# Network Egress Allowlists — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/hi/coding-agent-guardrails/sec-egress

> बाहर जाने वाला traffic सिर्फ़ उन hosts तक allow करें जिनकी काम को ज़रूरत है और metadata endpoints रोकें।

## डेटा कहाँ जा सकता है, यह नियंत्रित करें

Injected निर्देश को आम तौर पर **डेटा बाहर भेजना** (हमलावर के server को) या **कोड भीतर लाना** होता है। Agent सिर्फ़ छोटी hosts सूची, जैसे आपका package registry और Git host, तक पहुँच सके तो दोनों कठिन हो जाते हैं। **सटीक hostname** मिलाएँ (substring नहीं: `pypi.org.evil.com`, `pypi.org` नहीं है), निजी और link-local पते, जैसे cloud **metadata service** (`169.254.169.254`), रोकें, और नियम को सिर्फ़ agent में नहीं बल्कि sandbox या proxy में लागू करें।

## Host जाँच, चलाकर

मैंने यह चलाया। मिलता-जुलता domain और metadata IP रोके जाते हैं; सटीक allowed hosts पास होते हैं। असली deployment इसे network परत पर लागू करता है।

```python
from urllib.parse import urlparse
ALLOW = {"pypi.org", "files.pythonhosted.org", "registry.npmjs.org", "github.com"}

def egress_ok(url):
    return (urlparse(url).hostname or "") in ALLOW

for u in ("https://pypi.org/simple/x", "https://pypi.org.evil.com/x",
          "http://169.254.169.254/latest/meta-data", "https://github.com/a/b"):
    print(egress_ok(u), u)
```

Output:

```
True https://pypi.org/simple/x
False https://pypi.org.evil.com/x
False http://169.254.169.254/latest/meta-data
True https://github.com/a/b
```

## डिफ़ॉल्ट रूप से network नहीं

कई agent कामों (कोड बदलना, पहले से install tests चलाना) को network की बिल्कुल ज़रूरत नहीं। शून्य से शुरू करें, और ख़ास hosts तभी जोड़ें जब कोई काम साबित करे कि उसे चाहिए।

**Quiz:** सटीक hostname क्यों मिलाएँ, "contains pypi.org" क्यों नहीं?

- [ ] कोई फ़र्क़ नहीं पड़ता
- [ ] Hostnames सिर्फ़ case-insensitive होते हैं
- [ ] Substring जाँच तेज़ है
- [x] pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे

*Answer:* pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे. हमलावर भरोसेमंद नाम वाले domains पंजीकृत करते हैं, इसलिए सिर्फ़ सटीक मेल सुरक्षित है।
