Security & trust
Security, stated plainly
AIGuard is a guardrail: friction, authentication, and an audit trail around the shell commands an AI assistant tries to run. This page is the full, unsugarcoated version of what that means.
Threat model
In scope: honest-but-fallible
A well-intentioned assistant that makes mistakes: hallucinated flags, wrong working directory, over-broad deletes, commands that do more than you asked. AIGuard adds friction and a human checkpoint exactly here.
Out of scope: adversarial
A deliberately malicious or prompt-injected assistant that crafts evasive, obfuscated, or encoded commands may bypass the regex-based policy. AIGuard does not defend against this, and does not claim to.
AIGuard is an Execution-Layer Security (ELS) tool: it secures the point where an agent's decisions become executed commands. It complements model-level and prompt-level defenses; it does not replace them, and it does not gate file writes or network access performed without spawning a command.
Architecture guarantees — and their limits
- AIGuard fails closed. Any internal error in
aiguard-evaluateblocks the command. - The platforms fail open. Both Kimi Code CLI and Claude Code allow a command when a hook times out or crashes. This is documented platform behavior, outside AIGuard's control.
- Approvals are single-use, bound to the exact command string (SHA-256, truncated to 12 hex chars), and expire after 5 minutes.
- Absolute Blocks (
rm -rf /and equivalents, writes to~/.aiguard/) cannot be overridden by any approval or user policy. - State permissions:
~/.aiguard/is 0700; challenge, approval, audit, and TOTP files are 0600. - TOTP secrets are stored in the system keyring where available, with a 0600-file fallback on headless systems.
- Audit log (
~/.aiguard/audit.jsonl) records every command verbatim. Commands may contain secrets; treat the file as sensitive.
Known limitations
- Regex-based policy. Obfuscated, encoded, or novel
dangerous commands may evade the built-in patterns. The default for
unrecognized commands is
ask, but a small set of common safe prefixes is auto-allowed. - No protection within an approved command. A command is approved as a whole; what a script then does is not constrained.
- Presence, not judgment. Touch ID and TOTP confirm an authorized human is present — not that the human read the command. Read every command before approving.
- Notification leakage. The optional daemon shows the first 50 characters of a challenged command in a desktop notification.
- Keyring fallback. On headless systems the TOTP secret lives in a 0600 file; anyone who can read it can approve commands.
- Single-user design. State assumes one user account on one machine. Shared accounts and multi-machine sync are unsupported.
- Beta quality. Defects may exist in exactly the components meant to protect you. AIGuard must not be your only safeguard — maintain independent backups.
The complete operational risk statement is in Risk Disclosures.
Reporting a vulnerability
Report privately
Please report security issues privately via a GitHub Security Advisory rather than a public issue. While the repository is private, contact the maintainer directly.
Please include:
- the affected AIGuard version and platform;
- the assistant (Kimi Code CLI / Claude Code) and its version;
- steps to reproduce;
- whether the issue lets a command bypass policy evaluation or approval.
Supported versions
| Version | Supported |
|---|---|
| 6.1.0bx (Beta) | Latest pre-release only |
| < 6.1 | No |
If something goes wrong
1. Stop the assistant session.
2. Remove the hooks: aiguard uninstall kimi /
aiguard uninstall claude.
3. Report the problem — security issues privately per above, everything
else as a GitHub
issue.