AgentTrail Guard
Open-source CLI that checks AI coding agents' commands and file changes against 74 local guardrails before they run.
At a Glance
Free, open-source local CLI that checks coding agent commands and file changes against 74 guardrails; no account needed.
Engagement
Available On
Alternatives
Listed Oct 2026
About AgentTrail Guard
AgentTrail Guard is a free, open-source CLI from AgentTrail that hooks into Claude Code, Cursor, and Codex CLI and checks each tool call against 74 inspectable guardrails before it runs. It runs locally with no account required and is released under the Apache 2.0 license. The latest release listed is v0.4.1.
What It Is
Guard is a rule-based safety layer for AI coding agents. Your agent's hook sends Guard the tool name and inputs, Guard matches the command or file path against bundled and custom rules, and the agent receives a decision: block, ask for approval, or warn. When nothing matches, the agent's normal permission flow continues. It uses rule matching rather than an LLM reviewing code.
How the guardrails work
The 74 guardrails are grouped into 11 packs, such as working-tree, destructive-data, prod-infra, secret-exposure, rce-supply-chain, and test-integrity. They cover things like git reset --hard, terraform apply -auto-approve, reading .env files, piping curl into a shell, and deleting tests. Every rule is plain data with a title, severity, default action, and a description of what it deliberately does not match. Users can allow a single command shape, change a rule's action, disable a pack, or add their own rule validated with fixtures.
Setup and day-to-day use
Install with npm (Node.js 20+), then run agenttrail-guard init --agent claude, cursor, or codex. Codex CLI requires approving each Guard entry in /hooks. status shows what is enforcing and recent decisions. scan replays past agent session transcripts through current guardrails and writes a self-contained, redacted HTML report.
Limits and privacy
Guard checks only calls that reach its hooks, matches commands and file paths rather than file contents, and fails open on internal errors. Coverage differs by agent. It sends nothing by default; it keeps a scrubbed local decision log capped at 1 MiB and 30 days, and crash reporting is opt-in.
Relationship to AgentTrail OS
Guard is standalone. AgentTrail also makes AgentTrail OS, a hosted product listed as launching soon, for searchable session history, backtesting, approvals, and team policies.
Community Discussions
Be the first to start a conversation about AgentTrail Guard
Share your experience with AgentTrail Guard, ask questions, or help others learn from your insights.
Pricing
AgentTrail Guard (Open Source)
Free, open-source local CLI that checks coding agent commands and file changes against 74 guardrails; no account needed.
- Apache-2.0 license
- 74 inspectable guardrails
- Works with Claude Code, Cursor, Codex CLI
- Runs locally, no account needed
- Add your own rules via local JSON file
Capabilities
Key Features
- 74 guardrails across 11 packs
- Block, ask, or warn decisions before tool calls run
- Local evaluation with no account required
- Custom rules with fixture validation
- Per-rule allowlisting and action overrides
- Scan past sessions into a self-contained redacted HTML report
- Status command showing enforcement and recent decisions
- Scrubbed local decision log
- Opt-in crash reporting
