Command policy
Classifies compound commands, nested shells, wrappers, absolute paths, and quoted arguments.
LOCAL. OFFLINE. ZERO RUNTIME DEPENDENCIES.
A deterministic command guardrail and project risk check for Codex and Claude Code operating near Kubernetes, Terraform, Foundry, and production secrets.
Pay with Base USDC or request a PayPal invoice from dev.koriel@gmail.com. Product delivery follows payment verification.
$ was check --command \
"cast send 0x71… 'upgradeTo(address)'"
DENY 100 web3.cast.broadcast
$ was check --command "terraform apply tfplan"
ASK 60 infra.terraform.apply
$ was check --command "terraform plan"
ALLOW 0
0 network calls
0 secret values uploaded
106 automated tests
2 agent harnesses
THE FAILURE WINDOW IS ONE COMMAND
Safe inspection continues without noise. Infrastructure mutation asks or blocks according to the harness. Known destructive and signing patterns stop before execution.
Classifies compound commands, nested shells, wrappers, absolute paths, and quoted arguments.
Checks Codex, Claude Code, MCP, and secret-like filenames without reading secret contents.
Returns structured allow, ask, and deny decisions through current PreToolUse contracts.
DEFAULT POLICY
DENY wallet broadcasts and Forge `--broadcast`
DENY Terraform destroy and namespace deletion
DENY private-key reads and pipe-to-shell
ASK infrastructure and Kubernetes mutation
ALLOW plans, reads, tests, and contract calls
48-HOUR LAUNCH PRICING
Four organization launch slots are available. Each paid tier is for internal use under the commercial license.
Risk Check
$1
One project, one local audit, one report.
Individual
$249
Full guardrail for one operator.
TEAM DEFAULT
Team
$1,499
Up to ten named operators.
4 LAUNCH SLOTS
Organization
$2,500
One legal entity, internal use.
Web3 Agent Safety catches known command patterns. It is not a security boundary. Keep sandboxing, least-privilege credentials, hardware wallets, multisig policy, review, and deployment approval in place.
INSTALL IN MINUTES