Execution-Layer Security for AI agents
A guardrail between your AI assistant and your shell.
AIGuard hooks into Kimi Code CLI and Claude Code via their PreToolUse hooks and evaluates every shell command against a policy — allow, ask, or block. Dangerous commands wait for an out-of-band approval that only you can give: Touch ID on macOS, TOTP elsewhere.
- Python 3.11+
- macOS & Linux
- Apache-2.0
pipx install aiguard-gate
How it works
Four steps between intent and execution
Hook intercepts
Before the assistant runs a shell command, its official PreToolUse
hook pipes the command to aiguard-evaluate.
Policy decides
Every command gets a Decision — an action
(allow / ask / block), a risk
tier, and a plain-English warning.
You approve out-of-band
ask commands return
AIGUARD_CHALLENGE:<token>. You run
aiguard approve in any terminal — Touch ID on
macOS, 6-digit TOTP elsewhere.
Assistant retries
The approval is single-use, bound to the exact command string, and expires after 5 minutes. Retry, and the command runs.
Three possible outcomes for every command
allow
Safe commands — git status, ls — proceed
instantly. No friction for everyday work.
ask
Everything else is blocked with a challenge token until you approve
it out-of-band. ask is the default for unrecognized
commands — treat it as the normal case, not an alarm.
block
Catastrophic commands — rm -rf /, writes to
~/.aiguard/ — are refused. No override
exists: not by approval, not by user policy.
Features
What the guardrail gives you
Policy engine
Built-in block → ask → allow rules, first match wins. Extend with
your own patterns in ~/.aiguard/policy.toml — user
allow rules can never override an Absolute Block.
Out-of-band approval
Approvals happen in a separate terminal, outside the assistant's session. The assistant relays a token; it never sees your Touch ID or TOTP.
Platform-native auth
Touch ID via LocalAuthentication on macOS. RFC 6238 TOTP with any authenticator app on Linux (and as a macOS fallback).
Absolute Blocks
Filesystem-destroying commands and writes to AIGuard's own state are refused outright. No approval and no policy can override them.
Verbatim audit log
Every evaluated command and its Decision is appended to
~/.aiguard/audit.jsonl (0600) — a complete record of
what the assistant tried to run.
Local by design
No account, no cloud service, no telemetry. All state lives in
~/.aiguard/ (0700) on your machine.
Honesty section
What AIGuard does NOT do
AIGuard is a guardrail, not a sandbox. It reduces the chance that an honest-but-fallible assistant runs a dangerous command — it does not make agents safe, and it is not a security boundary.
-
Not a sandbox
No filesystem, network, or memory isolation. An approved (or ungated) command runs with your full privileges.
-
Not adversarial-proof
The threat model is the honest-but-fallible agent. A deliberately evasive or prompt-injected assistant that crafts obfuscated commands is out of scope and may bypass the regex-based policy.
-
Commands only
File writes and network access performed without spawning a shell command are not gated.
-
Host platforms fail open
Per Kimi and Claude documentation, a hook that times out or crashes allows the command (AIGuard itself always fails closed). Do not rely on AIGuard in yolo/auto-approve assistant modes, and do not use it as your only safeguard.
-
The audit log records commands verbatim
~/.aiguard/audit.jsonlmay contain secrets passed as CLI arguments. It is 0600 — keep it that way.
Install
Up and running in three commands
1 · Install the CLI
pipx install aiguard-gate
# macOS Touch ID support:
pipx inject aiguard-gate pyobjc-framework-LocalAuthentication
2 · Enroll & hook your assistant
aiguard setup # TOTP enrollment (required on Linux) aiguard install kimi # or: aiguard install claude
3 · Approve a challenge when one appears
aiguard approve <token> # Touch ID on macOS aiguard approve --totp <token> # force TOTP
Requirements
- Python 3.11 or newer
- macOS (Touch ID or TOTP) or Linux (TOTP)
- pipx
- Kimi Code CLI or Claude Code
Package vs. command
The PyPI package is aiguard-gate; the installed CLI
is aiguard.
Beta software
Evaluate on non-critical machines first. Policy rules, state formats, and CLI behavior may change between pre-releases without a deprecation period.