devalinaqvi

Agent Overwatch — Security skill for Claude Code

Security community

A deterministic guard for AI coding agents — checks each tool call before it runs (allow/ask/deny) and blocks secret reads, git push, and destructive commands, with a redacted audit log.

How to install Agent Overwatch

This entry records only its repository, not the path inside it, so there is no exact command to give. Open devalinaqvi/agent-overwatch and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agent Overwatch does

A deterministic guard for AI coding agents — checks each tool call before it runs (allow/ask/deny) and blocks secret reads, git push, and destructive commands, with a redacted audit log. Works with Claude Code and OpenAI Codex CLI.

Alternatives in Security

  • Agent Skills Guard — 一款提供Agent Skills安全扫描和可视化管理的桌面应用 A desktop application that provides security scanning and visual management fo 389 ★
  • UX Critique — Open-ended taste call on a specific surface 66 ★
  • Claude Guardrails — Hardened security configuration for Claude Code; permission deny rules, shell hooks, and prompt injection defe 33 ★

README

Agent Overwatch

A small, deterministic **guard for AI coding agents**. It checks supported local tool calls *before* they run, against a human-readable policy, and returns **allow / ask / deny** — with a redacted audit log of every decision.

Prompt-level "please don't" is advisory; an agent can ignore it. Agent Overwatch is enforcement *outside* the model — deterministic rules applied before the action runs.

**Ships two adapters — Claude Code and OpenAI Codex CLI — on a clean engine/adapter split.** The decision engine and policy are agent-agnostic; only a thin adapter is specific to each agent, so the *same rules* guard both. Adding another agent means writing one adapter.

![How Agent Overwatch works — agent → PreToolUse hook → adapter → engine.evaluate(policy) → allow/ask/deny, with a redacted audit log and a human-only bypass](docs/images/architecture.png)

Agent wants to…                 Overwatch decides             You get…
─────────────────────────────────────────────────────────────────────────
edit a source file          →   defer (normal flow)           normal edit
run the test suite          →   defer                         tests run
read .env / SSH keys        →   DENY                          blocked + logged
git push · DROP DATABASE    →   DENY                          blocked + logged
sudo · deploy              →   ASK (Claude) / DENY (Codex)   human action required

**Note on names.** The project and brand are **Agent Overwatch**. The CLI entrypoint on disk is `bin/interlock` (kept stable so existing installs keep working); every command below uses it as-is.

Proof — it actually blocks

Both agents, same policy, both stopped from reading a `.env` (fake credentials in a scratch dir). Recreated from real runs; machine-specific details replaced with placeholders.

**OpenAI Codex CLI** — the search command itself trips the rule; it never reaches the file:

![Codex CLI blocked by the hook with "Agent Overwatch SEC-030 — comma