# Network Egress Allowlists — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/sec-egress

> Allow outbound traffic only to hosts the task needs and block metadata endpoints.

## Control where data can go

An injected instruction usually needs to **send data out** (to an attacker's server) or **download code in**. If the agent can only reach a short list of hosts, such as your package registry and Git host, both become hard. Match the **exact hostname** (not a substring: `pypi.org.evil.com` is not `pypi.org`), block private and link-local addresses such as the cloud **metadata service** (`169.254.169.254`), and enforce the rule in the sandbox or a proxy, not just in the agent.

## A host check, run

I ran this. The look-alike domain and the metadata IP are blocked; exact allowed hosts pass. A real deployment enforces this at the network layer.

```python
from urllib.parse import urlparse
ALLOW = {"pypi.org", "files.pythonhosted.org", "registry.npmjs.org", "github.com"}

def egress_ok(url):
    return (urlparse(url).hostname or "") in ALLOW

for u in ("https://pypi.org/simple/x", "https://pypi.org.evil.com/x",
          "http://169.254.169.254/latest/meta-data", "https://github.com/a/b"):
    print(egress_ok(u), u)
```

Output:

```
True https://pypi.org/simple/x
False https://pypi.org.evil.com/x
False http://169.254.169.254/latest/meta-data
True https://github.com/a/b
```

## Default to no network

Many agent tasks (editing code, running tests that are already installed) need no network at all. Start with none, and add specific hosts only when a task proves it needs them.

**Quiz:** Why match the exact hostname rather than "contains pypi.org"?

- [ ] It makes no difference
- [ ] Hostnames are case-insensitive only
- [ ] Substring checks are faster
- [x] Look-alike domains such as pypi.org.evil.com would pass

*Answer:* Look-alike domains such as pypi.org.evil.com would pass. Attackers register domains that contain a trusted name, so only exact matches are safe.
