Get the latest tech news

Fine-grained HTTP filtering for Claude Code


Default‑deny HTTP(S) for dev tools and AI agents. Script rules in JS or shell, log every request, and keep egress within your policy.

RiskExampleAgents performing destructive actionsDeleting your databaseAgents leaking sensitive informationExposing API keys or credentialsAgents operating with more authority than desiredPushing straight to main instead of opening a PRAgents may transgress accidentally (user misinterpretation) or intentionally (prompt injection). In our case, they're imprecisecentralized, anycast load balancers power much of the internet and require constant maintenanceIPs change randomly and they're not a part of a service's implicit "contract". Optionally, you may redirect all traffic to the proxy server, otherwise you will need to take care in ensuring HTTP_PROXY is set in your environments and all of your web-faring applications respect it.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Claude Code

Claude Code

Related news:

News photo

OpenAI's new GPT-5 Codex model takes on Claude Code

News photo

Anthropic's Claude Code runs code to test if it is safe – which might be a big mistake

News photo

Using Claude Code to modernize a 25-year-old kernel driver