Skip to main content
All insights

What left the machine

aiossecurity

I run 4 AI coding CLIs side by side. Until this week I could not tell you what any of them had sent off my machine.

That is a bad position for somebody who tells buyers to ask for the payload. So I built the thing that answers it for me first.

What it is

The AI Control Panel is a web page that runs on my own machine and nowhere else. It covers Claude Code, Codex, Antigravity and Grok. It does not wrap the CLIs and it does not sit between me and the terminal.

Each CLI already writes files about its own sessions, and the panel reads those files and shows me what is open and what is waiting on me. After a reboot it lists the sessions that were interrupted and reopens the ones I pick.

Cost, at list price

The usage page reads Claude Code's transcripts and prices every request at list price, then rolls it up by project, skill, agent, model and hook for today, 7 days or 30 days. I can tie a stretch of work to a ticket by starting the prompt with the ticket number so the cost lands on the job that caused it.

That is the page I open when one task eats a third of the week.

The outbound list

The Egress page lists every tool call that says it sends something off the machine. A git push. A pull request or a deploy. An upload. A write through one of my own tool scripts or through an MCP server.

A host or a git remote it has not seen in the last 2 days shows up amber on the home page.

What it does not prove

These are attempts, not proof of what left. The panel reads what a tool call said it was going to do and it does not watch the network, so a command that lies about itself gets believed. I am not calling that an audit. It is a list I did not have a week ago, and it is where an audit would start.

Cost and the outbound list come from Claude Code only today. The other 3 CLIs show their sessions, tokens and turns. Their tool calls are not in the list yet.

Where it stands

The first commit was September 19 and the release notes list 36 merged pull requests since. The panel is .NET 10, the usage engine is Python with nothing outside the standard library, and the session watcher is PowerShell. It listens on loopback only.

I built it because I needed the answer on my own machine before I asked anyone else the question.

If you run agents anywhere with an audit requirement, ask it of your own setup. What did it send, and where is the list?

Have a Project in Mind?

Every project starts with understanding the problem. Tell us yours.