by FailproofAI
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement.
# Add to your Claude Code skills
git clone https://github.com/FailproofAI/failproofaiLast scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T17:00:43.013Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how failproofai compares with popular alternatives.
failproofai is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by FailproofAI. Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement. It has 5,253 GitHub stars.
Yes. failproofai passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/FailproofAI/failproofai" and add it to your Claude Code skills directory (see the Installation section above).
failproofai is primarily written in TypeScript. It is open-source under FailproofAI on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh failproofai against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Translations: 简体中文 · 日本語 · 한국어 · Español · Português · Deutsch · Français · Русский · हिन्दी · Türkçe · Tiếng Việt · Italiano · العربية · עברית
Observability and enforcement for every harness your agents run in. Wherever your agents run, we see it — and we can say no. Failproof hooks 12 agent harnesses — coding CLIs like Claude Code and Codex, chat gateways like Hermes, self-hosted assistants like OpenClaw — capturing every run and blocking dangerous tool calls before they execute. 40 built-in policies. Zero latency. Runs locally.
Twelve harnesses in two classes — ten coding CLIs, and two chat and assistant gateways (Hermes, OpenClaw). One policy API and one session history across all of them. What a policy can block is per-harness: stopping a tool call before it runs is verified on all twelve, turn-end gates on eight. The per-harness matrix lists the events each one honours.
Agents that run in none of them report through the Python SDK, which gives you tracing, sessions and audits. Enforcement there needs a hook in your own runtime — talk to us and we'll map it.
npm install -g failproofai
failproofai config # wire up your agents and the daemon
failproofai policies add FailproofAI/policies # choose what to enforce
failproofai # dashboard on localhost:8020
Setup wires the hooks and picks no policies — that second command is what
puts guardrails on the machine, and any pack is typed the same way
(failproofai policies add <owner>/<repo>; policies show <owner>/<repo> reads
one first). Run failproofai config with no terminal — CI, a container, an
agent driving it — and it applies rather than asking. On a machine that has
never been set up, any other command runs the same wizard first; disable that
with FAILPROOFAI_NO_FIRST_RUN=1.
Until a pack arrives, the only thing enforcing is block-failproofai-commands,
which is always on and cannot be switched off or paused: an agent that can pause
enforcement can switch off every other policy.
| Policy | What it blocks |
|---|---|
block-env-files |
Reads of .env and other secret files |
warn-repeated-tool-calls |
The agent looping on the same call |
block-sudo |
Privilege escalation |
warn-destructive-sql |
DROP, TRUNCATE, unbounded DELETE |
block-terraform / block-kubectl |
Unreviewed changes to live infrastructure |
block-rm-rf |
Recursive file deletion |
block-force-push / block-push-master |
git push --force, direct pushes to main |
Every one of these gates the call before it runs, so they hold on all twelve
harnesses. The first four apply to any agent that can call a tool; the last
three are the developer favourites — coding CLIs are the harness class we cover
deepest. The sanitize-* family is separate: it runs after a tool returns, so
it reports a secret in tool output rather than keeping it out of the context.
Drop a file into .failproofai/policies/ — it loads automatically, no flags needed.
Commit it and the whole team gets it on next pull.
import { customPolicies, deny, allow } from "failproofai";
customPolicies.add({
name: "no-production-writes",
match: { events: ["PreToolUse"] },
fn: async (ctx) => {
if (ctx.toolInput?.file_path?.includes("production"))
return deny("Writes to production paths are blocked.");
return all