AI-runtime-guard – Policy enforcement layer for MCP AI agents
AI-runtime-guard – Policy enforcement layer for MCP AI agents
I built this after realizing that AI agents with filesystem and shell access can delete files, leak credentials, or execute destructive commands — and there's no enforcement layer stopping them at the execution level. ai-runtime-guard is an MCP server that sits between your AI agent and your system. It enforces a policy layer before any file or shell action takes effect. No retraining, no prompt engineering, no changes to your agent or workflow. Your agent can say anything. It can only do what policy allows. What it does: - Blocks dangerous commands (rm -rf, dd, shutdown, privilege escalation) before execution - Gates risky commands behind human approval via a web GUI - Simulates blast radius for wildcard operations before they run - Creates automatic backups before destructive actions - Full audit trail of everything the agent does Works with Claude Desktop, Cursor, Codex, and any stdio MCP-compatible client. Default profile is basic protection out of the box — advanced tiers are opt-in. Validated on macOS Apple Silicon. Linux expected to work, formal validation coming in v1.1. Would love feedback from anyone running AI agents with filesystem access.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Imara – policy enforcement layer for MCP agents (npx imara)
Product Discovery MCP for AI Agents
PiPy semantic search MCP for AI agents
AI agents integrating tools at runtime
DashClaw – policy and approval layer for unattended coding agents
Crawdad – Runtime security layer for autonomous AI agents
OpsCat – A single-binary software catalog with MCP for AI agents
Policy-bounded crawling and evidence for AI agents
Give AI agents secure, real-time access to your files
Same-origin policy? What same-origin policy?