Runtime security for AI agents. Stops the tool calls that would delete your repo, nuke your shell, or leak your keys, then writes a tamper-evident, SHA-256 hash-chained audit trail you can verify with one command. Runs fully local: no signup, no telemetry, no API key.
You gave an AI coding agent terminal access so it could actually do work. But AI has senior engineer confidence and intern judgment.
- Agent hallucinates a variable? It runs
DROP TABLE users;. - Agent gets stuck in a loop? It force-pushes to
main. - Agent reads a poisoned webpage? It executes arbitrary shell commands.
By the time you realize what happened, your app is down.
No signup. No API key. No telemetry. Works offline. $0 forever.
Node CLI (protects Claude Code, Cursor, Codex):
npx grimdall init --hooksPython (LangChain, CrewAI, OpenAI Agents SDK, AutoGen):
pip install grimdallfrom grimdall import guard
@guard.wrap # That's it. Your agent is now blast-resistant.
def my_agent_function(prompt):
# your agent logic herenpx grimdall demo # watch it block rm -rf / live
grimdall audit:verify # prove the hash chain is intact
grimdall doctor # sanity-check your setupEvery tool call goes through the Grimdall core loop:
tool call β intercept β evaluate policy β allow / block / review β hash-chained audit
Default protections (out of the box):
- Blocks destructive shell calls:
rm -rfand fork bombs. - Blocks destructive SQL:
DROP TABLEandTRUNCATE. - Blocks path-traversal patterns (
..\). - Forces network commands (
curl) to human-in-the-loop review. - Secret masking (redacts API keys and tokens before they're written to the audit log).
- Prompt-injection detection (shell-destructive, SQL, and path-traversal patterns) with a weighted risk score.
The unique part: cross-language audit trail. Most tools support one language. Grimdall has a Node CLI and a Python runtime β both write to the exact same SHA-256 hash-chained, tamper-evident audit trail. Verify what your Python LangChain agent did using the Node CLI. Cryptographic proof of what was attempted, whether it was blocked, and when.
- Policy enforcement β declarative
allow/block/reviewpolicies with wildcard tool matching. - Secret masking β deep-clones call arguments and redacts OpenAI keys, AWS keys, GitHub tokens, bearer tokens.
- Injection detection β weighted risk score for shell-destructive, SQL-destructive, and path-traversal patterns.
- Human-in-the-loop Slack alerts β blocked calls can ping a Slack webhook in real time.
grimdall demoβ watch it blockrm -rf /live.grimdall audit:verifyβ one command proves the chain is intact.- Signed intent capsules β human-signed work orders with task + scope + expiry;
requires_intentpolicy option - Spend guardrails β hard budget caps per agent with 80/100/120 enforcement pipeline
- Trust Layer β Ed25519 agent identity + cryptographic signing on every audit entry
Every agent gets a cryptographic identity. Every action is signed. Every decision is verifiable.
grimdall identity init
# Generated Ed25519 keypair for claude-code
# Fingerprint: 7a:3f:9c:2e:8b:4d:1a:6f:5c:9e:2b:8a:3d:7f:4c:1e
# Keys stored locally: .grimdall/keys/claude-code.keyKeys never leave your machine. Every audit entry is signed by the agent. grimdall audit verify checks both the hash chain AND the signatures.
Why it matters: You can't spoof an Ed25519 signature by changing a display name. Identity is math now.
grimdall intent "deploy to staging" \
--scope "github:push,shell:npm run deploy" \
--ttl 30m
# Intent capsule created: .grimdall/intents/deploy-staging-20260826.json
# Signed by: aniket@grimdall.site
# Valid until: 2026-08-26 14:30:00 UTCHigh-risk actions can require a valid intent capsule. No capsule (or expired capsule) β human review. The agent shows the capsule to prove it's working within scope.
Policy integration:
{
"tool": "github_push",
"match": { "branch": "main" },
"action": "block",
"requires_intent": true
}Hard budget caps per agent. Real-time tracking. Automatic enforcement.
grimdall spend set claude-code --daily 50 --monthly 500
# Budget set: $50/day, $500/month
# Tracking starts now| Budget % | Action | What Happens |
|---|---|---|
| 0-80% | β Allow | Agent works normally, spend tracked |
| 80% | Log warning + optional Slack/email | |
| 100% | π Review | Pause for human approval |
| 120% | π« Block | Hard stop, no more tool calls |
grimdall spend
# claude-code: $32.40 / $50.00 (64.8%) β daily
# claude-code: $284.20 / $500.00 (56.8%) β monthly
# cursor: $12.80 / $100.00 (12.8%) β dailyWhy it matters: a16z data shows agents now burn 7x more tokens than humans. Observability tells you the bill is high. Grimdall stops the bleed before the invoice lands.
Agent Request β Identity Check β Intent Check β Budget Check β Execute
β β β β β
Who is it? Did they sign? Do they have Within budget? Signed +
this action? a work order? logged
Every decision is:
- Attributed (signed by a specific agent identity)
- Scoped (within an approved intent capsule)
- Budgeted (within spend limits)
- Verifiable (tamper-evident audit trail)
audit(shadow / learn-only mode): logs what would be blocked, blocks nothing. Run this for a week before switching.enforce: real blocking + review gates.
Switch with the CLI (grimdall mode audit β learn-only, grimdall mode enforce β hard enforcement). Start in audit, graduate to enforce.
Grimdall is a guardrail, not a force field. It reduces blast radius β it does not replace sandboxing, least-privilege credentials, or backups. Run agents with the smallest permissions possible, keep immutable backups, and treat
reviewactions as real decisions, not checkbox clicks.
Grimdall writes a tamper-evident, hash-chained record of every tool call it evaluates β the kind of evidence trail auditors ask for. Today you can verify integrity with grimdall audit:verify and inspect the log with grimdall audit:view. Grimdall is evidence infrastructure, not a certified compliance product.
- Industry policy packs β fintech, healthcare, legal, and government presets aligned to SOC 2 / HIPAA-style audit frameworks
Apache-2.0 License. Built by a solo founder in India who got tired of being terrified of his own code. If this saved your prod database, give it a star. π
