before anything changes.

# Undo the last AI action (shows diff + asks confirmation)
node9 undo

# Go back N actions at once
node9 undo --steps 3

Example output:

βͺ  Node9 Undo
    Tool:  str_replace_based_edit_tool β†’ src/app.ts
    When:  2m ago
    Dir:   /home/user/my-project

--- src/app.ts (snapshot)
+++ src/app.ts (current)
@@ -1,4 +1,6 @@
-const x = 1;
+const x = 99;
+const y = "hello";

Revert to this snapshot? [y/N]

Node9 keeps the last 10 snapshots. Snapshots are only taken for file-writing tools (write_file, edit_file, str_replace_based_edit_tool, create_file) β€” not for read-only or shell commands.

🌊 The Resolution Waterfall

Security posture is resolved using a strict 5-tier waterfall:

  • Env Vars: Session-level overrides (e.g., NODE9_PAUSED=1).
  • Cloud (SaaS): Global organization "Locks" that cannot be bypassed locally.
  • Project Config: Repository-specific rules (node9.config.json).
  • Global Config: Personal UI preferences (~/.node9/config.json).
  • Defaults: The built-in safety net.

πŸš€ Quick Start

npm install -g @node9/proxy

# 1. Setup protection for your favorite agent
node9 addto claude
node9 addto gemini

# 2. Initialize your local safety net
node9 init

# 3. Check your status
node9 status

πŸ›  Protection Modes

ModeTargetHow it works
Hook ModeClaude, Gemini, Cursornode9 addto <agent> wires native pre-execution hooks.
Proxy ModeMCP Servers, Shellnode9 "npx <server>" intercepts JSON-RPC traffic.
Manual ModeYounode9 rm -rf / protects you from your own typos.

βš™οΈ Configuration (node9.config.json)

Rules are merged additiveβ€”you cannot "un-danger" a word locally if it was defined as dangerous by a higher authority (like the Cloud).

{
  "settings": {
    "mode": "standard",
    "enableUndo": true,
    "approvers": {
      "native": true,
      "browser": true,
      "cloud": true,
      "terminal": true
    }
  },
  "policy": {
    "sandboxPaths": ["/tmp/**", "**/test-results/**"],
    "dangerousWords": ["drop", "destroy", "purge", "push --force"],
    "ignoredTools": ["list_*", "get_*", "read_*"],
    "toolInspection": {
      "bash": "command",
      "postgres:query": "sql"
    }
  }
}

πŸ”§ Troubleshooting

node9 check exits immediately / Claude is never blocked Node9 fails open by design to prevent breaking your agent. Check debug logs: NODE9_DEBUG=1 claude.

Terminal prompt never appears during Claude/Gemini sessions Interactive agents run hooks in a "Headless" subprocess. You must enable native: true or browser: true in your config to see approval prompts.

"Blocked by Organization (SaaS)" A corporate policy has locked this action. You must click the "Approve" button in your company's Slack channel to proceed.

πŸ—ΊοΈ Roadmap

  • Multi-Channel Race Engine (Simultaneous Native/Browser/Cloud/Terminal)
  • AI Negotiation Loop (Instructional feedback loop to guide LLM behavior)
  • Resolution Waterfall (Cascading configuration: Env > Cloud > Project > Global)
  • Native OS Dialogs (Sub-second approval via Mac/Win/Linux system windows)
  • Shadow Git Snapshots (1-click Undo for AI hallucinations)
  • Identity-Aware Execution (Differentiates between Human vs. AI risk levels)
  • Execution Sandboxing (Simulate dangerous commands in a virtual FS before applying)
  • Multi-Admin Quorum (Require 2+ human signatures for high-stakes production actions)
  • SOC2 Tamper-proof Audit Trail (Cryptographically signed, cloud-managed logs)

🏒 Enterprise & Compliance

Node9 Pro provides Governance Locking, SAML/SSO, and VPC Deployment. Visit [node9.ai](https://node9.ai

Keywords

ai-security

FAQs

Package last updated on 13 Mar 2026

Related posts