The wedge
Most guardrails write a nicer incident report. Seatbelt is in the loop before execution — the call doesn't run until the verdict says it can.
Pre-tool gating
Hooks inspect every shell command, file write, and MCP call before it executes — not in a log review the next morning. The verdict is allow, deny, or escalate, with the reason attached.
Sees through tricks
Deobfuscation unwraps base64, unicode games, and indirection before judging, and injection flags catch tool output trying to talk the agent into something. The disguise is judged, not the costume.
Snapshots
File state is snapshotted around agent writes, so what changed
is a diff you can read — and a state you can get back to — instead
of a surprise in git status.
Hash-chained audit
Every verdict lands in a hash-chained audit trail: what was attempted, which rule fired, what the blast radius was, and what happened. Tamper with a link and the chain says so.
Policies, not vibes
Deterministic rules and policy packs. Same call in, same verdict out — every run, every machine. No model in the decision loop, no temperature, no surprises.
Every surface
Claude Code plugin, pre-commit hook, GitHub Action, or the single Python file vendored straight into your project. Standard library only — nothing to install, nothing phoning home.
Verified, not vibes
Measured on the v0.2.0 release, October 2026 — the same bench and suites that ship in the repo.
call bash · rm -rf ~/projects/client-site inspect deobfuscated · matched rule: recursive-delete verdict DENIED · blast radius: everything under the target path safer move it to the trash, or name the subdirectory you mean audit verdict + rule + radius written to the hash-chained log
Where it's headed
Team governance is the next layer — that's GhostGuard, building on the same governor — alongside more policy packs and the bench growing teeth. The roadmap lives in the repo's CHANGELOG and docs.