// solutions / ai-tollgate

A flight recorder and customs checkpoint for AI agents

AI Tollgate records everything Claude Code, Cursor, Codex, Gemini CLI and other agents do on a developer's machine. It masks secrets before they reach the model, stops dangerous actions, and keeps a tamper-evident log that will stand up to an auditor.

One binary. No admin rights, no cloud. Install it and it's already working. Secrets never leave the machine: keys and tokens are swapped for placeholders in the request to the model and restored in the response, so the agent never notices. Every agent action is written as an event to an immutable, hash-chained log. Instead of a hundred settings, you get three modes: Silent, Smart and Strict.

AI Tollgate: the main console screen with protection mode, today's stats and events that need attention
// Overview: one page that tells you whether everything is fine or you need to step in

// what it solves

Your AI agent already has a developer’s permissions. The question is what it does with them, and who can see it

Agents are handed entire repositories, they read secrets and reach out to the network, prompt injection can turn them against you, and almost nobody has a log of their actions they can actually trust. Here are six problems companies are already running into.

1. Secrets leak into LLMs

Developers feed agents entire repositories, .env files, tokens, keys and customer data included. All of it ends up in LLM providers’ logs, and nobody knows how much has already leaked.

What Tollgate does. A local gateway sits between the agent and the model API. Secrets are detected by rules (RE2 regular expressions plus entropy analysis) and replaced with BB_SECRET_… tokens right in the request, then restored in the model’s response. Tool calls keep working and the user is never asked to confirm anything. The toll audit command shows within a minute which secrets your agents have already seen, by scanning transcripts of sessions that ran before the gateway was installed.

2. Nobody can say what the agent did

The agent deleted a branch, shipped broken code to production or pulled data out, and there’s no log. Questions from legal, auditors, insurers and regulators go unanswered.

What Tollgate does. A full trace of every session: the prompt, files read, LLM calls, commands, edits, network requests, MCP tool calls. The log is append-only, hash-chained and anchored externally. toll verify proves that no event was altered or deleted, and toll incident builds a signed evidence pack that can be verified on any other machine.

3. Agents can be tricked into leaking data themselves

Prompt injection in a README, in an MCP server response, on a web page. Poisoned tool descriptions. An MCP server that quietly updated itself. Packages the model hallucinated and an attacker then registered.

What Tollgate does. A tripwire on incoming content that catches injections and hidden Unicode. Chained rules such as “read a secret, then went to the network” or “saw an injection, then makes an outbound call”. Pinning of MCP tool descriptions. A scanner for MCP servers and skills (heuristics plus AI review). New packages checked against public registries. And decoy secrets that no regex would ever flag, where any use at all is a 100% signal.

4. An agent can break far more than its working folder

rm -rf ~, git push --force main, drop database, kubectl delete namespace, curl … | sh, an attempt to shut down Tollgate itself.

What Tollgate does. A built-in rule set and three protection modes. When the user needs to confirm something, the question and the reason appear in the agent’s own permission dialog, not in yet another pop-up. A runaway breaker stops an agent stuck in a loop firing hundreds of calls a minute. toll undo rolls files back to where they were before the session started.

5. Compliance demands a log you don’t have

The EU AI Act (most provisions apply from 2 August 2026), SOC 2 and ISO/IEC 42001 all call for logging and oversight of AI operations. The budget line already exists. The evidence doesn’t.

What Tollgate does. toll report --days 90 produces an AI usage report for management and auditors: how many sessions, which agents, how many secrets masked, how many actions stopped. toll team serve spins up a self-hosted fleet console that countersigns the logs from every machine.

6. If a security tool gets in the way, it’s gone by day two

Any security tool that slows developers down ends up switched off.

What Tollgate does. Rule number one is to stay out of the way. Right after install it runs in Silent mode: recording and masking only, no prompts. At most three notifications an hour, high or critical only. “Don’t ask again” takes one click. If the Tollgate service fails, the agent keeps working (fail-open). And developers get something out of it too: a session receipt for PRs, line-level agent blame, and session rollback.

// three modes instead of a hundred settings

Switch with one click, no restart

Silent

Records and masks secrets, never asks anything. On by default after install.

