TraceBrake is here. Foreman Agent Safety has a new name; the project, safety model and open-source history continue.

Local-first Agent safety for Windows

Every agentgets power.Give it brakes.

TraceBrake is the human-controlled safety broker and black box for AI agents. It watches behaviour, records what matters and puts a deliberate control point between autonomous software and sensitive actions.

  • Runs locally
  • Windows 10/11
  • GPL-3.0
  • No account or telemetry
TraceBrake Interface illustration
TRACEBRAKEEXAMPLE DATA
01Request to review
02Connected agents
YouDecision authority
REVIEW REQUIRED

An agent wants to change a protected file.

Check the target and proposed action before deciding.

Agent
Example coding assistant
Action
Write configuration
State
Waiting for your decision
Illustrative layout · example data · not connected to your machine

SEE EVERY AGENT

GATE EVERY ACTION

KEEP THE HUMAN IN CONTROL

It’s all about the brakes

The permission prompt runs inside the agent.
TraceBrake does not.

An agent's permission prompt is code in the agent's own process, governed by the agent's own settings, and one flag turns it off. TraceBrake is a separate process. It does not read those settings and does not need the agent's cooperation to see it or stop it. The Agent Handbrake spec calls that a second brake and sets out four properties it has to have.

01

A separate mechanism, outside the agent

02

A stop that is a floor, not a request

03

The agent cannot release it

04

A present human must

Five scenarios

1 / 5

Described, not recorded. Each names the mechanism in the source.

  1. 01 · A separate mechanism

    You turned the permissions off. The brake did not notice.

    An agent runs in skip-permissions mode and fans out: shells spawning shells, a compiler, git, a script that outlives its turn. TraceBrake watches from outside the agent. Every child is attributed to the harness that spawned it, whether or not the agent knows TraceBrake exists.

    How: process-tree attribution by ancestry; orphans and hung children flagged; per-agent escalation through Watch, Alert, Alarm, Emergency. No flag, wrapper or plugin required.

  2. 02 · A floor, not a request

    The stop does not travel through the pipe.

    A desktop action stream is mid-batch. You hit STOP. Every pending action is rejected, not paused. Held keys and buttons are released so a half-finished drag cannot complete. The input sidecar is terminated, not asked. None of that rides the same channel the actions rode.

    How: the halt is an access-controlled memory-mapped flag plus BlockInput, a synthetic release-all and TerminateProcess; the sidecar re-reads the flag before every injected input; a panic epoch refuses anything approved before the stop. Latency under a flooded capture channel is designed for and listed as a still-open on-device measurement.

  3. 03 · The agent cannot release it

    It asked nicely. Then it asked as someone else.

    The harness calls acknowledge_alert on a Critical finding: refused. It asks for kill authority over its own children: there is none to grant. It reconnects claiming another harness's name: the name changes where a question is sent, never what is authorised.

    How: High and Critical acknowledgements are rejected at the tool; killing is an operator action in the UI; self-declared identity is advisory only, never an input to authorisation.

  4. 04 · A human must

    Release needs a face, not a token.

    The stop is on. A process holding your session, your cookies and your bearer token tries to resume. It cannot. Resuming goes through the same presence gate as the most sensitive desktop actions: Windows Hello or a FIDO2 key, a thing a program running as you cannot satisfy on its own.

    How: panic resume is routed through PresenceGuard, the same gate that binds desktop computer use; when no authenticator is enrolled the gate fails closed rather than open.

  5. 05 · Sight before the pull

    You see it before you stop it.

    A new MCP server appears in an agent's config overnight. TraceBrake baselined the set yesterday and raises it this morning. Opt in, and it reads the server's tool descriptions and flags "ignore previous instructions" hiding in one of them. You pull the brake having looked.

    How: config-only MCP inventory with no network access; an opt-in tool-description injection scan that never launches a stdio server; an append-only event log with ordering integrity.

It’s all about the brakes

TraceBrake does not yet claim conformance to its own spec. The spec says so. Plain-language version.

Why TraceBrake

AI moves at machine speed.
Accountability shouldn’t disappear.

Coding agents can launch processes, change tool configuration, handle credentials and drive browsers or devices. Most actions are useful. Some are stuck, surprising or far outside the operator’s intent.

Conventional antivirus sees isolated commands. Agent harnesses see only their own task. TraceBrake joins the context: which harness acted, how its behaviour is changing, what it is trying to reach and whether a person is actually present.

01

Orphaned shells and hung update processes

02

Risky commands without task attribution

03

Silent MCP and permission drift

04

Computer use without a shared safety boundary

One local control plane

Observe the whole system.
Intervene where it counts.

TraceBrake combines endpoint signals, harness identity and operator authority without sending your activity to a hosted service.

01

Behaviour engine

Risk is a pattern, not one scary command.

Attribute process trees to the harness that spawned them, detect hangs and orphans, and escalate behaviour through Watch, Alert, Alarm and Emergency.

Watch Alert Alarm Emergency
02

Unified broker

One audited route to the outside world.

Broker browser and opt-in Android/ADB actions through a bounded surface, regardless of which authorised model or harness is driving.

03

Human authority

Presence is a security signal.

Presence Lock and per-harness trust settings distinguish attended work from actions that should ask, hold or stop when the operator is away.

OPERATOR PRESENCERequired for sensitive action
04

Black box

Evidence before explanation.

Keep an exportable local event history with source attribution, severity and the context needed to reconstruct what happened.

05

Vault

Secrets go to destinations—not agents.

Domain-bound credential resolution lets an approved executor fill a live destination without returning the secret to the requesting harness.

06

AI checks AI

A second harness can challenge the first.

Route concerning activity and attributed hand-offs to another connected model while keeping the operator as the final authority.

The control loop

Fast when it’s routine.
Deliberate when it matters.

01
A

Attribute

Connect the action to a harness, process tree and task episode.

02
R

Read context

Combine the command, target, trust level, behaviour and presence state.

03
!

Decide

Allow routine work, ask the operator, or refuse a bounded broker action.

04
T

Trace

Record the outcome so later review starts with evidence, not guesswork.

An honest boundary: TraceBrake is safety visibility and a control point for mediated actions—not a Windows sandbox. A process already running as your user may retain the same underlying access as you.

TraceBrake behaviour dashboard showing per-agent escalation metrics

Open by design

Trust the controls.
Inspect the code.

The current TraceBrake alpha is open source under GPL-3.0-or-later. It runs locally on Windows, requires no account and sends no product telemetry.

Runtime
.NET / WPF
Platform
Windows x64
State
Local only
Stage
Alpha

TraceBrake is here

Autonomy needs accountability.

Formerly Foreman Agent Safety. Same mission, clearer name: give powerful agents accountable brakes.

Follow development on GitHub