Skip to main content

Agentsward

A guardrail layer for autonomous coding agents. Agentsward classifies the risk of every shell command and file edit your AI coding agent attempts, routes the risky ones to your phone for approval, and — critically — denies by default when no one responds. Every decision is logged.

Not a remote-control app. Anthropic's Remote Control already lets you drive a Claude session from your phone. Agentsward is the policy layer underneath: it decides what an agent is allowed to do, enforces protected files unconditionally, fails safe, and is built to gate any agent — not just one vendor's.

Why it exists

Native permission prompts (and Remote Control's mirrored version of them) ask "allow this?" with no risk model, no protected-file enforcement, and no fail-safe: ignore the prompt and nothing is denied. Agentsward adds the missing governance layer:

Native prompt / Remote Control Agentsward
Risk classification — CRITICAL → LOW, defaults to "ask"
Protected files (.env, CI, lockfiles, .claude/) — Always re-affirm, bypass auto-allow
No-response behavior nothing denied default-deny (fail-safe timeout)
Phone-set guards / auto-rules — yes
Audit trail — every classify/approve/deny logged

How it works

A PreToolUse hook intercepts the agent's tool call, a classifier scores it, and:

  • LOW → auto-approve.
  • CRITICAL → auto-deny.
  • MEDIUM / HIGH → sent to your phone with a diff/snippet; blocks until you decide.
  • Protected file (gate config, secrets, supply-chain/CI) → always reaches you, regardless of score.
  • No decision within the timeout → deny (fail-safe).

Install

pip install agentsward            # the CLI command is `agentsward`
agentsward setup                   # one step: pair phone + wire every installed agent

agentsward setup (or agentsward install) auto-detects and wires Claude Code, OpenAI Codex, and Google Gemini CLI — whichever are installed. To target one explicitly:

agentsward install --claude        # Claude Code (or install-hooks / --global for all projects)
agentsward install --codex         # OpenAI Codex        (or install-codex-hooks)
agentsward install --gemini        # Google Gemini CLI   (or install-gemini-hooks)
agentsward install --all           # every supported agent

Then restart the agent you wired — Claude Code (or run /hooks), Codex, or Gemini (in auto-accept/YOLO so the phone is the sole gate). It's idempotent and leaves any other hooks in place.

Approval channels

Agentsward is transport-agnostic — the gate is the product, the channel is a detail:

  • Telegram (default, zero infra):
    agentsward init                 # bot token + chat id
    
  • Cloud relay + mobile app (approvals from anywhere):
    agentsward pair                 # link this machine to the phone app
    

Quick manual test (no agent needed):

agentsward approve-command "git push origin main"   # exits 0 (allow) / 1 (deny)

Approval modes (agentsward mode)

Mode Who approves Use when
phone (default) Only your phone. The local popup is suppressed — the hook tells Claude Code allow/deny directly, so work continues the instant you tap. You're away, or don't want anyone at the keyboard approving for you.
laptop Only the local prompt. No phone notifications; the hook steps aside. You're at the desk and don't want phone pings.

agentsward mode laptop takes effect immediately (read at runtime).

Claude Code hook

install-hooks wires the gating + notification hooks with the correct local path filled in. The gating hook looks like:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          { "type": "command", "command": "agentsward hook --timeout 1800", "timeout": 1800 }
        ]
      }
    ]
  }
}
  • Critical invariant: the inner --timeout must be ≤ the outer "timeout", or Claude Code kills the hook before your phone can respond. install-hooks keeps them matched.
  • Hook config changes take effect only after restarting Claude Code (snapshotted at session start). Hook code is live with an editable install.

Other commands

agentsward logs -n 20      # activity timeline
agentsward pending         # is a command awaiting me, or did it stop?
agentsward resume          # lift a Stop kill-switch
agentsward instructions    # show instructions sent from the phone

Storage

All state lives in ~/.agentsward/: config.json, approvals.json, instructions.json, audit_log.json.

License

Proprietary. See LICENSE.

Metadata

Release files for agentsward 0.5.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentsward 0.5.1
File Size Uploaded
agentsward-0.5.1.tar.gz 87.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentsward 0.5.1
File Interpreter ABI Platform
agentsward-0.5.1-py3-none-any.whl Python 3 none any Details

Total release size: 181.4 kB

Release files / agentsward-0.5.1.tar.gz

Download URL agentsward-0.5.1.tar.gz
Size 87.7 kB
Tags Source
SHA-256 checksum
How to use checksums
9198ca1f33fd8d74141b6c2bed02e10e67d40fd4c676e423a938bd413d985dbc
BLAKE2b-256 checksum
How to use checksums
4f1729d71da0941fe07013dce977b2cc19e7121a614b131aad45d05f3fb0678a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release files / agentsward-0.5.1-py3-none-any.whl

Download URL agentsward-0.5.1-py3-none-any.whl
Size 93.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0bd814f66a5117cc90c909cb61d33b45f66a104ab87eb6d54b2134835d811266
BLAKE2b-256 checksum
How to use checksums
8a6fa0f128efa54f849e61820bfc62019953580e3cdb2789d654960d2d4b309c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.13

Release history Release notifications | RSS feed

This release

0.5.1 This release

2 release files

0.5.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page