Are you an LLM? You can read better optimized documentation at /docs/agent-guard/operations/uninstall.md for this page in Markdown format
Uninstall and clean up
agentguard uninstall removes Agent Guard's state, credentials, and data from your Mac. Use it when you are done with Agent Guard, when you want to start over from a clean slate, or when you are preparing a machine for someone else.
Run uninstall
bash
agentguard uninstallBy default, this removes:
- Every Keychain entry under the service
AgentGuard, whatever its account:vm-claude-code-credentials,vm-codex-credentials,vm-antigravity-credentials, and any others. - Credential staging files (
~/.agentguard/github-token,~/.agentguard/auth.json). - Every named environment under
~/.agentguard/vm/environments/, with its installed packages, conversation history, and overlay state. Uninstall warns about a microVM still running in one of them but does not stop it, and that microVM's later writes to the environment are lost. - Configuration files:
state.json,ruleset.json,sandbox.sb,strict-sandbox.sb, andconfig.json. - The policies directory:
~/.agentguard/policies/. - The bin directory:
~/.agentguard/bin/. - The audit-upload LaunchAgent, if
agentguard audit schedule installregistered one. - Process ID files and legacy audit logs inside
~/.agentguard/. - Finally, the whole
~/.agentguard/directory, including the rootfs image and the cached runtime images.
Uninstall leaves in place:
- The
agentguardbinary, which the installer puts in/usr/local/bin/by default. Remove it yourself if you do not want it. - Registry logins made with
agentguard policy add --username, which are kept in thekitCLI's credential store. Remove them withkit logout <registry>. - The
PATHline the installer may have added to~/.zshrc. Uninstall prints a reminder.
Preview the uninstall
Run with --dry-run to see exactly what would be removed without deleting anything:
bash
agentguard uninstall --dry-runUseful before running uninstall on a machine that has been used for a while, just to confirm what is about to disappear.
Keep your configuration
--keep-config preserves ~/.agentguard/config.json, which holds your policy source references. Useful if you want to reset state but plan to reinstall Agent Guard later without re-running every agentguard policy add. The cached policy files are still deleted; the next agentguard run pulls them again.
bash
agentguard uninstall --keep-configWhen --keep-config is set, the final sweep that removes the ~/.agentguard/ directory is also skipped, so the config file has somewhere to live.
What is intentionally preserved
~/Library/Logs/AgentGuard/ is not touched by uninstall. The policy audit logs and the policy server logs stay where they are. When AGENTGUARD_HOME is set, logs are written to $AGENTGUARD_HOME/logs/ instead, and are removed with the rest of that directory.
This is intentional. If you later reinstall Agent Guard or need to forensically review what an agent did on this machine, the audit trail is still there. To wipe the logs as well, delete the directory manually:
bash
rm -rf ~/Library/Logs/AgentGuard/Do this only when you are sure you no longer need the audit history.
Clean up the rootfs cache separately
The 500 MB rootfs disk image lives at ~/.agentguard/vm/rootfs.img. It is removed when uninstall sweeps the ~/.agentguard/ directory at the end. If you used --keep-config (which skips the sweep) and want to reclaim that disk space, remove it manually:
bash
rm ~/.agentguard/vm/rootfs.imgIf you reinstall Agent Guard later, the next agentguard run extracts the image again from the agentguard binary.
Wipe Keychain entries manually
agentguard uninstall removes every Keychain entry under the AgentGuard service. To confirm nothing is left over, list them:
bash
security find-generic-password -s AgentGuardTo delete an entry by hand:
bash
security delete-generic-password -s AgentGuard -a vm-claude-code-credentials
security delete-generic-password -s AgentGuard -a vm-codex-credentials
security delete-generic-password -s AgentGuard -a vm-antigravity-credentialsThis is mainly useful when a previous Agent Guard install left entries behind that the current install did not recognize.
Reinstalling later
If you uninstalled with the defaults (including config) and want to come back later, the install flow is identical to the first time. Curl the installer, configure policies, run your first agent. There is no state to migrate.
If you uninstalled with --keep-config and want to come back later, reinstall the binary and your configured policy sources will start syncing automatically on the next agentguard run.
Full cleanup checklist
For a complete removal with nothing left behind:
bash
agentguard uninstall # state, env, policies, config
rm -rf ~/Library/Logs/AgentGuard/ # audit logs
sudo rm /usr/local/bin/agentguard # the binary itself
kit logout <registry> # each registry you logged in to
# Optional: confirm no Keychain entries remain
security find-generic-password -s AgentGuard 2>&1 | grep -v "could not be found"After this, the machine has no trace of Agent Guard.
