Leash – Security guardrails for AI coding agents
Leash – Security guardrails for AI coding agents
AI coding agents like Claude Code can hallucinate dangerous commands. Wrong paths, wrong directories, and suddenly you're running "rm -rf ~/" instead of "rm -rf ./". I built Leash to catch these mistakes before they execute. It's a simple hook that runs before each tool call. Blocks dangerous commands outside the working directory, protects sensitive files like .env and .git even inside the project, and stops destructive git operations like reset --hard or push --force. Some things it handles that weren't obvious at first: agents doing "cd ~/Downloads && rm -rf folder" to escape the sandbox, compound patterns like "find -delete" or "xargs rm" targeting paths outside the project, and symlink-based escapes. Works with Claude Code, OpenCode, Pi, and Factory Droid. Setup is just "npm install -g @melihmucuk/leash" followed by "leash --setup claude-code". Not a full sandbox. If you need real isolation, use containers. This just catches the common hallucination patterns that cause accidental damage. https://github.com/melihmucuk/leash
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Todoist for AI coding agents
Orchestrate your AI coding agents
AgentToolBench-Code – security benchmark for AI coding agents
A security layer for AI coding agents
Client intake for AI coding agents
Vectimus – Cedar policy enforcement for AI coding agents
The design library for AI coding agents
Stop re-explaining your project to AI coding agents
Symphony – a live map of your AI coding agents
Stop copy-pasting between your AI coding agents