Skip to main content

agent-guard

See what your AI coding agent touches, and fence it in.

agent-guard is a Claude Code hook that runs before every tool call. It does two things:

  1. Logs every read, write, edit, shell command, and web fetch to a local audit trail, viewable on a live dashboard.
  2. Blocks any file access outside the folders you allow, so a stray agent can't wander into ~/.ssh, your browser profile, or the rest of your disk.

Pure Python standard library. No dependencies, no telemetry, nothing leaves your machine.

pip install agentguard
agentguard install      # adds the PreToolUse hook to ~/.claude/settings.json
agentguard dashboard    # http://127.0.0.1:8799

Open a new Claude Code session and watch it work in real time.


Why

Agentic coding tools can read and write anything the process can. Most of the time that's fine; occasionally it isn't, and either way you can't see it. Cloud sandboxes solve this by locking the agent in a box, but you lose your local setup. agent-guard is the lightweight local version: a boundary you define, a log you can audit, and a red banner the moment something steps over the line.

How it works

Claude Code fires a PreToolUse hook before running any tool and passes it the tool name and arguments as JSON on stdin. agent-guard:

  • appends the call to a JSONL audit log (for the dashboard), and
  • for file tools (Read, Write, Edit, MultiEdit, NotebookEdit, Grep, Glob), resolves the target path and checks it against your allowed roots.

Exit code 2 blocks the tool and the reason is shown back to the agent; exit 0 allows it. It fails open: any internal error allows the call, so a bug in the guard can never brick your agent.

Config is re-read on every call, so edits take effect immediately, no restart.

Configuration

agentguard install writes ~/.agentguard/config.json:

{
  "enforce": true,
  "allowed_roots": [
    "C:\\Users\\you\\Downloads",
    "C:\\Users\\you\\.claude"
  ],
  "log_path": "C:\\Users\\you\\.agentguard\\access-log.jsonl"
}
  • allowed_roots — folders the agent may read/write. Everything else is outside. Add your project directories here.
  • enforcetrue blocks; set false to log-only (watch first, fence later).
  • log_path — where the audit trail is written.

Point somewhere else with AGENTGUARD_CONFIG=/path/to/config.json.

The dashboard

agentguard dashboard          # default port 8799
agentguard dashboard --port 9000

Auto-refreshing local page: tiles (reads / writes / shell / web / outside / blocked), a filterable activity table (all / outside / blocked), an activity-over-time timeline, and the top folders being touched. A red banner appears the instant anything is blocked.

Commands

Command What it does
agentguard install Add the PreToolUse hook to ~/.claude/settings.json (merges, keeps your other hooks).
agentguard uninstall Remove it again.
agentguard dashboard Serve the live dashboard.
agentguard status Print config, whether the hook is installed, and recent counts.
agentguard harden Show credential read-deny rules to add to Claude Code's own permissions (dry-run; --apply to write).
agentguard hook The guard itself — what Claude Code invokes. You won't run this by hand.

harden

The folder fence stops access outside your roots. harden adds a second layer using Claude Code's native permissions.deny: it keeps tools away from credential files (.ssh, .aws, .env, *.pem, browser login data, …) wherever they live. It's a dry-run by default:

agentguard harden          # print what it would add
agentguard harden --apply  # write the rules to settings.json

Manual install (without pip)

The repo works as-is. Clone it and point a PreToolUse hook at the shim:

{
  "hooks": {
    "PreToolUse": [
      { "hooks": [{ "type": "command", "command": "python",
                    "args": ["/path/to/agent-guard/guard.py"], "timeout": 10 }] }
    ]
  }
}

Then python dashboard.py for the dashboard.

License

MIT.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sneakoscope-0.1.0.tar.gz (13.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sneakoscope-0.1.0-py3-none-any.whl (14.2 kB view details)

Uploaded Python 3

File details

Details for the file sneakoscope-0.1.0.tar.gz.

File metadata

  • Download URL: sneakoscope-0.1.0.tar.gz
  • Upload date:
  • Size: 13.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for sneakoscope-0.1.0.tar.gz
Algorithm Hash digest
SHA256 260ca5f42021ada56bd59cdbfeddd47094f717c41bc3a8b4c99fb04a8428a893
MD5 21cab3f0e94ce0295e1d3c021118d6aa
BLAKE2b-256 015b62a1e2de354bff9974897f46a90c022ca89d3fdc8dc87beab302596b5e8c

See more details on using hashes here.

File details

Details for the file sneakoscope-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: sneakoscope-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 14.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.3

File hashes

Hashes for sneakoscope-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9c09c60fa9e94f9fe3caf550d52a5c6f87998f360ae95f3d74da54a562c48775
MD5 09bb94a659093356805b2bd5cd542193
BLAKE2b-256 ebc374ab6bebb33e4502b7b9ace07d74d3ec05c7648395cf0f4bf22d4b769ae1

See more details on using hashes here.

Release history Release notifications | RSS feed

0.4.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page