Guardrail
- **Runtime**: Node.js - **Framework**: Express 4.x - **Entry point**: `api/server.js` - **Port**: 3001
Install / Use
npx skills add codewithrakshit/GuardrailInstalls into whichever agent you are using.
Amazon Q Rules
Amazon Q Developer rules
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of Guardrail
Guardrail scores 56/100 on our quality scale, 4161st of 4,578 Development & Engineering skills we index.
Its Amazon Q Rules is 2.6 KB long, well organised into 12 sections and no code examples: a solid amount of guidance for an agent.
It has no GitHub stars yet, so there is no community track record; judge it on its content.
Maintenance, license and trust
- We could not determine when the repository was last updated.
- Our last check on 2026-09-27 found the source still online.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 68/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
Guardrail compared with similar skills
All 4 of these similar skills score higher than Guardrail; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| Guardrail (this skill)by codewithrakshit | 56 | 0 | — | Amazon Q Rules |
| Agent-Reachby Panniantong | 100 | 95.5k | 3d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 75.0k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 45.8k | 2d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.8k | today | CLAUDE.md |
Frequently asked questions
- How do I install Guardrail?
- Run
npx skills add codewithrakshit/Guardrail. The install tabs above show the steps for each supported agent. - Which AI agents does Guardrail work with?
- It is written for Amazon Q, as a Amazon Q Rules file. Other agents that read the same format can often use it too.
- Is Guardrail safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It declares no license and scores 68/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is Guardrail still maintained?
- We could not determine when the repository was last updated.
Skill content
View source on GitHubGuardRail AI — Tech Stack
Backend (api/)
- Runtime: Node.js
- Framework: Express 4.x
- Entry point:
api/server.js - Port: 3001
Middleware
helmet— security headerscors— frontend athttp://localhost:3000express-rate-limit— 50 req/hour defaultcompression— gzipjoi— request validation (api/middleware/validation.js)
AWS SDKs (v3)
| SDK | Usage |
|-----|-------|
| @aws-sdk/client-bedrock-runtime | AI vulnerability analysis via Amazon Bedrock Nova Lite |
| @aws-sdk/client-secrets-manager | Secret provisioning with 24h TTL |
| @aws-sdk/client-dynamodb | Scan results + audit logs |
| @aws-sdk/client-s3 | Patched code storage |
| @aws-sdk/client-cloudwatch-logs | Event logging |
API Routes
| Method | Path | File |
|--------|------|------|
| POST | /api/scan | routes/scan.js |
| GET | /api/result/:id | routes/result.js |
| GET | /api/logs | routes/logs.js |
| POST | /api/demo | routes/demo.js |
| POST/GET | /api/session | routes/session.js |
| GET | /health | inline in server.js |
Core Services (api/services/)
security-orchestrator.js— main workflow coordinatorbedrock-client.js— Bedrock Nova Lite AI callspatch-generator.js— produces patched codesecret-lifecycle-manager.js— Secrets Manager + 24h TTLsession-manager.js— per-scan session isolationevent-logger.js— DynamoDB + CloudWatch audit trailremediation-engine.js— vulnerability remediation logics3-storage.js— S3 upload/download
Frontend (web/)
- Framework: Next.js 14 (App Router)
- Language: TypeScript
- Styling: Tailwind CSS
- Port: 3000
Key Dependencies
axios— API calls to backendlucide-react— iconsprismjs— code syntax highlightingreact-diff-viewer-continued— before/after patch diffs
Pages (web/app/)
/— landing page (page.tsx)/scan— code submission/results— vulnerability report + patch viewer/dashboard— scan history/demo— guided demo
IDE Extension (extensions/vscode/)
- Built with VS Code Extension API
- Works on: VS Code, Kiro, Cursor, Windsurf
- Trigger:
Ctrl+Shift+G - Features: inline diagnostics, quick-fix lightbulb, auto-scan on save
- Packaged as
.vsix
Infrastructure
- Config:
config/aws-config.json - Docker:
api/Dockerfile,web/Dockerfile,docker-compose.yml - Deploy script:
scripts/deploy-infra.js - Env:
api/.env(copy fromapi/.env.example)
Supported Languages for Scanning
JavaScript, TypeScript, Python, Java, Go, Ruby, PHP
Related Skills
Agent-Reach
95.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
75.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
45.8kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.8kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
