# AgentTrail Guard

> Open-source CLI that checks AI coding agents' commands and file changes against 74 local guardrails before they run.

AgentTrail Guard is a free, open-source CLI from AgentTrail that hooks into Claude Code, Cursor, and Codex CLI and checks each tool call against 74 inspectable guardrails before it runs. It runs locally with no account required and is released under the Apache 2.0 license. The latest release listed is v0.4.1.

## What It Is

Guard is a rule-based safety layer for AI coding agents. Your agent's hook sends Guard the tool name and inputs, Guard matches the command or file path against bundled and custom rules, and the agent receives a decision: block, ask for approval, or warn. When nothing matches, the agent's normal permission flow continues. It uses rule matching rather than an LLM reviewing code.

## How the guardrails work

The 74 guardrails are grouped into 11 packs, such as working-tree, destructive-data, prod-infra, secret-exposure, rce-supply-chain, and test-integrity. They cover things like `git reset --hard`, `terraform apply -auto-approve`, reading `.env` files, piping `curl` into a shell, and deleting tests. Every rule is plain data with a title, severity, default action, and a description of what it deliberately does not match. Users can allow a single command shape, change a rule's action, disable a pack, or add their own rule validated with fixtures.

## Setup and day-to-day use

Install with npm (Node.js 20+), then run `agenttrail-guard init --agent claude`, `cursor`, or `codex`. Codex CLI requires approving each Guard entry in `/hooks`. `status` shows what is enforcing and recent decisions. `scan` replays past agent session transcripts through current guardrails and writes a self-contained, redacted HTML report.

## Limits and privacy

Guard checks only calls that reach its hooks, matches commands and file paths rather than file contents, and fails open on internal errors. Coverage differs by agent. It sends nothing by default; it keeps a scrubbed local decision log capped at 1 MiB and 30 days, and crash reporting is opt-in.

## Relationship to AgentTrail OS

Guard is standalone. AgentTrail also makes AgentTrail OS, a hosted product listed as launching soon, for searchable session history, backtesting, approvals, and team policies.

## Features
- 74 guardrails across 11 packs
- Block, ask, or warn decisions before tool calls run
- Local evaluation with no account required
- Custom rules with fixture validation
- Per-rule allowlisting and action overrides
- Scan past sessions into a self-contained redacted HTML report
- Status command showing enforcement and recent decisions
- Scrubbed local decision log
- Opt-in crash reporting

## Integrations
Claude Code, Cursor, Codex CLI

## Platforms
WINDOWS, MACOS, LINUX, WEB, API, CLI

## Pricing
Open Source

## Version
v0.4.1

## Links
- Website: https://www.agenttrail.sh/
- Documentation: https://www.agenttrail.sh/get-started/guard
- Repository: https://github.com/agenttrailhq/guard
- EveryDev.ai: https://www.everydev.ai/tools/agenttrail-guard
