Risk Disclosures
Operational warnings, stated up front. By installing or using AIGuard you accept the following, without limitation.
No warranty
Provided “as is”
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND (Apache-2.0, sections 7–8). No guarantees regarding reliability, availability, performance, or suitability for production use — it is not suitable for production use. You evaluate and use this software at your own discretion and risk.
A guardrail, not a security boundary
- Not a sandbox. No filesystem, network, or memory isolation. An approved (or ungated) command runs with your full privileges.
- Honest-but-fallible threat model only. A deliberately adversarial or prompt-injected assistant that crafts evasive commands is out of scope and may bypass the policy engine.
- Commands only. File writes and network access performed without spawning a shell command are not gated.
- Pattern matching has blind spots. The policy is
regex-based. Novel or obfuscated dangerous commands may be classified
alloworaskinstead ofblock. Treataskas the normal case, not as an alarm.
Fail-open platforms
Hook timeout = command runs
Per Kimi Code CLI and Claude Code documentation, a hook that times out or crashes allows the command to run. AIGuard itself always fails closed, but the platforms do not.
- Do not run an assistant in yolo/auto-approve mode and rely on AIGuard as your only barrier — platform fail-open behavior can combine with auto-approval to bypass everything.
- Keep hook timeouts in mind on slow or heavily loaded machines.
You are the approval
- Read the command before approving. The whole point is that you, not the assistant, judge the risk. Approving reflexively defeats the system.
- Approvals are bound to the exact command string and are single-use — but a command you approve runs with your privileges. One careless approval can destroy data.
- Touch ID and TOTP prove presence, not judgment.
Data sensitivity
~/.aiguard/audit.jsonlrecords every evaluated command verbatim, including any secrets passed as CLI arguments. The file is 0600 — keep it that way, and delete it securely when retiring the tool.- On headless systems without a keyring backend, the TOTP secret is stored as a 0600 file. Anyone who reads it can approve commands.
- Desktop notifications (daemon) display the first 50 characters of the challenged command on screen.
Operational warnings
- Breaking changes during Beta. Policy rules, state file formats, and CLI behavior may change between pre-releases without a deprecation period.
- Assistant updates may break hooks. An assistant update can silently change hook behavior. Re-verify after upgrading an assistant.
- Daemon is informational. If it is not running, you
get no notifications — check for
AIGUARD_CHALLENGE:messages from the assistant. - Do not weaken
~/.aiguard/permissions. The 0700/0600 modes are part of the security model.
If something goes wrong
- Stop the assistant session.
- Remove the hooks:
aiguard uninstall kimi/aiguard uninstall claude. - Report the problem — security issues privately per the security policy, everything else as a GitHub issue.