squidbrake
Brakes for your AI agents: every tool call is checked against your rules, held for human approval when risky, and recorded in a tamper-evident audit trail. Works with Claude Code and any MCP app.
Install / Use
claude mcp add batrapulkit -- npx -y github:batrapulkit/squidbrakeIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of squidbrake
squidbrake scores 84/100 on our quality scale, 723rd of 1,000 Security skills we index.
Its MCP Server is 24 KB long, well organised into 27 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so squidbrake is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
WarningOur scan of the whole file found 4 high-risk patterns. Read the lines below before installing squidbrake, and do not run it with automatic approvals.
- highDecodes hidden content and executes itline 217
| hidden | `eval`, `curl ... \| sh`, `base64 -d \| bash`, `powershell -EncodedCommand` | review | - mediumDeletes the home directory, the root filesystem or a disk (mentioned as something to block)line 215
| catastrophic | `rm -rf /`, `rm -rf ~`, `rmdir /s /q d:\`, `mkfs`, `dd of=/dev/sda`, `chmod -R 777 /` | block | - mediumSends the output of a local command to a remote serverline 217
| hidden | `eval`, `curl ... \| sh`, `base64 -d \| bash`, `powershell -EncodedCommand` | review | - mediumSends the output of a local command to a remote serverline 234
Uploads from the shell count too (`curl -d @.env https://...`, `scp`, `git push`). Anything sent out after outside - noteInstalls by piping a downloaded script into a shellline 26
- **Reads what a command really does:** `ls && rm -rf ~/`, `bash -c "..."`, `rmdir /s /q d:\` or `curl ... | sh` are - noteInstalls by piping a downloaded script into a shellline 217
| hidden | `eval`, `curl ... \| sh`, `base64 -d \| bash`, `powershell -EncodedCommand` | review |
Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
squidbrake compared with similar skills
All 4 of these similar skills score higher than squidbrake; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| squidbrake (this skill)by batrapulkit | 84 | 10 | today | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.2k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install squidbrake?
- Run
claude mcp add batrapulkit -- npx -y github:batrapulkit/squidbrake. The install tabs above show the steps for each supported agent. - Which AI agents does squidbrake work with?
- It is written for Claude Code, Claude Desktop, Cursor, Gemini CLI and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is squidbrake safe to use?
- Our scan of the whole file found 4 high-risk patterns. Read the lines below before installing squidbrake, and do not run it with automatic approvals. It is Apache-2.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is squidbrake still maintained?
- The repository was last updated today, so squidbrake is actively maintained.
Skill content
View source on GitHubSquidbrake
<!-- mcp-name: io.github.batrapulkit/squidbrake -->
Brakes for your AI agents. Every action an agent takes (running a command, editing a file, sending an email, issuing a refund, changing a database) goes through Squidbrake first. It is checked against your rules, held for a person when it's risky, recorded in a tamper-evident audit trail, and can be stopped instantly.
Free and open source (Apache 2.0). Runs on your laptop or your own server; your data never leaves it.
- Rules, not vibes:
rules.yamlsays what runs by itself, what's blocked, and what waits for a person. No LLM in the decision path. - Human approval: risky actions wait in the dashboard, on your phone (one-tap links, push via ntfy) or in Slack. The approver sees what led to it, e.g. the email the agent just read.
- Reads what a command really does:
ls && rm -rf ~/,bash -c "...",rmdir /s /q d:\orcurl ... | share split and read before they run. Wiping a disk or home folder is blocked;git push --force,terraform destroy,kubectl deleteor cloud deletes wait for a person; commands that only look (ls,git status) run without asking. - Catches prompt injection without a model: if an agent sends data to an address that only a web page, email or issue mentioned (not you, not your own systems), it's held and the approver is told where the address came from.
- Judges by history: blocks a retry of something a person rejected, catches look-alike domains
(
acrne-corp.compretending to beacme.com), flags duplicate refunds, and lets you write sequence rules ("deleting a database right after its backups were turned off") that say which earlier step caused them. - Works with real agents:
squidbrake connect allconnects Claude Code, Cursor, Codex, Gemini CLI, VS Code Copilot and Antigravity (their commands, reads and edits, via hooks) and the MCP servers they already use; any MCP app (Stripe, GitHub, Slack, databases, internal tools) can be wrapped too. - For teams: a key per person and per agent, roles (only
financeapproves wires), an emergency stop (all agents, one agent, or one conversation, which also ends Claude Code's turn), reports, CSV export, and evidence anyone can verify offline (python verify.py). - Fails closed: if Squidbrake is down, guarded tools don't run.
See SHOWCASE.md for a 5-minute demo with a sandbox company, and incidents/ for 8 real AI-agent incidents replayed against the shipped rules (Replit, the Railway volume deletion, GitHub MCP, Supabase MCP, Claude Code and Antigravity deletes...): 11 of 11 harmful actions stopped, checked in CI.

See it live, nothing to install
Click the button and the live demo starts in your browser (free with a GitHub account): a sandbox company's AI
support agent works its inbox while you watch. A scam wire is blocked, refunds wait for a person, and a demo
manager approves or rejects them. If the editor asks whether to allow tasks that run automatically, click
Allow: that's the demo starting. On your own machine: pip install -r requirements.txt then python demo/live_demo.py.
Try it in 30 seconds
pipx install squidbrake # or: pip install squidbrake
squidbrake connect all # every AI agent on this computer now goes through it
squidbrake # start it: opens the dashboard
connect all finds the agents you have (Claude Code, Cursor, Codex, Gemini CLI, VS Code Copilot, Antigravity) and
the MCP servers they already use, and routes them all through Squidbrake. It prints your dashboard key the first
time, backs up every config it changes, and squidbrake connect all --remove undoes it. Restart the agents, then
ask one to run rm -rf ~/ and watch it get blocked. squidbrake connect status shows which agents are covered, and
catches the one step people miss (Codex runs a new hook only after you approve it in /hooks).
