Dev.to Security 🔐 Cybersecurity 👁 0 📖 4 min read

How to Catch Rogue LLM Agents on a Local Machine?

As a security guy, I kept asking myself what an AI agent does on my machine apart from answering my questions. Can it read my secrets? Which IPs and countries does it talk to? What files can it reach? What processes doe

How to Catch Rogue LLM Agents on a Local Machine?

As a security guy, I kept asking myself what an AI agent does on my machine apart from answering my questions.

Can it read my secrets? Which IPs and countries does it talk to? What files can it reach? What processes does it start? Can I stop it if it does something I don't like?

I could not find one tool that shows all of that in one place. So I decided to make my own, so meet Topgent.

Topgent - main view

What is Topgent

List of the detected agents
The name is top plus agent. top shows the running processes on Linux and macOS. Topgent monitors real behaviour of the AI agents on your local machine.

For each agent it shows the files and credentials it can reach, the networks and countries it connects to, the processes it starts, and the model it uses. Then it gives the agent a risk grade, and you can stop it.

It is old school on purpose. Detection and scoring are deterministic rules, and I chose not to have any LLMs involved. It runs locally and collects metadata only.

Example of the Blast Radius

How does an OS tell a process from an agent?

It doesn't. To the OS, Claude Code is a process like any other, with a PID (Process Identifier number), an owner, a path and some network sockets. There is no "agent" flag for OS.

So topgent looks at the executable's identity and where it was installed.

Three questions

Most tools mix these up:

  • Declared: what the agent says it can do
  • Observed: what it has actually done
  • Reachable: what it could do right now

Example: your SSH key. If an agent never touched it, a tool that only watches events sees nothing and the agent looks clean. But the agent could still read that key any time it wants. Topgent shows that as reachable. It never opens the key to test it. It asks the OS whether the account is allowed to read that file.

An agent is declared critical

Why Rust

Topgent reads OS data like socket tables, audit logs, config files. Memory safety matters when you use that data and parse it. The parsers have 11 fuzz targets(OSS-Fuzz), and trufflehog, gitleaks, osv-scanner and semgrep run on every push to ensure we catch some obvious security issues.

Topgent itself runs unprivileged, and there is an optional packet capture helper that needs a privilege, and it stays off until you turn it on.

Pitfalls so far

1. I didn't want another antivirus. Topgent reports first and acts only when you ask. When you stop a process, it rechecks the PID and start time right before signalling, so it never kills a reused PID by accident.

2. Three operating systems have three different ways to get security events. Linux has audit, macOS and Windows have their own, and none of them share access easily. Linux has been the least painful. On Windows I can't check file readability yet, so there are no reachability findings there, and a Windows score is not comparable with a Linux one.

3. How much detail to show. The operating system reports a huge amount of detail, and most of it is noise. Nobody wants to read thousands of lines to find one problem. So Topgent shows a simple risk grade first. If you want to know why an agent got that grade, one click shows the evidence behind it.

4.Short-lived processes. Topgent looks at the machine in snapshots, like taking a photo. In my tests it found every process that stays running, but it could not find the quick ones. If a process starts and exits between two snapshots, it never appears in either photo. An agent can run a quick command and be gone before Topgent looks. That is why I want eBPF on Linux, which watches events as they happen instead of taking photos. I am planning to release this soon.

eBPF, in simple words

eBPF lets you run small programs inside the Linux kernel after a safety check. You can watch process starts and connections as they happen. I am planning to add it in the next release to catch short-lived processes and look inside containers.

No proxy

Many tools inject themself between the agent and the user. I decide to go the other way and work with the OS. Topgent looks into the interaction between the agent and the OS. As mentioned Topgent can also capture network packets (headers only).

Where it is now

v0.5.1 works on macOS, Linux and Windows. Nineteen agent families are defined, including Claude Code, Codex CLI, Gemini CLI, Aider, OpenHands, Goose, OpenCode, Cursor, Ollama and Cline. Some are verified per platform and the README table shows which.

Releases are unsigned for now. I also need to get a macOS developer ID and a paid Apple account.

The tool is Apache-2.0. I also plan an enterprise version for teams that need one view of all agents.

Try it

I would appreciate your honest feedback. If you want to contribute or work on this together, I am happy to collaborate. Windows and macOS event visibility is where I need the most help.

How do you spot and stop a rogue AI agent on your machine?
https://github.com/farikonsec/topgent

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.