Smart

Asks only about actions that can do real damage. Before you switch, the console shows how many times Smart would have interrupted you over the last 30 days.

Strict

Every risky action goes through a human, right in the agent’s own permission dialog.

// who it’s for

One log, a different payoff for every role

DeveloperA personal log of agent sessions, a receipt for PRs, toll why <file>:<line> to see which agent wrote a given line, and one-command rollback of edits.
Head of Engineering, platform teamVisibility across every agent and model on the team without adding friction for developers. Which MCP servers and skills are installed, and whether they’ve been vetted.
CISO, security engineerOutbound secret masking, policy as code in the repository, honeypot testing of agents, and a map of where agents connect.
Compliance, auditA provable log, period reports, signed incident packs, and external anchoring of the hash chain with RFC 3161 timestamps.

// features

Four layers: record, protect, audit, prove

Record: everything the agent does

  • Three sensors, one event schema. The LLM gateway intercepts calls to model APIs, the MCP gateway captures every tool call, and agent hooks record file, command and network activity. Every source is normalized into a single format: file.read, file.write, cmd.exec, net.request, mcp.call, llm.request and so on.
  • Sessions. Every agent run becomes a session with a full timeline. A “lethal trifecta” indicator lights up when the agent has seen private data, read untrusted content and talked to the network.
  • File snapshots. Content-addressed versions before and after every edit, with a unified diff in the console and rollback.
  • Plain-language search, offline and without an LLM: “secrets yesterday”, “commands last 3 days”, “what did the agent do with the payment files on Tuesday”.
  • Network map. Every host agents reached: cloud provider, country, channel (shell, fetch, LLM, MCP) and number of requests.
  • Auto-discovery. toll discover finds every agent, local inference server and MCP config on the machine and shows what’s running unsupervised. Agents that can be connected safely are connected automatically.

Protect: secrets, policies, circuit breakers

  • Reversible secret masking in LLM traffic (HMAC tokenization, key held in memory only), with original values restored in the model’s response, SSE streams included.
  • Policy as code. YAML: the built-in set plus ~/.config/aitollgate/policies.yaml plus <repo>/.aitollgate/policies.yaml, reviewed in PRs like any other code. Conditions: event type, path globs, command and host regexes, session flags with a time window. toll policy test --mode strict replays your history through the rules and shows how many hits Strict mode would have produced.
  • Native permission dialog. No pop-ups of our own: an ask decision goes to the PreToolUse dialog in Claude Code, Cursor or Grok CLI, with the reason attached.
  • Runaway breaker. More than N calls a minute, and the agent gets a single question and a pause.
  • Package install guard. New packages are checked against npm and PyPI for nonexistent and look-alike names (typosquatting and slopsquatting).
  • Self-protection. Attempts to stop the service, wipe the log or rewrite policies trigger a dedicated rule with critical severity.

Audit: how your agents can be tricked

  • Honeypot. Decoy sets: .env, AWS, GCP and Azure keys, SSH and PGP keys, GitHub, npm, Slack and Stripe tokens, Docker and Kubernetes configs, a crypto wallet, a webhook trap. Observe-only or block mode. “Test all agents” plants decoys in every working directory, and “Run a live test” launches an agent into the trap itself.
  • Leak watch for real keys. Fingerprints of real keys from CLI configs (the keys themselves are never stored), with an alert when one of them leaves the machine.
  • MCP servers and skills. An inventory of everything your agents load. A fast local scan is free; AI review works with an API key from any of six supported providers. Verdict: clean, suspicious or dangerous, with an explanation and a flag if the component has changed since it was last checked.
  • MCP gateway. toll mcp wrap .mcp.json gives you a log of every call, pinned tool descriptions, and detection of rug pulls (a server changing behavior after approval) and tool poisoning.
  • Injection tripwire. Incoming content (web pages, MCP responses) is scanned for “ignore previous instructions”-style commands, requests to send keys, hidden Unicode and ASCII smuggling. The session gets flagged and the next outbound network call needs confirmation.

