Beta — for evaluation and testing only. AIGuard is a guardrail, not a security boundary. Read the risk disclosures

Documentation

Execution-Layer Security (ELS) for AI agents — out-of-band command approval for Kimi Code CLI and Claude Code.

Beta documentation

These pages track the current Beta pre-release (6.1.0bx). Behavior may change between pre-releases. The authoritative long-form documents live in the repository.

What AIGuard is

AIGuard is an Execution-Layer Security tool: it secures the layer where an agent's decisions become real actions — process and command execution on your machine. It hooks into your assistant's official PreToolUse mechanism, evaluates every shell command against a policy, and returns one of three actions: allow ask block

It is a guardrail against honest-but-fallible agents — not a sandbox, and not a defense against adversarial ones. See Risk Disclosures before relying on it.

Quick start

pipx install aiguard-gate
aiguard setup
aiguard install kimi     # or: aiguard install claude

Full instructions: Installation.

Pages in these docs

PageContents
Architecture Evaluation flow, policy engine, approval flow, state layout
Installation Requirements, pipx install, TOTP enrollment, hook setup
Releases Versioning, release process, support policy
Risk Disclosures Operational warnings — read before relying on AIGuard
Security Guarantees, known limitations, vulnerability reporting
Contributing Development setup, workflow, design records