Local-first execution contracts for CLI and AI agents
Approve an execution boundary once. Reuse it until the command, inputs, or policy changes.
How it works
Guardrail normalizes the execution contract, hashes it, and compares it with the acknowledged manifest. A changed command, argument, input, recipe, or bound policy stops before execution.
Structured commands, paths, policies, and sorted allowlists become deterministic contract data for the current execution context.
The candidate contract and computed risk are shown in a real TTY. Type APPROVE to store the acknowledged manifest.
On reuse, Guardrail rebuilds and compares the contract. An exact match runs; drift returns Exit 12 and requires review.
Risk classification
Guardrail computes risk independently of what you declare. If it computes higher — the higher level wins.
Reviewed or pinned source, safe binaries, local or temporary writes, and no inherited environment.
The fallback for work that is not RED but does not satisfy every GREEN condition.
Generated/unknown sources and high-impact targets require strong confirmation.
Launch recipe pack
Bundled, parameterized contracts for common workflows. Cards show manifest-declared risk; runtime trust and policy checks may escalate the resolved artifact.
Creates a pull request with explicit repository, base/head branches, title, and a content-hash-bound body file.
Runs lockfile-bound npm ci through the bundled wrapper with scripts, audit, and funding prompts disabled.
Runs terraform validate and terraform plan -input=false for one bounded configuration path.
Builds a tagged container image from a bounded relative context with no arbitrary Docker flags.
From a source checkout. Requires Node.js 20 or newer.