Back to News
RSS feedgithub.com

agentcap Monitors AI Coding-Agent Activity with eBPF

Summary

agentcap is a Linux observability project for AI coding agents that records activity at the kernel level with eBPF and exposes per-agent Prometheus metrics for Grafana. It requires no agent SDK or code changes and can attach to agents that are already running. The collector attributes child processes to the agent that launched them, so commands such as bash or curl appear under the originating agent. It reports executed binaries, DNS domains, destination ports, opened files with read/write mode, CPU time, network bytes, file I/O, process churn, and probe health. OpenClaw, Claude Code, Codex, Gemini CLI, aider, and other agents are included through configurable process-name prefixes, with custom agents supported by editing the watch list. The BPF probe combines tracepoints, BPF-LSM hooks, and fexit programs; a kernel LPM trie matches agent prefixes, while inherited process trees preserve attribution. Lifecycle events use a ring buffer and high-rate counters are polled once per second. DNS visibility covers direct port-53 traffic and systemd-resolved varlink lookups, but DoH and DoT expose only their network connection, not the domain. Cardinality is capped for labels such as tools, domains, ports, and file paths. The project provides a local Prometheus endpoint on port 9464, Grafana dashboard import instructions, and an optional Docker demo. BPF-LSM, BTF, and compatible kernel support are required for full operation; if BPF-LSM is unavailable, the probe reports itself as down instead of crashing.