Community release · Local posture
Local AI Software and MCP Posture Scanning for Mac
See what AxLoop Community v0.2.0 scans locally on Apple Silicon Macs, how it handles AI software and MCP posture evidence, and the preview's current limits.
AxLoop Community v0.2.0 gives Apple Silicon Mac users a local, explicit way to inventory supported AI software, inspect known MCP configuration, review evidence-backed findings, and keep scan history without enrolling in a hosted service.
Preview status
AxLoop Community v0.2.0 is a publicly downloadable Mac Apple Silicon preview. It was published September 6, 2026. It runs explicit local scans and does not install a background service or provide hosted enrollment, upload, or synchronization.
Local AI posture starts with a defensible inventory
AI software on a developer laptop is no longer just a single chat application. A Mac may contain desktop assistants, coding tools, command-line agents, and MCP client configuration that connects those products to local or remote tools. Before a team can govern activity across a fleet, an owner needs a smaller and more immediate answer: what is present on this machine, what evidence supports that answer, and what is outside the scanner's coverage?
AxLoop Community v0.2.0 addresses that first layer with an explicit local posture scan. It creates a small AI-product inventory, inspects known MCP configuration, and presents findings with the evidence used to reach them. It does not claim to observe live agent activity or continuously monitor the Mac.
What the v0.2.0 workflow does
- The owner opens the local workspace. The Homebrew-installed axloop-crawler open command starts a loopback browser interface. The terminal process must remain running while the interface is in use.
- The owner starts the scan. A first scan is explicit rather than automatic. Progress, retry state, and coverage limitations remain visible.
- The scanner builds local inventory. The preview checks for five officially supported AI products and performs partial discovery of dormant command-line tools. This is a bounded product list, not universal AI-software discovery.
- The scanner inspects known MCP configuration. It checks supported configuration paths and parses recognized MCP declarations where possible. Parsing and path coverage are partial, so an empty result is not proof that no MCP configuration exists elsewhere.
- The owner reviews findings. Inventory items and posture findings can be opened to inspect the underlying evidence and known coverage limits.
Evidence, owner review, history, and drift
The useful unit is not a generic warning. Each finding is intended to remain connected to the local evidence behind it so the owner can review what the scanner observed before treating it as fact. That matters when configuration can be duplicated, generated, stale, or stored outside the paths the preview understands.
Scan results are retained in a local SQLite database. History makes previous scans available after the application is reopened, allowing the owner to compare scans and inspect drift over time. This is local historical posture—not continuous event collection—and changes only become visible when another scan is explicitly run.
The preview keeps the operating boundary local
Local-first does not mean invisible or automatic. The owner launches the process, starts each scan, reviews the evidence, chooses whether to export, and stops the process with Ctrl-C. Closing the browser tab alone does not stop the local server.
What “posture scanning” means in this release
In v0.2.0, posture is a narrow inspection layer around supported AI-product presence, known MCP configuration, evidence quality, and change across scans. The release can help answer questions such as:
- Which officially supported AI products were detected on this Mac?
- Which recognized MCP declarations were found in supported paths?
- What evidence supports each inventory item or finding?
- What changed between explicit scans?
- Which coverage limitations should qualify the result?
That is useful groundwork, but it is intentionally smaller than a complete endpoint security scanner, software asset-management system, or runtime observability agent.
Current gaps are part of the product contract
The v0.2.0 preview should be evaluated by what it proves and by what it does not yet cover. The current boundaries include:
- Five officially supported products. Other AI applications may not be identified.
- Partial dormant CLI discovery. Installed command-line tools that are not running or are stored in unexpected locations may be missed.
- Partial MCP parsing and path coverage. Unsupported formats, generated configuration, and alternate locations may remain unseen.
- No dedicated filesystem-posture rule family. The preview does not claim broad inspection of AI-accessible files and directories.
- No dangerous-command rule family. It does not classify every command an agent or MCP tool could execute.
- No package-posture rule family. It is not a general dependency, vulnerability, or package-integrity scanner.
- No macOS-permission rule family. It does not provide complete analysis of privacy permissions, entitlements, or operating-system controls.
- No credential-scope rule family. It does not map the effective reach of tokens, keys, sessions, or delegated access.
- No HTML export. Export is sanitized NDJSON rather than a polished standalone report.
These limits make negative findings appropriately modest: “not detected within current coverage” is more defensible than “not present.”
Posture first; activity and fleet governance later
Local posture is one layer in a larger operating model. It can establish a reviewable inventory and show configuration drift, but it cannot reveal which tools were called, which data moved, whether a permission was exercised, or how behavior changes across many devices.
Dynamic activity observation and fleet governance remain later layers. Those layers require different evidence, identity, policy, enrollment, aggregation, and approval boundaries. AxLoop Community v0.2.0 should not be described as already delivering them.
Publicly downloadable preview—not an implementation-source claim
The September 6 release is a Mac-only Apple Silicon preview. The public repository contains distribution materials, documentation, release metadata, tests, and downloadable artifacts; it does not publish the application implementation source. For that reason, Community preview and publicly downloadable are accurate descriptions. Calling the implementation open source would overstate what the repository currently provides.
Existing Mac mini install, scan, history, export, and upgrade checks passed before release. Clean-machine acceptance, Linux and Windows downloads, a notarized installer, activity capture, and hosted synchronization are not claimed for v0.2.0.
Frequently asked questions
It performs an explicit local scan for a small supported inventory of AI products and known MCP configuration, then presents evidence-backed findings and visible coverage limits in a browser interface on the same Mac.
No. The v0.2.0 preview does not install a background service. The user starts the local interface from Terminal, explicitly runs a scan, and stops the foreground process when finished.
No hosted account, enrollment, or synchronization is available in this preview. Scan history is stored in a local SQLite database, and the user can export sanitized NDJSON evidence.
The public repository contains Community distribution materials, documentation, release metadata, tests, and downloadable artifacts. It does not publish the application implementation source, so publicly downloadable is the accurate description for this preview.
No. v0.2.0 is a local posture-scanning layer. Dynamic activity observation and fleet-wide governance remain later layers, not capabilities claimed for this preview.
Primary public sources
Release status, installation behavior, local-data boundaries, and acceptance limits were checked against the public AxLoop Community materials on September 7, 2026.
- AxLoop Community public repository and README
- AxLoop Community v0.2.0 release
- AxLoop Community changelog
- Community release and local-data guide
Start with evidence you can inspect.
Download the Community preview to inspect supported local AI software and known MCP configuration on an Apple Silicon Mac, with explicit scans and owner-controlled history.
Explore the broader AxLoop product direction