Your rules, keys and data live in ~/.squidbrake; edit ~/.squidbrake/rules.yaml and changes apply at once.
Only Claude Code? It's also a plugin, installed from inside Claude Code (see plugin/):
/plugin marketplace add batrapulkit/squidbrake, then /plugin install squidbrake@squidbrake.
From a clone instead: git clone https://github.com/batrapulkit/squidbrake && cd squidbrake, then ./start.sh
(Windows: start.bat) and ./connect.sh claude-code (Windows: connect.bat claude-code).
Or with Docker: docker run -d -p 8080:8080 -v squidbrake-data:/app/data --name squidbrake ghcr.io/batrapulkit/squidbrake
(keys: docker logs squidbrake).
1. Start it
| Where | Command |
|---|---|
| Windows | double-click start.bat |
| macOS / Linux | ./start.sh |
| A Linux server, 24/7 | ./install.sh (or ./install.sh gateway.yourdomain.com for HTTPS) |
The first start installs everything, prints an admin key (for the dashboard) and an agent key
(shown once, so save them), and opens http://localhost:8080/dashboard. No configuration needed; every
setting in .env.example is optional.
Keys: python server.py add-key NAME [--approver], python server.py remove-key NAME, python server.py keys.
Changes apply immediately, no restart needed. (Inside Docker, prefix with docker compose exec gateway.)
2. Connect real agents
With the gateway running, one command per agent (installed with pip, type squidbrake connect ... instead;
from a clone, use the .venv Python that start.bat / start.sh created):
.venv/Scripts/python connect.py all # every agent at once (Windows; macOS/Linux: .venv/bin/python)
.venv/Scripts/python connect.py claude-code # or one at a time
.venv/Scripts/python connect.py mcp --name antigravity # also: claude-desktop, cursor
| Agent | What's checked | One at a time |
|---|---|---|
| Claude Code | every tool call (Bash, PowerShell, edits, reads, web, MCP) | connect claude-code |
| Cursor | terminal commands and file reads, plus its MCP servers | connect agents --agent cursor, connect guard --agent cursor |
| Codex | shell commands and edits. Approve the hook once in Codex with /hooks: until then Codex skips it | connect agents --agent codex |
| Gemini CLI | shell commands, reads, writes and edits, plus its MCP servers | connect agents --agent gemini-cli |
| VS Code Copilot | agent-mode commands, reads and edits, plus its MCP servers | connect agents --agent vscode |
| Antigravity | terminal commands, reads and writes, plus its MCP servers | connect agents --agent antigravity |
| Windsurf, Kiro, Claude Desktop | their MCP servers | connect guard --agent windsurf |
- Claude Code: a hook sends every tool call (Bash, PowerShell, Edit, Write, Read, WebFetch, MCP tools)
through the gateway before it runs. Blocked calls are refused with the reason, and calls held for
approval wait until you decide in the dashboard. It also adds the database tools below.
Add
--project DIRto limit it to one project;--removeundoes it. If the gateway is down, Claude Code's tool calls are blocked (fail closed) and it says why. - Antigravity, Claude Desktop, Cursor, any MCP client: prints the config block to paste in. The agent
gets
list_tables,describe_table,queryandexecutetools on a SQLite database (data/shop.db, created with sample customers / products / orders; setDB_PATHto use your own). Reads run immediately,UPDATE/DELETE/INSERT/ALTERwait for your approval, andDROP/TRUNCATEare blocked.
Wrapping a GitHub or Stripe MCP server? Start with the commented example policies in
examples/rules/ and adjust their tool-name patterns to the server's tool list.
Things to ask the agent, then watch the dashboard:
- "Show me the top 5 customers by revenue" (runs)
- "Give every customer on the team plan a 15% discount" (waits for you to approve)
- "Delete all failed orders" (approve or reject it; a rejection note is passed back to the agent)
- "Drop the orders table" (blocked)
- In Claude Code: "commit and push this" (the
git pushwaits for approval)
3. Show it to someone
- Right now, from your PC:
cloudflared tunnel --url http://localhost:8080prints a publichttps://….trycloudflare.comlink. Give viewers their own key:python server.py add-key guest. Afterwards, press Ctrl+C and runpython server.py remove-key guest. - Permanently:
./install.sh gateway.yourdomain.comon a small cloud server.
4. Other computers (a friend, a teammate, a server)
Make a clean copy (no keys, no history): python pack.py -> dist/squidbrake.zip.
- Their own gateway: unzip, double-click
start.bat(Windows) or run./start.sh. It makes its own keys. - Their agents on YOUR gateway: in your dashboard's Team tab add them (a person, to watch/approve) and add
their agent (type AI agent); send them that agent key. They unzip and run, for example:
connect.bat wrap --sandbox --agent claude-code --url https://your-gateway --key gw_...(orconnect.bat claude-code --url ... --key ...to route every Claude Code action through your gateway). - A cloud server, 24/7: unzip there and run
bash install.sh(HTTPS included, no domain needed).
Other ways to send calls through it
Any MCP server - put Squidbrake in front of it, in any MCP client. The agent sees the app's normal tools, and
each call is checked first (with GATEWAY_URL and GATEWAY_API_KEY set in the client's MCP config):
squidbrake proxy --app linear --url https://mcp.linear.app/mcp # a remote MCP server
squidbrake proxy --app stripe -- npx -y @stripe/mcp --tools=all # one started by a command
squidbrake connect guard does this for the servers your agents already use.
Python - wrap your tools:
from client import Gateway, Denied
gw = Gateway("https://gateway.
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
87.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