Prove: a log you can trust

  • Append-only ledger (SQLite) with a hash chain. toll verify checks its integrity.
  • External anchoring. An ed25519-signed witness log and RFC 3161 timestamps. toll team serve adds a second, independent witness.
  • Session receipt. A Markdown card for your PR description: what the agent read and changed, which commands it ran, which hosts it reached, whether it saw secrets, which rules fired, and the log hash.
  • Git integration. Commits get a Blackbox-Session trailer, and toll why <file>:<line> gives you agent blame.
  • Incident pack. toll incident builds a signed zip of the session’s events, and toll incident verify <zip> checks it anywhere.
  • Period report. toll report --days 90 for management and auditors.

For teams

  • toll team serve is a self-hosted fleet server: one console for every machine, log countersigning, regression detection.
  • Machines join with a single token. No SaaS, and your data never leaves your perimeter.

// how it works

A single static binary. No admin rights, no cloud

  • One binarytoll is written in Go without cgo and runs on Linux, macOS and Windows. It bundles the daemon, a system tray icon, a local console at 127.0.0.1:7355, the LLM gateway, the MCP gateway, agent hooks and the CLI.
  • No-admin installAutostart is set up at the user level (XDG autostart, LaunchAgent, HKCU Run). One command, toll install, and your agents are connected.
  • Local-firstContent is always scanned locally. Secret values are never written to the log, only their type and count. The only outbound requests are package name lookups against public registries and, if you explicitly turn it on, one RDAP query per host for the network map.
  • Local APIBound to 127.0.0.1, rejects foreign Host headers (DNS rebinding) and Origin headers (CSRF), and requires a token for writes.

// inside the console

Ten tabs: what your agents do, how they’re protected, and how they can be tricked

The console runs at http://127.0.0.1:7355, locally, with no cloud. The left-hand menu has three groups. Monitor (Overview, Activity, Sessions, Network Map) shows what agents are doing. Protect (Agents, Rules) covers which agents are protected and how. Audit (Honeypot, MCP Servers, Skills) checks what agents load and how they can be fooled. Settings sit at the bottom.

Activity: the action feed

A live feed of everything every agent on the machine does: reading and editing files, terminal commands, network requests, MCP tool calls, model requests. Filter chips (All, Flagged, Secrets, Commands, Files, Network, LLM, MCP), plain-language search and real-time updates over SSE. Click a row to open the event card: tool, directory, the rule that fired, the hash in the log chain, raw JSON.

AI Tollgate: the agent action feed with filters and plain-language search.

AI Tollgate: the agent action feed with filters and plain-language search

Every agent run is its own session you can revisit, search and attach to a pull request: the user’s first message as the title, the agent, the model, the project, and counts of secrets and triggered rules.

AI Tollgate: the list of agent sessions.

AI Tollgate: the list of agent sessions

The full timeline of the session in execution order. The “lethal trifecta” indicator is three lights: Saw private data, Read untrusted content, Talked to the network. All three at once is the textbook prompt injection data leak. The “Copy receipt for PR” button copies a Markdown receipt of the session for your pull request description.

AI Tollgate: an agent session card with the lethal trifecta indicator.

AI Tollgate: an agent session card with the lethal trifecta indicator

Network Map

Where your agents go: every external address in the log, LLM gateways, web fetches, networked MCP servers, commands like curl, wget and ssh. The cloud provider (AWS, GCP, Azure, Cloudflare, GitHub, Anthropic and others) is identified offline from IP ranges. If an agent wandered off to a host it has no business with, you’ll spot it in seconds.

AI Tollgate: a map of where AI agents connect.

AI Tollgate: a map of where AI agents connect

Agents: agents and models

Open full screenshot →

Which AI tools are installed on the machine and which of them are being monitored. Tollgate finds them on its own and connects the safe ones automatically: Claude Code, Cursor, Codex, Grok CLI, Gemini CLI, Continue, Aider, Goose, DeepSeek, aichat and more, showing exactly how each one is connected. Local model servers (Ollama, LM Studio, vLLM) are listed too.

AI Tollgate: agents and models under monitoring.

AI Tollgate: agents and models under monitoring

The rules Tollgate uses to decide what to do with an agent action: alert, ask or block. The built-in set covers reading files that contain secrets, access to ~/.ssh and ~/.aws, “read a secret, then sends it to the network”, destructive commands, curl | sh, and attempts to disable Tollgate itself. Each rule shows how many times it fired in the last 30 days. Your own rules live in YAML and get reviewed in the repository’s pull requests.

