AgentJail.

Policy guardrails for coding agents

Overview

Nancy is actively building AgentJail as a personal open-source product for governing coding agents. It checks tool calls locally before they run and blocks dangerous actions using deterministic policy rather than instructions that a model can ignore.

AgentJail works with Claude Code, Codex CLI, and Cursor. Its controls cover sensitive file access, destructive shell commands, untrusted MCP tools, network egress, and cloud or database credentials.

Why It Exists

Coding agents can access developer machines, credentials, repositories, and production systems. Prompt files are useful context, but they are not an enforcement boundary. AgentJail adds a policy layer outside the model so unsafe actions can be stopped before execution.

Core Capabilities

  • Local, offline policy evaluation with Open Policy Agent and Rego
  • File, command, MCP, credential, and network controls
  • OS-native sandboxing with Linux Landlock and macOS Seatbelt
  • Default-deny policies and auditable decisions
  • Support for Claude Code, Codex CLI, and Cursor

Learn more at agentjail.io or review the open-source repository.

How It Works

1

Intercept

Capture a coding agent's tool call before the requested shell command, file operation, MCP action, or network request executes.

2

Evaluate

Evaluate the action locally against deterministic policy-as-code rules using Open Policy Agent and Rego.

3

Enforce

Allow, deny, or require approval before execution, with OS-native sandboxing through Landlock on Linux and Seatbelt on macOS.

4

Audit

Record policy decisions and agent activity so teams can inspect what happened without relying on prompt-based guardrails.

Tech Stack

GoOpen Policy AgentRegoLandlockSeatbelt