Beta — for evaluation and testing only. AIGuard is a guardrail, not a security boundary. Read the risk disclosures

Security & trust

Security, stated plainly

AIGuard is a guardrail: friction, authentication, and an audit trail around the shell commands an AI assistant tries to run. This page is the full, unsugarcoated version of what that means.

Threat model

In scope: honest-but-fallible

A well-intentioned assistant that makes mistakes: hallucinated flags, wrong working directory, over-broad deletes, commands that do more than you asked. AIGuard adds friction and a human checkpoint exactly here.

Out of scope: adversarial

A deliberately malicious or prompt-injected assistant that crafts evasive, obfuscated, or encoded commands may bypass the regex-based policy. AIGuard does not defend against this, and does not claim to.

AIGuard is an Execution-Layer Security (ELS) tool: it secures the point where an agent's decisions become executed commands. It complements model-level and prompt-level defenses; it does not replace them, and it does not gate file writes or network access performed without spawning a command.

Architecture guarantees — and their limits

  • AIGuard fails closed. Any internal error in aiguard-evaluate blocks the command.
  • The platforms fail open. Both Kimi Code CLI and Claude Code allow a command when a hook times out or crashes. This is documented platform behavior, outside AIGuard's control.
  • Approvals are single-use, bound to the exact command string (SHA-256, truncated to 12 hex chars), and expire after 5 minutes.
  • Absolute Blocks (rm -rf / and equivalents, writes to ~/.aiguard/) cannot be overridden by any approval or user policy.
  • State permissions: ~/.aiguard/ is 0700; challenge, approval, audit, and TOTP files are 0600.
  • TOTP secrets are stored in the system keyring where available, with a 0600-file fallback on headless systems.
  • Audit log (~/.aiguard/audit.jsonl) records every command verbatim. Commands may contain secrets; treat the file as sensitive.

Known limitations

  • Regex-based policy. Obfuscated, encoded, or novel dangerous commands may evade the built-in patterns. The default for unrecognized commands is ask, but a small set of common safe prefixes is auto-allowed.
  • No protection within an approved command. A command is approved as a whole; what a script then does is not constrained.
  • Presence, not judgment. Touch ID and TOTP confirm an authorized human is present — not that the human read the command. Read every command before approving.
  • Notification leakage. The optional daemon shows the first 50 characters of a challenged command in a desktop notification.
  • Keyring fallback. On headless systems the TOTP secret lives in a 0600 file; anyone who can read it can approve commands.
  • Single-user design. State assumes one user account on one machine. Shared accounts and multi-machine sync are unsupported.
  • Beta quality. Defects may exist in exactly the components meant to protect you. AIGuard must not be your only safeguard — maintain independent backups.

The complete operational risk statement is in Risk Disclosures.

Reporting a vulnerability

Report privately

Please report security issues privately via a GitHub Security Advisory rather than a public issue. While the repository is private, contact the maintainer directly.

Please include:

  • the affected AIGuard version and platform;
  • the assistant (Kimi Code CLI / Claude Code) and its version;
  • steps to reproduce;
  • whether the issue lets a command bypass policy evaluation or approval.

Supported versions

VersionSupported
6.1.0bx (Beta)Latest pre-release only
< 6.1No

If something goes wrong

1. Stop the assistant session. 2. Remove the hooks: aiguard uninstall kimi / aiguard uninstall claude. 3. Report the problem — security issues privately per above, everything else as a GitHub issue.