by agenttrailhq
Observability and guardrails for your ai agents. AgentTrail Guard traces your agent's execution and automatically compiles repeat failures into permanent guardrails.
# Add to your Claude Code skills
git clone https://github.com/agenttrailhq/guardSee how guard compares with popular alternatives.
guard is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by agenttrailhq. Observability and guardrails for your ai agents. AgentTrail Guard traces your agent's execution and automatically compiles repeat failures into permanent guardrails. It has 3 GitHub stars.
guard's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/agenttrailhq/guard" and add it to your Claude Code skills directory (see the Installation section above).
guard is primarily written in TypeScript. It is open-source under agenttrailhq on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh guard against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
Check your AI coding agent's commands and file changes before they run. Works with Claude Code, Cursor, and Codex CLI. Local, free, and no account needed.
Quick start · Guardrails · Reference · Changelog
AgentTrail Guard is a free, open-source CLI that connects to your coding agent's hooks and checks every tool call that reaches them against 74 inspectable guardrails before it runs. Guard can block a matching call, send it to you for approval, or record it as a warning, depending on the agent. When nothing matches, your agent's normal permission flow continues.
You need: Node.js 20 or newer, npm, and at least one of Claude Code, Cursor, or Codex CLI.
npm install -g @agenttrail/guard
agenttrail-guard init --agent claude # Claude Code
agenttrail-guard init --agent cursor # Cursor
agenttrail-guard init --agent codex # Codex CLI
Each setup is independent, and settings are shared under ~/.agenttrail/guard/. To see
exactly what init would change first, add --print; it changes nothing.
init demonstrates the engine by evaluating a synthetic rm -rf / and showing its
decision. The command is never executed. This checks the engine; you still need to
complete your agent's setup below.
/hooks, and approve each agenttrail-guard entry.
Guard does not run until you approve it.agenttrail-guard status
status shows what is enforcing in each agent, recent decisions, and settings that need
attention. For Codex, ON means the hook is installed and well-formed; confirm approval in
Codex's own /hooks screen, because Guard cannot read that state.
To upgrade, install the latest release, re-run init for each agent you use, and restart
that agent. Your settings are kept, and Codex keeps the approval you already gave. Before
1.0, a minor release can include a breaking change, so skim the changelog
first.
npm install -g @agenttrail/guard@latest
agenttrail-guard init --agent claude # and again for cursor or codex, if you use them
To remove Guard from an agent, run uninstall for it. It removes only what Guard added, and
keeps your settings in ~/.agenttrail/guard/.
agenttrail-guard uninstall --agent claude # or: --agent cursor, --agent codex
What each step changes is covered in Updating and Uninstall.
Prefer a guided walkthrough? See the AgentTrail Guard installation guide.

A real Claude Code session. The agent decides to reset the database to get a schema push
through; Guard blocks prisma db push --force-reset with dd.accept-data-loss before it runs.
Your coding agent runs shell commands and edits files all day, faster than you can review
each one. Most of those calls are exactly what you want. The ones that aren't, like
git reset --hard over a day of uncommitted work, rm -rf on the wrong path,
terraform apply -auto-approve, or a read of your .env, tend to be the ones you can't take
back. Guard puts a rule-based check on every tool call that reaches its hooks, in every
session, so the risky ones stop and explain themselves before they run, and everything else
carries on as normal.
~/.agenttrail/guard/.agenttrail-guard status shows recent decisions, and scan turns
past agent sessions into a self-contained HTML report.agenttrail-guard status shows recent decisions.Guard uses rule matching, not an LLM reviewing your code. It can stop a matching call only when your agent sends it through the installed hooks, it does not inspect file contents, and it does not guarantee that every dangerous action will be caught. On an internal error it fails open: your agent's normal permission flow continues. Read the coverage and runtime limits before relying on it.
The table below is real output: each row is a Claude Code PreToolUse call passed to
Guard's hook, and the reason Guard returned before anything ran.
| Your agent proposes | Guard's answer to Claude Code |
|---|---|
git reset --hard origin/main |
Deny: agenttrail-guard blocked this: git reset --hard discards uncommitted work (guardrail wt.reset-hard) |
terraform apply -auto-approve |
Ask: agenttrail-guard needs a person to approve this: Terraform apply/destroy without the confirmation prompt (guardrail pi.terraform-auto-approve) |
Read .env |
Warn: agenttrail-guard is warning about this: Flag reading a .env file (guardrail block-env-file-read) |
npm test |
No output. Claude Code's normal permission flow decides. |
git commit -m "docs: explain why rm -rf / is dangerous" |
No output. Mentioning a command is not running it. |
In a real Claude Code session, an agent told it was only dev data reached for
npx prisma db push --force-reset, and dd.accept-data-loss blocked it before it ran.
Read the case study.
Every decision names its guardrail, and every guardrail explains itself (the description is wrapped and trimmed here):
$ agenttrail-guard guardrails show wt.reset-hard
wt.reset-hard working-tree · severity: high
git reset --hard discards uncommitted work
Action block (shipped default)
Enforcing yes
Discards every uncommitted change in the working tree, irrecoverably — there is no
reflog for work that was never committed. Does NOT match `git restore` (see
wt.restore-path), `git checkout -- .` (see wt.checkout-discard) [...]
Guard ships with 74 guardrails across 11 packs. Packs are named for the harm they prevent, not the technique used to spot it. By default, 13 guardrails block, 50 ask, and 11 warn.
| Pack | Rules | Representative examples | Defaults |
|---|---|---|---|
working-tree |
9 | git reset --hard, git clean -fd, force-push, rm -rf |
5 block, 4 ask |
destructive-data |
8 | rm -rf on an absolute path, dropping a database, destructive SQL, deleting Docker volumes |
5 block, 3 ask |
prod-infra |
8 | terraform apply -auto-approve, kubectl delete, Helm uninstall or rollback, production config edits |
8 ask |
secret-exposure |
10 | Reading .env or credential files, printing tokens, hard-coded secrets in commands, public bucket ACLs |
1 block, 4 ask, 5 warn |
rce-supply-chain |
6 | Piping curl into a shell, running code from a URL, TLS verification off, a redirected registry |
1 block, 5 ask |
| `safety-bypa |