AI Tollgate: policy rules with alert, ask and block actions.

AI Tollgate: policy rules with alert, ask and block actions

Honeypot: a trap for agents

Open full screenshot →

Fake secrets planted where your agents work: .env, AWS, GCP and Azure keys, SSH and PGP keys, GitHub, npm, Slack and Stripe tokens, Docker and Kubernetes configs, a crypto wallet. The keys are worthless, so any action involving them is a clean signal. “Test all agents” is observe-only, while “Run a live test” launches an agent into the trap itself. Leak watch for real keys from CLI configs is available separately.

AI Tollgate: honeypot decoys for AI agents.

AI Tollgate: honeypot decoys for AI agents

Every MCP server your agents can call, collected from Claude Code, Cursor and Gemini CLI configs and project .mcp.json files. Two levels of checks: Quick scan (free local heuristics) and AI scan (a verdict from the model of your choice, with an explanation across covert execution, exfiltration, deception and prompt injection). The result is clean, suspicious or dangerous. New and updated servers are flagged separately.

AI Tollgate: MCP server inventory and review.

AI Tollgate: MCP server inventory and review

Every skill (SKILL.md) installed for your agents, from plugins, marketplaces and project directories. A skill’s instructions get injected into the agent’s context whenever it triggers, and people install skills and forget about them. Same review flow as MCP: free quick heuristics, AI review with an API key, and clean, suspicious or dangerous verdicts with quoted findings.

AI Tollgate: review of installed agent skills.

AI Tollgate: review of installed agent skills

Everything Tollgate does is controlled by plain toggles: softening hard blocks into questions, package install guard, runaway breaker, secret masking and value restoration in responses, fail-open on gateway errors, notification limits, no-admin autostart, per-agent coverage, log integrity checks. Change something, hit Save, and the daemon applies it within a second.

AI Tollgate: protection, privacy and notification settings.

AI Tollgate: protection, privacy and notification settings

// agent coverage, honestly

We tell you straight where coverage is full and where it’s partial

AgentActions (files, commands, MCP)LLM traffic maskingEnforcement (ask, block)
Claude CodeYes, via hooksYes, via gatewayYes, PreToolUse
CursorYes, via hooksNo, traffic goes to Cursor’s backendYes, via hooks
CodexYes, recordingYes, OpenAI-compatible API via gatewayNo pre-tool hook
Gemini CLIYes, MCP via gatewayNo, traffic goes to GoogleYes, on MCP calls
Grok CLIYes, via hooksNoYes, PreToolUse
Aider, Continue, DeepSeek, aichat, local models (Ollama, LM Studio, vLLM and others)NoYes, OpenAI-compatible traffic via gatewayNo
Any MCP clientYes, via toll mcp wrapNoYes, policies on tool calls
Any other toolNoYes, point its API base URL at the gatewayNo

// principles

Five decisions Tollgate is built on

01

Stay out of the way

Silent mode by default. Every decision was made so the tool doesn’t get uninstalled on day two.

02

No pop-ups of our own

Questions go through the agent’s own dialog, not a separate window that’s annoying and easy to ignore.

03

The product must never become a leak channel

Local-first, secrets are never stored, and none of your agents’ data leaves the machine.

04

A log you can trust

Hash chain, external anchoring, signatures, verification on any machine.

05

Value for developers, not just for security

Receipts, agent blame, session rollback: things developers will use even when security isn’t asking.

// built by AgentOffense

Breaking AI agents is what we do for a living. Tollgate is what we run on our own machines

Our Airlock firewall controls an agent’s tool calls in the moment. AI Tollgate covers more ground: it records everything, masks secrets, tests how your agents can be tricked, and keeps a log an auditor will believe. Want an attacker’s view of your AI agents, or help rolling Tollgate out across your team’s fleet? That’s our day job.

// get in touch

Want Tollgate on your machine, or across your whole team?

Pricing and terms depend on the size of your team, so we work them out individually. Leave your contact details and we’ll get back to you within one business day.

./request_engagement