infraveil-guard
A cooperative guardrail for AI agents that blocks destructive shell commands, SQL statements, or cloud operations until a human approves them out-of-band, with a tamper-evident local ledger.
README
<!-- mcp-name: io.github.infraveilhq/agent-guard -->
infraveil-guard
A seatbelt for your AI agent. Put a governed, tamper-evident gate in front of
the destructive things an agent can do — rm -rf, DROP TABLE, terraform destroy, git push --force, kubectl delete namespace, DELETE FROM … with no
WHERE. The agent proposes; the dangerous ones are blocked until a human
approves them out of band; every decision is written to a local hash-chained
ledger you can verify.
Offline by design: no account, no network, no telemetry. It runs entirely on your machine. Open your network tab — it talks to nobody.
pip install infraveil-guard
Why
Coding agents (Claude Code, Cursor, and friends) are great until the one time
they run rm -rf in the wrong directory, or drop the production database to "fix
a migration." You don't want to read every command — you want the catastrophic
ones to stop and wait for you. That's all this does, and it does it well.
Wire it into your agent
Add it as an MCP server. For Claude Code / Cursor / any MCP client:
{
"mcpServers": {
"infraveil-guard": {
"command": "infraveil-guard"
}
}
}
Then add one rule to your agent's instructions (CLAUDE.md, system prompt, etc.):
Before running any shell command, SQL statement, or infrastructure/cloud operation, first call
guard_actionwith the exact command. Only proceed if it returnsproceed: true. If it returnsdecision: "blocked", stop and ask me to approve it — I'll give you a one-time code to pass back asapproval_code.
That's it. Safe commands sail through (and are logged). Dangerous ones stop.
How approval works (the part that matters)
When the agent hits something dangerous, guard_action returns blocked and an
action_id. The agent cannot approve itself — by construction, not by good
behavior. You approve in your own terminal:
$ infraveil-guard approvals
1 action(s) blocked, waiting for approval:
[9b58e9c499b3] CRITICAL CRITICAL risk: drop table (+0 more). Irreversible.
DROP TABLE users;
approve with: infraveil-guard approve 9b58e9c499b3
$ infraveil-guard approve 9b58e9c499b3
Action requesting approval
id: 9b58e9c499b3
risk: CRITICAL (IRREVERSIBLE)
why: CRITICAL risk: drop table. Irreversible.
command:
DROP TABLE users;
Approve this action? [y/N] y
APPROVED. Give the agent this one-time code:
8f2510
It is valid for 15 minutes and works exactly once.
You hand the agent 8f2510; it calls guard_action("DROP TABLE users;", approval_code="8f2510"); the guard checks it, lets it through once, and records
the approval. The code is minted only by the human CLI, is single-use, and
expires — so an agent can't forge or replay it.
Inspect everything — trust nothing
Every decision (allowed, blocked, approved, denied) is appended to a hash-chained
ledger at ~/.infraveil-guard/ledger.jsonl. Editing, deleting, reordering, or
inserting any line breaks the chain:
$ infraveil-guard verify
{ "ok": true, "count": 42, "message": "Hash chain verified across 42 entries - no tampering." }
$ infraveil-guard log 10 # the last 10 decisions, raw
It's ~400 lines of plain stdlib Python. Read it. That's the point.
Tools (MCP)
| Tool | What it does |
|---|---|
guard_action(action, approval_code="") |
Gate an action before running it. Returns proceed true/false. |
assess_action(action) |
Classify blast radius without recording or gating. |
verify_ledger() |
Verify the tamper-evident ledger's hash chain. |
recent_decisions(limit=20) |
The most recent decisions, newest first. |
Configuration
| Env var | Default | Meaning |
|---|---|---|
INFRAVEIL_GUARD_THRESHOLD |
high |
Gate actions at/above this severity: none|low|medium|high|critical. |
INFRAVEIL_GUARD_MODE |
enforce |
enforce blocks dangerous actions; audit logs everything but never blocks (use it to watch your agent before you trust the gate). |
INFRAVEIL_GUARD_HOME |
~/.infraveil-guard |
Where the ledger and approval queue live. |
What this is — and isn't
It is a high-signal classifier + an out-of-band human-approval gate + a tamper-evident local log. It's the smallest honest version of "a human approves before anything irreversible happens."
It is not a sandbox. It works because your agent is told to route actions
through guard_action — a cooperative guardrail, not an unbypassable jail. That
is a deliberate trade: in exchange you get something you can install in one line,
read end to end in an afternoon, and run with no account, no network, and no
dependency on anyone else's infrastructure — including ours. Nothing here calls
home, checks a license, or needs a server to keep working. It does one job and
owns it: stop the catastrophic actions and wait for a human. Yours to fork and
run forever.
Related
Part of Infraveil's open-source tools for running backends you own:
- infraveil-lockin — scan a repo and score how locked in your app is to one cloud provider (
npx infraveil-lockin). - infraveil — a policy DSL you enforce in CI, plus offline audit-ledger and signature verification.
License
AGPL-3.0-or-later. Use it, fork it, read every line. If you run a modified version as a network service, share your changes. © Infraveil Corporation.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。