Contact us

Email support@macmon.app and we'll get back to you, usually within a few days. It helps to include:

Please don't send your MacMon database. It can contain sensitive details, such as commands your AI agents ran.

Getting started

  1. Move MacMon to your Applications folder and open it. It appears as a shield in the menu bar.
  2. The setup window walks you through each step. Nothing changes until you click:
    • Turn on background checks. This adds a background item that runs a check every 15 minutes, even while the app is closed.
    • Grant Full Disk Access (optional). Only needed to list other apps' privacy permissions.
    • Install the AI agent hook (optional). Records Claude Code and Codex tool calls as they happen.
  3. The first check takes a few minutes. It records your Mac's current state as the baseline, and reads back through the last day of sign-in activity and two weeks of AI agent sessions. Later checks take a few seconds.

Frequently asked questions

What does the color of the menu bar shield mean?

It shows the most serious open alert. A plain shield means there are no open medium or high-severity alerts. A colored shield means there's something to look at. Open MacMon to see what it is. The shield is also tinted if background checks have stopped running.

Does MacMon fix problems or change my settings?

No. MacMon only audits. Each failing check explains why it matters and shows how to fix it, often with a button that opens the right System Settings pane, but you make the change. A monitor that changed settings on its own would be one more thing to audit.

Does MacMon block malware or risky commands?

No. MacMon is a tripwire, not a lock. It records and alerts. It never blocks a command, an install, or a sign-in. Keep the protections built into macOS turned on, such as Gatekeeper, XProtect, and the firewall. MacMon checks that they're on.

Why did I get an alert for something I installed myself?

MacMon alerts on change, not on intent. A new login item or a new privacy permission looks the same whether you added it or something else did. If you recognize it, choose Accept to add it to your allowlist, or Acknowledge to dismiss the alert. Each alert lists the common harmless causes to help you decide.

Is it a problem that MacMon's first run already lists lots of things?

No. The first run sets the baseline: it records what's on your Mac without alerting on each item. After that, you're told about additions, removals, and changes. Keep in mind that the baseline trusts whatever is already there, so it's worth a quick look through Inventory after setup.

Why does MacMon ask for Full Disk Access?

Only to read the macOS databases that record which apps have privacy permissions, such as Full Disk Access, Accessibility, and Screen Recording. Everything else works without it, and the two privacy permission checks show "not checked" until you grant it. Grant it to MacMon's collector in System Settings › Privacy & Security › Full Disk Access. MacMon's Settings › Permissions has a button that shows you which file to add.

Why does MacMon flag my terminal or code editor for having Full Disk Access?

An AI agent running inside your terminal or editor inherits that app's permissions. If your terminal has Full Disk Access, so does every agent and script you run in it. If you need the access, accept the alert to add it to your allowlist.

Which AI agents does MacMon support?

Claude Code and Codex. MacMon reads their configuration and session transcripts, and can install a logging hook for each. For Codex, approve the hook in Codex afterwards with the /hooks command.

Will the AI agent hook slow down or interrupt my agent?

No. The hook records each tool call and adds about 5 ms. It never blocks a call, never prints anything, and always reports success to the agent, even if something goes wrong inside MacMon.

An AI alert looks like a false positive. What should I do?

AI tool call rules match patterns in commands, so some harmless commands will match. Each alert shows the exact part of the command that matched, what the agent said it was doing, and the prompt before it. If it's harmless, acknowledge it. If you've reviewed a configuration item such as a hook or MCP server, choose Trust. MacMon flags it again only if it changes.

The app says background monitoring is "On, but not running".

macOS sometimes stops starting MacMon's background item after the app is updated or moved. Click Restart Background Monitoring in Overview, the menu bar window, or Settings › General. If it keeps happening, check that MacMon is in your Applications folder, then email us.

Can I pause MacMon?

Yes. Choose Pause in the menu bar window, or Pause monitoring in the main window or Settings › General. Scheduled checks stop until you resume. You can also turn background checks off entirely in Settings › General or System Settings › General › Login Items & Extensions.

Does MacMon use the internet or send my data anywhere?

No. MacMon makes no network connections, and its scans run with network requests refused. There are no accounts, analytics, or servers. The only exception is an optional command-line feature, macmon vulns --online, which you have to run by hand. See the privacy policy.

Can I use MacMon from the command line?

Yes. MacMon includes the macmon command-line tool. In Settings › General, add the command, which links it to ~/.local/bin/macmon. Then try macmon status, macmon alerts, macmon ai, or macmon report --open for an HTML report. The app and the command line share the same history and settings.

How do I uninstall MacMon?
  1. In MacMon's Settings › General, turn off background checks.
  2. In Settings › Agent Hooks, remove the Claude Code and Codex hooks if you installed them. If you turned on Protect the hook, choose Remove Protection too.
  3. Quit MacMon and move it from Applications to the Trash.
  4. To delete MacMon's history and settings, delete ~/Library/Application Support/macmon/ and ~/.config/macmon/.
  5. If you granted Full Disk Access, remove MacMon's collector from System Settings › Privacy & Security › Full Disk Access.
What do I need to run MacMon?

macOS 15 Sequoia or later, on a Mac with Apple silicon and Intel. MacMon is written and tested for macOS 26 Tahoe on Apple silicon.

Reporting a security issue

If you find a security problem in MacMon itself, please email support@macmon.app with "Security" in the subject before sharing it publicly. We'll confirm we received it and keep you updated on the fix.