Cup'n'String
Join Waitlist

© 2026 Cup'n'String

All Guides/macOS Packet Filter (pf) Guide
MA

macOS Packet Filter (pf)

Integration & Setup Manual

macOS pf Firewall Integration Guide

Overview

Cup’n’String leverages the native macOS Packet Filter (pf) firewall. Rather than installing heavy third-party VPN overlays, the agent programs pf rule changes directly to restrict unauthorized AI agent connections.

Support level

Kernel-Level Enforcement

What Cup’n’String detects

  • macOS packet filter configuration state
  • Active pf anchor rules and tables
  • Configuration drift from administrative policy

What it governs

  • Outbound connection blocks for unauthorized ports/protocols
  • Host-level socket isolation rules
  • Fail-closed security overlays for network traffic
  • Enforce default-deny rules for unapproved external model gateways
  • Restrict outbound traffic from AI agent CLI tools to the local proxy port
  • Enable continuous drift scanning to revert manual ruleset tampering

Setup outline

  1. Install the Cup’n’String desktop agent on macOS.
  2. The agent installs a system daemon that coordinates rule sets under pfctl.
  3. Policy decisions are applied via anchors without interfering with other system rules.

Verification

Attempt to access an unauthorized model host via curl and verify that the connection fails immediately due to a firewall block.

Troubleshooting

Verify the packet filter service is enabled using sudo pfctl -s info.

Known limitations

Requires administrator/root privileges during agent installation to load pf rule changes.

Integration Info

Support LevelKernel-Level Enforcement
CategoryFirewalls
Setup ComplexityMedium
Governed Safeguards
Network

Links

Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.

Supported Environments Matrix