Ghost Developer Studio

Agent Seatbelt

A seatbelt for AI coding agents.
It reads the tool call before the tool call happens.

One self-contained Python file that reads every tool call before it runs — shell commands, file writes, MCP calls — and denies or escalates the ones that end careers: recursive deletes, secret exfiltration, production deploys, agent-bypass launches, memory poisoning. Every verdict names its rule, its blast radius, and the safer path.

$ pip install ghost-seatbeltLive on PyPI

v0.2.0 is live on PyPI and GitHub. Also a Claude Code plugin: /plugin marketplace add littlestjames82-sys/agent-seatbelt. Every number below was measured on the current release.

The wedge

Most guardrails write a nicer incident report. Seatbelt is in the loop before execution — the call doesn't run until the verdict says it can.

🛡️

Pre-tool gating

Hooks inspect every shell command, file write, and MCP call before it executes — not in a log review the next morning. The verdict is allow, deny, or escalate, with the reason attached.

allow escalate deny
🔍

Sees through tricks

Deobfuscation unwraps base64, unicode games, and indirection before judging, and injection flags catch tool output trying to talk the agent into something. The disguise is judged, not the costume.

📸

Snapshots

File state is snapshotted around agent writes, so what changed is a diff you can read — and a state you can get back to — instead of a surprise in git status.

🧾

Hash-chained audit

Every verdict lands in a hash-chained audit trail: what was attempted, which rule fired, what the blast radius was, and what happened. Tamper with a link and the chain says so.

🎛️

Policies, not vibes

Deterministic rules and policy packs. Same call in, same verdict out — every run, every machine. No model in the decision loop, no temperature, no surprises.

🧩

Every surface

Claude Code plugin, pre-commit hook, GitHub Action, or the single Python file vendored straight into your project. Standard library only — nothing to install, nothing phoning home.

Verified, not vibes

Measured on the v0.2.0 release, October 2026 — the same bench and suites that ship in the repo.

206/206
Seatbelt Bench cases passing
0
false positives on the bench
275/275
pytest tests passing (v0.2.0)
1 file
stdlib only · zero dependencies
call     bash · rm -rf ~/projects/client-site
inspect  deobfuscated · matched rule: recursive-delete
verdict  DENIED · blast radius: everything under the target path
safer    move it to the trash, or name the subdirectory you mean
audit    verdict + rule + radius written to the hash-chained log
The honest limits: Seatbelt judges the tool call, not the model's intentions — a genuinely novel attack phrased plainly can pass, which is why every verdict is logged and policies are yours to tighten. It gates coding-agent tool calls; it is not a sandbox, and it doesn't replace one.

Where it's headed

Team governance is the next layer — that's GhostGuard, building on the same governor — alongside more policy packs and the bench growing teeth. The roadmap lives in the repo's CHANGELOG and docs.