Node · zero dependencies
Guardrails for agentic code execution. It sits between an AI coding agent and your shell, and refuses the operations that are easy to talk yourself into — reading a credential file, moving a token onto a server, running something destructive because it seemed necessary.
Real output, from a session building this very site.
I had been explicitly authorised to provision an ntfy credential and place it on a web host. I had created the token myself, minutes earlier. Every attempt to move it through the shell was refused — including one where I was only writing a documentation file that happened to mention the word.
The third block is the interesting one. It was arguably a false positive — a doc file, not a secret. But that is the correct trade for this class of tool: an agent that can be argued into an exception is not a guardrail. The work-around was to use a file-writing tool instead of the shell, which is exactly the narrower path the rule intends.
Five modules, no dependencies.
Context-aware pattern matching with severity levels and customisable allow/deny lists, wrapped in a reusable SafetyChecker.
Catches instruction overrides, hidden text, encoded payloads, delimiter attacks and homoglyph substitution.
Wraps a call with safety checks and a git snapshot, reverting automatically if it fails.
Takes a backup branch before an agent edits code, so a bad run is one command from undone.
Express middleware and generic pre-execution hooks, plus a Claude Code guardrail hook.
Uses Node's execFile rather than exec, so the checker itself can't become the injection vector.
Not on npm — clone it.
The README carries an npm badge, but the package is not published; the registry returns 404 for it. Install from the repository until that changes.