Skip to content

Latest commit

Β 

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Grimdall β€” runtime security for AI agents

Runtime security for AI agents. Stops the tool calls that would delete your repo, nuke your shell, or leak your keys, then writes a tamper-evident, SHA-256 hash-chained audit trail you can verify with one command. Runs fully local: no signup, no telemetry, no API key.

Version npm PyPI license ci

grimdall demo

πŸ”₯ The Problem

You gave an AI coding agent terminal access so it could actually do work. But AI has senior engineer confidence and intern judgment.

  • Agent hallucinates a variable? It runs DROP TABLE users;.
  • Agent gets stuck in a loop? It force-pushes to main.
  • Agent reads a poisoned webpage? It executes arbitrary shell commands.

By the time you realize what happened, your app is down.

⚑ Quickstart (Zero Friction)

No signup. No API key. No telemetry. Works offline. $0 forever.

Node CLI (protects Claude Code, Cursor, Codex):

npx grimdall init --hooks

Python (LangChain, CrewAI, OpenAI Agents SDK, AutoGen):

pip install grimdall
from grimdall import guard

@guard.wrap  # That's it. Your agent is now blast-resistant.
def my_agent_function(prompt):
    # your agent logic here

πŸ§ͺ Try It in 30 Seconds

npx grimdall demo        # watch it block rm -rf / live
grimdall audit:verify    # prove the hash chain is intact
grimdall doctor          # sanity-check your setup

πŸ› οΈ How It Works (The Solution)

Every tool call goes through the Grimdall core loop:

tool call β†’ intercept β†’ evaluate policy β†’ allow / block / review β†’ hash-chained audit

Default protections (out of the box):

  • Blocks destructive shell calls: rm -rf and fork bombs.
  • Blocks destructive SQL: DROP TABLE and TRUNCATE.
  • Blocks path-traversal patterns (..\).
  • Forces network commands (curl) to human-in-the-loop review.
  • Secret masking (redacts API keys and tokens before they're written to the audit log).
  • Prompt-injection detection (shell-destructive, SQL, and path-traversal patterns) with a weighted risk score.

🧩 Features

The unique part: cross-language audit trail. Most tools support one language. Grimdall has a Node CLI and a Python runtime β€” both write to the exact same SHA-256 hash-chained, tamper-evident audit trail. Verify what your Python LangChain agent did using the Node CLI. Cryptographic proof of what was attempted, whether it was blocked, and when.

  • Policy enforcement β€” declarative allow / block / review policies with wildcard tool matching.
  • Secret masking β€” deep-clones call arguments and redacts OpenAI keys, AWS keys, GitHub tokens, bearer tokens.
  • Injection detection β€” weighted risk score for shell-destructive, SQL-destructive, and path-traversal patterns.
  • Human-in-the-loop Slack alerts β€” blocked calls can ping a Slack webhook in real time.
  • grimdall demo β€” watch it block rm -rf / live.
  • grimdall audit:verify β€” one command proves the chain is intact.
  • Signed intent capsules β€” human-signed work orders with task + scope + expiry; requires_intent policy option
  • Spend guardrails β€” hard budget caps per agent with 80/100/120 enforcement pipeline
  • Trust Layer β€” Ed25519 agent identity + cryptographic signing on every audit entry

πŸ” Trust Layer β€” Identity is Math

Every agent gets a cryptographic identity. Every action is signed. Every decision is verifiable.

Agent Identity (Ed25519)

grimdall identity init
# Generated Ed25519 keypair for claude-code
# Fingerprint: 7a:3f:9c:2e:8b:4d:1a:6f:5c:9e:2b:8a:3d:7f:4c:1e
# Keys stored locally: .grimdall/keys/claude-code.key

Keys never leave your machine. Every audit entry is signed by the agent. grimdall audit verify checks both the hash chain AND the signatures.

Why it matters: You can't spoof an Ed25519 signature by changing a display name. Identity is math now.

Signed Intent Capsules

grimdall intent "deploy to staging" \
  --scope "github:push,shell:npm run deploy" \
  --ttl 30m

# Intent capsule created: .grimdall/intents/deploy-staging-20260826.json
# Signed by: aniket@grimdall.site
# Valid until: 2026-08-26 14:30:00 UTC

High-risk actions can require a valid intent capsule. No capsule (or expired capsule) β†’ human review. The agent shows the capsule to prove it's working within scope.

Policy integration:

{
  "tool": "github_push",
  "match": { "branch": "main" },
  "action": "block",
  "requires_intent": true
}

πŸ’° Spend Guardrails β€” The Runaway-Bill Kill Switch

Hard budget caps per agent. Real-time tracking. Automatic enforcement.

Set a Budget

grimdall spend set claude-code --daily 50 --monthly 500
# Budget set: $50/day, $500/month
# Tracking starts now

The Enforcement Pipeline

Budget % Action What Happens
0-80% βœ… Allow Agent works normally, spend tracked
80% ⚠️ Alert Log warning + optional Slack/email
100% πŸ›‘ Review Pause for human approval
120% 🚫 Block Hard stop, no more tool calls

Check Spend

grimdall spend
# claude-code: $32.40 / $50.00 (64.8%) β€” daily
# claude-code: $284.20 / $500.00 (56.8%) β€” monthly
# cursor: $12.80 / $100.00 (12.8%) β€” daily

Why it matters: a16z data shows agents now burn 7x more tokens than humans. Observability tells you the bill is high. Grimdall stops the bleed before the invoice lands.


🎯 How They Work Together

Agent Request β†’ Identity Check β†’ Intent Check β†’ Budget Check β†’ Execute
     ↓                ↓              ↓              ↓           ↓
  Who is it?     Did they sign?  Do they have  Within budget?  Signed +
                  this action?  a work order?               logged

Every decision is:

  • Attributed (signed by a specific agent identity)
  • Scoped (within an approved intent capsule)
  • Budgeted (within spend limits)
  • Verifiable (tamper-evident audit trail)

🎚️ Modes: Audit vs Enforce

  • audit (shadow / learn-only mode): logs what would be blocked, blocks nothing. Run this for a week before switching.
  • enforce: real blocking + review gates.

Switch with the CLI (grimdall mode audit β†’ learn-only, grimdall mode enforce β†’ hard enforcement). Start in audit, graduate to enforce.

⚠️ Caution β€” Read This

Grimdall is a guardrail, not a force field. It reduces blast radius β€” it does not replace sandboxing, least-privilege credentials, or backups. Run agents with the smallest permissions possible, keep immutable backups, and treat review actions as real decisions, not checkbox clicks.

πŸ“‹ Compliance

Grimdall writes a tamper-evident, hash-chained record of every tool call it evaluates β€” the kind of evidence trail auditors ask for. Today you can verify integrity with grimdall audit:verify and inspect the log with grimdall audit:view. Grimdall is evidence infrastructure, not a certified compliance product.

πŸ—ΊοΈ Roadmap

  • Industry policy packs β€” fintech, healthcare, legal, and government presets aligned to SOC 2 / HIPAA-style audit frameworks

πŸ’¬ Community & Support


Apache-2.0 License. Built by a solo founder in India who got tired of being terrified of his own code. If this saved your prod database, give it a star. πŸ™

About

local first tool to Stop rogue AI agents from deleting production. Runtime security layer that intercepts tool calls, blocks dangerous commands, and audits everything.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages