Local-first execution contracts for CLI and AI agents

NOTHING RUNS WITHOUT APPROVAL.

Approve an execution boundary once. Reuse it until the command, inputs, or policy changes.

# approved on the first run
guardrail run -- npm test
 
# a later request changes the contract
guardrail run -- npm test --silent
 
▶ Execution paused. Drift detected.
+ new argument: --silent REVIEW REQUIRED
approved: npm test ✓ UNCHANGED
 
Exit 12. Re-run interactively to review the new contract.
new argument → drift review production target → RED system path → RED outside-repo write → RED package install → YELLOW+ generated source → RED changed recipe → drift review missing approval → fail closed new argument → drift review production target → RED system path → RED outside-repo write → RED package install → YELLOW+ generated source → RED changed recipe → drift review missing approval → fail closed

THE ENGINE BEHIND THE BLOCK

Guardrail normalizes the execution contract, hashes it, and compares it with the acknowledged manifest. A changed command, argument, input, recipe, or bound policy stops before execution.

01
⬡

Normalize

Structured commands, paths, policies, and sorted allowlists become deterministic contract data for the current execution context.

02
◈

Review and acknowledge

The candidate contract and computed risk are shown in a real TTY. Type APPROVE to store the acknowledged manifest.

03
▣

Enforce on every run

On reuse, Guardrail rebuilds and compares the contract. An exact match runs; drift returns Exit 12 and requires review.

12
Exit code on drift
20+
Required Node.js runtime
3
Risk levels
25
Bundled recipes

EVERY COMMAND GETS A VERDICT

Guardrail computes risk independently of what you declare. If it computes higher — the higher level wins.

GREEN

Reviewed, structured, local

Reviewed or pinned source, safe binaries, local or temporary writes, and no inherited environment.

  • structured argv
  • reviewed_internal source
  • repo-local paths
  • no destructive traits
YELLOW

Scoped but elevated risk

The fallback for work that is not RED but does not satisfy every GREEN condition.

  • package installs
  • bounded local writes
  • shell mode without RED traits
  • community recipe minimum
RED

Untrusted or high-impact

Generated/unknown sources and high-impact targets require strong confirmation.

  • production or system targets
  • sudo or admin commands
  • writes outside the repo
  • destructive system-path work

BOUNDED WORKFLOWS,
OUT OF THE BOX

Bundled, parameterized contracts for common workflows. Cards show manifest-declared risk; runtime trust and policy checks may escalate the resolved artifact.

gh-open-pr MEDIUM*

Creates a pull request with explicit repository, base/head branches, title, and a content-hash-bound body file.

repo: owner/repo base + head: bounded body_file: content hash
npm-install MEDIUM*

Runs lockfile-bound npm ci through the bundled wrapper with scripts, audit, and funding prompts disabled.

package_dir: relative path lockfile: content hash scripts: disabled
terraform-plan-only MEDIUM*

Runs terraform validate and terraform plan -input=false for one bounded configuration path.

config_path: relative apply/destroy: absent structured argv
docker-build MEDIUM*

Builds a tagged container image from a bounded relative context with no arbitrary Docker flags.

image: explicit tag context_dir: relative structured argv

GIVE IT THE
GUARDRAIL.

From a source checkout. Requires Node.js 20 or newer.

$ npm install && npm link
Read the docs View on GitHub