by LucidAkshay
Tactical AI Workspace Monitor & EDR
# Add to your Claude Code skills
git clone https://github.com/LucidAkshay/kavachTactical AI Workspace Monitor & EDR

Kavach (Sanskrit for "Armor") is an open source Endpoint Detection and Response (EDR) layer designed exclusively to restrain, monitor, and remediate autonomous AI agents and local LLMs operating on your machine.
Autonomous AI agents are revolutionary, but they are inherently volatile. When they operate on your local file system, they move at superhuman speeds. A single hallucination can delete production databases, overwrite source code, or exfiltrate private API keys.
Architecture Transparency: Kavach v1.1.0 operates as a high performance asynchronous file system observer using Userland APIs. It monitors designated workspaces, quarantines malicious actions, and provides immediate remediation tools. It is an EDR monitor, not a strict synchronous sandbox. True system call blocking requires kernel drivers, which are slated for our v1.2 roadmap.
Kavach is armed with an exhaustive array of active defense mechanisms operating at the application layer to outsmart and contain rogue agents.
No comments yet. Be the first to share your thoughts!
.kavach_phantomsystem_auth_tokens.json file. Any process attempting to read or modify the decoy instantly triggers a High Risk lockdown and a distinct TRAP TRIGGERED alarm. Decoys are automatically scrubbed when the session ends.npm install loops) to force automatic agent suspension.%TEMP%, Prefetch, Logs) to eliminate alert fatigue.package.json for known malware dependencies.Moving from a passive EDR tool to a true Zero Trust Sandbox requires native hardware drivers and autonomous intelligence. These are currently under active development:
sys_enter_openat and sys_enter_mkdir.Kavach is built for absolute performance and zero latency, running entirely locally on your machine with zero cloud dependencies.
Akshays.Kavach_1.1.0_x64-setup.exe). (Note: Windows requires running as Administrator for process termination; macOS requires Full Disk Access).Kavach features a "Direct Line" communication module for users to report anomalies, suggest features, or collaborate.
Kavach is proudly released under the GNU General Public License v3.0 (GPLv3). Permanent attribution to Akshay Sharma is required in all forks, distributions, and derivatives, and any modifications must remain open source under the same license terms.