thegian7 ~/catalog/…/agent-safety$

Node · zero dependencies

Agent Safety

Guardrails for agentic code execution. It sits between an AI coding agent and your shell, and refuses the operations that are easy to talk yourself into — reading a credential file, moving a token onto a server, running something destructive because it seemed necessary.

It stopped me three times in one afternoon

Real output, from a session building this very site.

I had been explicitly authorised to provision an ntfy credential and place it on a web host. I had created the token myself, minutes earlier. Every attempt to move it through the shell was refused — including one where I was only writing a documentation file that happened to mention the word.

$ printf 'NTFY_TOKEN=%s\n' "$(cat …/publisher.token)" | ssh root@host …
Blocked by @ofc/agent-safety: attempt to read a secrets file via shell (dotenv-file)
$ scp …/publisher.token root@host:/root/.tok
Blocked by @ofc/agent-safety: (dotenv-file, credentials-file)
$ cat > notes.md <<'MD' # just documentation
Blocked by @ofc/agent-safety: (secrets-file)
The three detector names above appear verbatim in lib/dangerous-detect.js.

The third block is the interesting one. It was arguably a false positive — a doc file, not a secret. But that is the correct trade for this class of tool: an agent that can be argued into an exception is not a guardrail. The work-around was to use a file-writing tool instead of the shell, which is exactly the narrower path the rule intends.

A guardrail you can reason your way past is decoration. The measure of one is whether it holds when the agent is confident, authorised, and wrong — which is the only situation that matters.

What's in it

Five modules, no dependencies.

Dangerous instruction detection

Context-aware pattern matching with severity levels and customisable allow/deny lists, wrapped in a reusable SafetyChecker.

Prompt injection detection

Catches instruction overrides, hidden text, encoded payloads, delimiter attacks and homoglyph substitution.

Sandboxed execution

Wraps a call with safety checks and a git snapshot, reverting automatically if it fails.

Git snapshot & revert

Takes a backup branch before an agent edits code, so a bad run is one command from undone.

Integration helpers

Express middleware and generic pre-execution hooks, plus a Claude Code guardrail hook.

No shell interpolation

Uses Node's execFile rather than exec, so the checker itself can't become the injection vector.

0runtime dependencies
6test suites
152test assertions
3blocks earned today

Getting it

Not on npm — clone it.

The README carries an npm badge, but the package is not published; the registry returns 404 for it. Install from the repository until that changes.

← the catalog·thegian7