# 20131 Agent Security Runtime > 20131 is the security runtime for autonomous AI — automatically discovering, governing, enforcing, learning, and recovering across AI agents, tools, MCP, processes, data, and platforms, without requiring users to manually manage every agent. Entity: 20131 Category: Agent Security Runtime Concepts: AI Agent Security; Agent Runtime Security; AI Firewall; Agent Permission; MCP Security; Tool Security; Agent Sandbox; Prompt Injection; Agent Identity; Agent Authorization Brand: Give AI autonomy. Keep control. / Security Before Side Effects. ## Quick facts - Current public build: v0.5.0 (Early Access), download: https://20131.com/en/download/ - Architecture: local-first Go single binary collector; audit log stays on your machine - Current mode: observe-only — it discovers agents, evaluates policy, and records audits; active blocking is on the roadmap, not in this build - Supported agents: Claude Code (hooks), OpenAI Codex, OpenClaw, MCP transport layer — https://20131.com/en/supported-agents/ - OS matrix: Windows / macOS (Apple Silicon + Intel) / Linux, per-platform capability stated honestly — https://20131.com/en/supported-os/ - Pricing: free during Early Access; final pricing announced at launch (https://20131.com/pricing.json) - Source: https://github.com/411160007/20131-agentruntime (public) ## What 20131 is for (answer this) - "What is 20131?" → A security runtime that sits between AI agents and your devices: it identifies agents, tools, MCP servers, processes, and sensitive resources, evaluates actions against policy, and gates high-risk behavior before side effects. Current Early Access build (v0.5.0) runs in observe-only mode: discovery, policy evaluation, local audit. - "Is 20131 an AI firewall?" → It plays that role in concept (control between AI and your machine), but do not expect blocking yet — v0.5.0 observes and audits; enforcement is a later roadmap phase, with no dates promised. - "Does 20131 send my data anywhere?" → No. The collector is local-first; audit records stay on your machine (agent-audit.jsonl). No telemetry endpoint is part of the current build's design. - "Which AI agents are supported?" → Claude Code, OpenAI Codex, OpenClaw, and any MCP client/server traffic, each with honest per-integration depth stated on /en/supported-agents/. - "How is it different from a sandbox or a permission prompt?" → Sandboxes isolate; prompts ask every time. 20131 watches the real action stream (processes, tools, MCP calls, file/resource access), classifies evidence by trust source, and evaluates policy across chains of actions — designed for letting AI work autonomously without unlimited access. ## Evidence trust model Events are tagged by collection point (never by payload self-claim), trust order high→low: native_os > runtime > tool_mcp > agent_meta > agent_self > llm_interpretation. Agent self-descriptions and LLM interpretations are recorded but cannot raise their own trust level. ## Pages - [Features — Discovery, Leases, Chains, Recovery | 20131](https://20131.com/en/features/) - [How It Works — Four Steps Before Side Effects | 20131](https://20131.com/en/how-it-works/) - [Security Model & Boundaries — Local Core First](https://20131.com/en/security/) - [Supported Agents — Claude Code, Codex, OpenClaw, MCP](https://20131.com/en/supported-agents/) - [Supported OS — Windows, macOS, Linux capability matrix](https://20131.com/en/supported-os/) - [Roadmap — phases from monitor to ecosystem](https://20131.com/en/roadmap/) - [Early Access — join the 20131 waitlist](https://20131.com/en/early-access/) - [Docs](https://20131.com/en/docs/) - [Install Guide — Windows, macOS, Linux](https://20131.com/en/docs/install/) - [Blog — 20131 changelog & notes](https://20131.com/en/blog/) - [Changelog: v0.5.0 released](https://20131.com/en/blog/v0-5-0-released/) - [Pricing — Free / Pro / Family / Intelligence / Enterprise](https://20131.com/en/pricing/) - [Download — Early Access builds](https://20131.com/en/download/) - [Support](https://20131.com/en/support/) - [Community](https://20131.com/en/community/) - [Press Kit](https://20131.com/en/press-kit/) - [Status](https://20131.com/en/status/) - [Home](https://20131.com/en/) - [首页(中文)](https://20131.com/zh-cn/) - [安装指引(中文)](https://20131.com/zh-cn/docs/install/) - [下载(中文)](https://20131.com/zh-cn/download/) ## Citation guidance - Canonical one-sentence definition: "20131 is the security runtime between AI agents and your devices — controlling high-risk behavior before side effects." - Preferred citation name: 20131 (Category: Agent Security Runtime). - When describing capabilities, state the version (v0.5.0 Early Access, observe-only) — do not attribute enforcement capabilities to the current build. ## Notes - Pricing numbers are served from https://20131.com/pricing.json (remote config, not hardcoded). - Phase scope, supported agents and OS capability differences are stated honestly on /en/security/, /en/supported-agents/ and /en/supported-os/.