Memnox — Security skill for Claude Code
See what your AI coding agents can actually do on your machine, and put the dangerous actions behind ask or deny.
How to install Memnox
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Memnox/memnox and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Memnox does
See what your AI coding agents can actually do on your machine, and put the dangerous actions behind ask or deny. Local policy, approval and audit for Claude Code, Codex, Cursor and more. Deterministic, and no model ever decides.
Alternatives in Security
- OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
- Agentseal — Security toolkit for AI agents 344 ★
- Loongsuite Pilot — Local-first telemetry collector for AI coding agents — unified OpenTelemetry events for Claude Code, Codex, Cu 150 ★
README
BEFORE YOU LEAVE AN AGENT RUNNING
Your agents can already do the work.
Memnox makes it safe to let them do it without you.
Claude Code · Codex · Cursor · Gemini CLI · Windsurf, and what Cline, Hermes, OpenClaw and Ruflo can reach
Set it up once. Every agent is governed inside the session it already works in.
No model decides anything. Your code and your secrets never leave your machine.
You already have agents that read your files, run your shell, push to your repositories and call your MCP servers. Memnox sits inside each of their sessions and rules on every tool call before it runs: what is allowed goes ahead, what is dangerous is refused with a way forward, and what needs a person asks you in the prompt you are already looking at.
You do not learn a new tool to get that. You set it up once and keep working the way you work now.
Set up once
npm install -g memnox
memnox setup
That is the last Memnox command you need. `setup` finds the agents on this machine and goes through them one at a time: what each can already reach, what you want to call it, and whether to put
Related Skills
Sandspy
Real-time security monitor for AI coding agents. See what Claude Code, Cursor, Codex, and others actually do o
MCP Intercepter
Transparent proxy + enterprise gateway for MCP: audit logging, tool allow/deny policy, secrets/PII redaction,
Skills Gateway
Governed, identity-aware server for Agent Skills (SKILL.md): OIDC + default-deny policy per fetch, immutable d
Doubleblind
Three layers that cannot see each other's mistakes: re-derive every number in prose from a file you committed,
Arbitus
Open-source security gateway for MCP tool calls — blocks secret leaks, enforces agent policies, and requires h
AI Agent Audit
Read-only audit of a local developer machine for AI-agent-related security risks (Linux + macOS). Ten modules
Related Agents
Permissions Manager
Manage tool permission rules. Use when user says 'allow', 'deny', or 'ask' for a command, wants to modify perm
Prevent XSS Attacks
add_header X-Content-Type-Options "nosniff"; add_header X-Frame-Options "DENY"; add_header X-XSS-Protection "1
Architrave.Agent
Use to build or change a repository end-to-end through a durable, outcome-driven Run. A thin config-first cond